🇿🇦
conure.sh
2026-09-04 02:57:30
(3 minutes ago)
csagent: score 20.0: secrets grab x2; 1 domain(s) in 3s
Web App Attack
🇫🇷
✨
2026-09-04 02:51:10
(9 minutes ago)
Domain : lyons-centre.events
Rule : env
2026-09-04 02:50:16 ***hidden-privacy*** GET /@fs/src/.env r ...
show more
Domain : lyons-centre.events
Rule : env
2026-09-04 02:50:16 ***hidden-privacy*** GET /@fs/src/.env raw?? 80 - 35.187.27.141 HTTP/1.1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:128.2) Gecko/20100101 Firefox/128.2; compatible; Claude-SearchBot/1.0; https://www.anthropic.com/claude-searchbot - lyons-centre.events 404 0 2 1535 369 39 - -
show less
Hacking
SQL Injection
🇺🇸
TPI-Abuse
2026-09-04 02:41:51
(18 minutes ago)
(mod_security) mod_security (id:210492) triggered by 35.187.27.141 (141.27.187.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.187.27.141 (141.27.187.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 22:41:44.778948 2026] [security2:error] [pid 29500:tid 29500] [client 35.187.27.141:11062] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.spacerecording.com"] [uri "/@fs/.env"] [unique_id "apov6AZqO6FLqh1tDlfXdgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 02:20:50
(39 minutes ago)
(mod_security) mod_security (id:210492) triggered by 35.187.27.141 (141.27.187.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.187.27.141 (141.27.187.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 22:20:43.017821 2026] [security2:error] [pid 29243:tid 29243] [client 35.187.27.141:62382] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "crosspexotics.dance4ovations.com"] [uri "/@fs/.env"] [unique_id "apoq-0Si1-AG0rz3YMzq_wAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 01:48:14
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 35.187.27.141 (141.27.187.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.187.27.141 (141.27.187.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 21:48:08.212605 2026] [security2:error] [pid 25585:tid 25585] [client 35.187.27.141:6078] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.makeupbyindi.com"] [uri "/@fs/app/.env"] [unique_id "apojWKTr7zGV1bEuWGtRJAAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
masterguru
2026-09-04 01:23:31
(1 hour ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-197)
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 01:02:26
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 35.187.27.141 (141.27.187.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.187.27.141 (141.27.187.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 21:02:19.527012 2026] [security2:error] [pid 29904:tid 29904] [client 35.187.27.141:34624] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.leonardodecaprio.com"] [uri "/@fs/root/.env"] [unique_id "apoYm-A1rJDJHucO0v3_8gAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇾
lns.bz
2026-09-04 00:59:17
(2 hours ago)
Too many 404 requests [BY]
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 00:44:12
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.187.27.141 (141.27.187.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.187.27.141 (141.27.187.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 20:44:08.828940 2026] [security2:error] [pid 6882:tid 6882] [client 35.187.27.141:56768] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.shannonraevocalstudio.com"] [uri "/@fs/app/.env"] [unique_id "apoUWPrMmjC5Pmpgou_dPwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Philister11
2026-09-04 00:03:24
(2 hours ago)
CrowdSec: crowdsecurity/http-path-traversal-probing (BE/AS396982)
Web App Attack
Hacking
Anonymous
2026-09-03 23:56:13
(3 hours ago)
Bot / seems abusive / Apache connections: 21
DDoS Attack
Web Spam
Bad Web Bot
Web App Attack
🇸🇪
vaia.cloud
2026-09-03 23:25:01
(3 hours ago)
crowdsecurity/http-probing
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-03 23:16:30
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.187.27.141 (141.27.187.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.187.27.141 (141.27.187.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 19:16:25.694601 2026] [security2:error] [pid 13826:tid 13826] [client 35.187.27.141:61320] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.coloradofingerprinting.com"] [uri "/@fs/root/.env"] [unique_id "apn_yfZPe8REc-NrhZCnEAAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
pm33
2026-09-03 22:57:52
(4 hours ago)
Excessive crawling HTTP 404
Web App Attack
🇺🇸
TPI-Abuse
2026-09-03 22:38:19
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.187.27.141 (141.27.187.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.187.27.141 (141.27.187.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 18:38:14.172939 2026] [security2:error] [pid 14299:tid 14299] [client 35.187.27.141:53760] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.stindustries.us"] [uri "/@fs/src/.env"] [unique_id "apn21oOP5wtWh0GTN7RzHQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack