🇺🇸
TPI-Abuse
2026-09-06 02:56:54
(6 minutes ago)
(mod_security) mod_security (id:210492) triggered by 35.188.159.205 (205.159.188.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.188.159.205 (205.159.188.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:56:50.098439 2026] [security2:error] [pid 3655278:tid 3655278] [client 35.188.159.205:38662] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.sargentandco.com"] [uri "/.env.old"] [unique_id "apzWcl_vfsBj62fMownL-gAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
mnsf
2026-09-06 02:05:39
(57 minutes ago)
Scanning/Probing (20)
Brute-Force
Web App Attack
🇫🇷
dynamix
2026-09-06 01:44:56
(1 hour ago)
Multiple WAF Violations
Web App Attack
🇬🇧
Aetherweb Ark
2026-09-06 01:21:24
(1 hour ago)
(mod_security) mod_security (id:949110) triggered by 35.188.159.205 (US/United States/205.159.188.35 ...
show more
(mod_security) mod_security (id:949110) triggered by 35.188.159.205 (US/United States/205.159.188.35.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
🇺🇸
kosada.com
2026-09-06 00:08:10
(2 hours ago)
Repeated exploit attempts, for example: /actuator/configprops /actuator/ (HTTP/1.1 port 443)
Web App Attack
🇬🇧
consul.to
2026-09-05 23:49:57
(3 hours ago)
Web attack/malicious scanning detected
Web App Attack
🇳🇴
jad-abuse
2026-09-05 23:13:21
(3 hours ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: env_probe ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: env_probe, scanner_ua, actuator, ignition_debug, source_backup, config_backup. Observed by 1 sensor(s); 19 hits.
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 22:54:50
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.188.159.205 (205.159.188.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.188.159.205 (205.159.188.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 18:54:43.827841 2026] [security2:error] [pid 21862:tid 21862] [client 35.188.159.205:43700] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.naghmehfarahmand.com"] [uri "/.env.production"] [unique_id "apydswgUUfoAhYIukE9kugAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 21:32:32
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.188.159.205 (205.159.188.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.188.159.205 (205.159.188.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 17:32:27.736434 2026] [security2:error] [pid 26983:tid 26983] [client 35.188.159.205:42700] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "innatmichaellynns.com"] [uri "/.env"] [unique_id "apyKa2N-hTszxVF5Ap06pQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 21:07:55
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.188.159.205 (205.159.188.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.188.159.205 (205.159.188.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 17:07:49.025336 2026] [security2:error] [pid 15087:tid 15087] [client 35.188.159.205:40850] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "unitoolsupplies.com"] [uri "/wp-config.php.bak"] [unique_id "apyEpS7bFwNXvxXCcsGh2wAAACQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
VHosting
2026-09-05 20:40:04
(6 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇳🇱
e.fierstra
2026-09-05 20:34:05
(6 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇩🇪
IVski.com
2026-09-05 20:33:49
(6 hours ago)
IVski WAF | Sensitive file probe - looking for exposed .env and .git config
DDoS Attack
Bad Web Bot
🇳🇱
WeCloudit-Anti-Abuse
2026-09-05 20:28:47
(6 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-05 20:27:40
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.188.159.205 (205.159.188.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.188.159.205 (205.159.188.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 16:27:33.367311 2026] [security2:error] [pid 29013:tid 29013] [client 35.188.159.205:41652] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "banjogram.com"] [uri "/.env.local"] [unique_id "apx7NenRNY3MgPWEIIE1ywAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack