🇳🇱
Site.eu
2026-09-08 20:47:17
(16 hours ago)
Excessive multi-domain requests
Brute-Force
🇳🇱
WeCloudit-Anti-Abuse
2026-09-08 20:22:09
(16 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-path-traversal-probing
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-08 19:36:33
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.189.138.70 (70.138.189.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.189.138.70 (70.138.189.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 15:36:28.319352 2026] [security2:error] [pid 13350:tid 13350] [client 35.189.138.70:48442] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.barristershall.com"] [uri "/@fs/root/.env"] [unique_id "aqBjvLcJSPt0OdoCZn7L-AAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
BlueWire Hosting
2026-09-08 19:22:03
(17 hours ago)
High-confidence malicious configuration/VCS probe
Web App Attack
🇳🇱
Savvii
2026-09-08 18:31:34
(18 hours ago)
20 attempts against mh-misbehave-ban on redirect
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
LRob
2026-09-08 18:11:28
(19 hours ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /@fs/.env (+8 more) | 2026-09-08 18:11 UTC
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 17:58:39
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.189.138.70 (70.138.189.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.189.138.70 (70.138.189.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 13:58:34.301328 2026] [security2:error] [pid 14118:tid 14118] [client 35.189.138.70:64374] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.thecollective.org"] [uri "/@fs/app/.env"] [unique_id "aqBMypNm84IKxpEMGSvjBAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇯🇵
S.O.B.A. Dev.
2026-09-08 17:58:08
(19 hours ago)
Web vulnerability scanning
Brute-Force
Web Spam
Web App Attack
🇳🇱
Mangelot Hosting
2026-09-08 17:26:30
(19 hours ago)
(modsecurity) srv102 ModSecurity 35.189.138.70 (JP/Japan/70.138.189.35.bc.googleusercontent.com): 30 ...
show more
(modsecurity) srv102 ModSecurity 35.189.138.70 (JP/Japan/70.138.189.35.bc.googleusercontent.com): 30 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 17:09:55
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.189.138.70 (70.138.189.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.189.138.70 (70.138.189.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 13:09:48.198231 2026] [security2:error] [pid 3016:tid 3016] [client 35.189.138.70:12120] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.astariamedia.com"] [uri "/@fs/.env.production"] [unique_id "aqBBXLLgEBYMHJsuYlKupgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇸🇪
vaia.cloud
2026-09-08 16:50:02
(20 hours ago)
crowdsecurity/http-probing
Brute-Force
Web App Attack
Anonymous
2026-09-08 16:06:54
(21 hours ago)
Multiple web server 400 error codes from same source ip
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 15:59:01
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.189.138.70 (70.138.189.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.189.138.70 (70.138.189.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 11:58:54.055643 2026] [security2:error] [pid 30448:tid 30448] [client 35.189.138.70:12482] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "capecodbeachfront.com"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252froot/.env"] [unique_id "aqAwvlnG2xinRZf5hESogQAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 15:20:00
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.189.138.70 (70.138.189.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.189.138.70 (70.138.189.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 11:19:54.539268 2026] [security2:error] [pid 21237:tid 21237] [client 35.189.138.70:9884] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.victotex.com"] [uri "/@fs/app/.env"] [unique_id "aqAnmuSdunugATnzNkxFeQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇪
cmbplf
2026-09-08 15:06:32
(22 hours ago)
733 requests with url.path */@fs/*
131 requests with url.path *.config/*
Brute-Force
Bad Web Bot