🇺🇸
TPI-Abuse
2026-09-08 17:50:33
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 35.189.180.114 (114.180.189.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.189.180.114 (114.180.189.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 13:50:28.794806 2026] [security2:error] [pid 1248:tid 1315] [client 35.189.180.114:43718] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "test.giere.us"] [uri "/@fs/.env.production"] [unique_id "aqBK5PVXKXnwOLXFzoLPgAAAAIk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Mangelot Hosting
2026-09-08 16:39:52
(2 hours ago)
(modsecurity) srv104 ModSecurity 35.189.180.114 (TW/Taiwan/114.180.189.35.bc.googleusercontent.com): ...
show more
(modsecurity) srv104 ModSecurity 35.189.180.114 (TW/Taiwan/114.180.189.35.bc.googleusercontent.com): 30 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
🇩🇪
paissangroup
2026-09-08 16:37:41
(2 hours ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 16:22:14
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.189.180.114 (114.180.189.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.189.180.114 (114.180.189.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 12:22:09.284885 2026] [security2:error] [pid 32328:tid 32328] [client 35.189.180.114:27778] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.mapleleaf-marketing.com"] [uri "/@fs/.env"] [unique_id "aqA2MTir7b-8_Ri37tfpuAAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 16:01:00
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.189.180.114 (114.180.189.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.189.180.114 (114.180.189.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 12:00:55.668231 2026] [security2:error] [pid 8016:tid 8016] [client 35.189.180.114:35264] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.restaurantehaowey.com"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252froot/.env"] [unique_id "aqAxN_7h3Kz_o7FLku4O-wAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-08 15:46:41
(3 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-08 15:38:57
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.189.180.114 (114.180.189.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.189.180.114 (114.180.189.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 11:38:49.769278 2026] [security2:error] [pid 32702:tid 32711] [client 35.189.180.114:51544] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.artbox.cibernetic.com"] [uri "/@fs/src/.env"] [unique_id "aqAsCbko9nTiG42FJdn8CwAAAMY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 15:14:14
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.189.180.114 (114.180.189.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.189.180.114 (114.180.189.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 11:14:07.716000 2026] [security2:error] [pid 19507:tid 19507] [client 35.189.180.114:52768] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.interartny.com"] [uri "/@fs/.env"] [unique_id "aqAmP0AwgGisrn3nxsIWiAAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇦🇺
AWW-Admin
2026-09-08 15:07:00
(4 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 35.189.180.114 (TW/Taiwan/114.180.189.3 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 35.189.180.114 (TW/Taiwan/114.180.189.35.bc.googleusercontent.com)
show less
SQL Injection
🇩🇪
onlyops.app
2026-09-08 15:00:09
(4 hours ago)
Web application firewall (ModSecurity) detected malicious traffic | detected by Fail2Ban (plesk-mods ...
show more
Web application firewall (ModSecurity) detected malicious traffic | detected by Fail2Ban (plesk-modsecurity jail) | onlyops.app
show less
Exploited Host
🇨🇭
backslash
2026-09-08 14:51:00
(4 hours ago)
block ruleset bad bot: misc bad content F608233CC4C86EE814CE8DDDA9C4A0D3C79882F6
Bad Web Bot
🇳🇱
Savvii
2026-09-08 14:48:29
(4 hours ago)
20 attempts against mh_ha-misbehave-ban on yeti
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 14:47:57
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.189.180.114 (114.180.189.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.189.180.114 (114.180.189.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 10:47:51.642173 2026] [security2:error] [pid 32199:tid 32199] [client 35.189.180.114:58732] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.spaceritual.net"] [uri "/@fs/app/.env"] [unique_id "aqAgFzIlx-oQlizUsHM4yQAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇴
jad-abuse
2026-09-08 14:18:02
(5 hours ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: env_probe ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: env_probe, aws_creds, source_backup, path_traversal, ssh_keys, ai_secrets, git_exposure, config_backup. Observed by 1 sensor(s); 372 hits.
show less
Hacking
Web App Attack
Anonymous
2026-09-08 14:05:27
(5 hours ago)
Aggressive web scan
Web App Attack