๐บ๐ธ
TPI-Abuse
2026-08-01 17:12:18
(23 minutes ago)
(mod_security) mod_security (id:210492) triggered by 35.189.68.162 (162.68.189.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.189.68.162 (162.68.189.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 13:12:14.424975 2026] [security2:error] [pid 2613264:tid 2613264] [client 35.189.68.162:36164] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.jamiesbballpool.com"] [uri "/.env.example"] [unique_id "am4o7v7iaYwa5LEOqow1mwAAACw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
zynex
2026-08-01 16:35:12
(1 hour ago)
URL Probing: /.env
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 16:30:55
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 35.189.68.162 (162.68.189.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.189.68.162 (162.68.189.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 12:30:49.569582 2026] [security2:error] [pid 2272925:tid 2272925] [client 35.189.68.162:42622] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.amarrasdeescobar.com.cerrovictoria.com"] [uri "/.env.save"] [unique_id "am4fOV-wApfl1nVX0WMkjAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 15:47:26
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 35.189.68.162 (162.68.189.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.189.68.162 (162.68.189.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 11:47:21.376518 2026] [security2:error] [pid 1287440:tid 1287440] [client 35.189.68.162:49456] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.blog.mosherpit.com"] [uri "/.env.dev"] [unique_id "am4VCZGAo4tMKmvh05aEKwAAACQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
Inartis
2026-08-01 15:40:07
(1 hour ago)
35.189.68.162 - - [01/Aug/2026:17:40:06 +0200] "GET /.env.prod HTTP/1.1" 403 5575 "-" "crusader-work ...
show more
35.189.68.162 - - [01/Aug/2026:17:40:06 +0200] "GET /.env.prod HTTP/1.1" 403 5575 "-" "crusader-worker/1.0"
35.189.68.162 - - [01/Aug/2026:17:40:06 +0200] "GET /.env HTTP/1.1" 403 5575 "-" "crusader-worker/1.0"
35.189.68.162 - - [01/Aug/2026:17:40:06 +0200] "GET /.env.old HTTP/1.1" 403 5575 "-" "crusader-worker/1.0"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
antlac1
2026-08-01 15:13:25
(2 hours ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
๐ช๐ธ
masterguru
2026-08-01 15:11:46
(2 hours ago)
Inbound Anomaly Score Exceeded (Total Score: 5). Operator GE matched 5 at TX:anomaly_score. (949110- ...
show more
Inbound Anomaly Score Exceeded (Total Score: 5). Operator GE matched 5 at TX:anomaly_score. (949110-122)
show less
Hacking
๐ฉ๐ช
Bedios GmbH
2026-08-01 15:03:30
(2 hours ago)
Login credentials theft attempt
Hacking
๐จ๐ฆ
Blinker73
2026-08-01 14:51:34
(2 hours ago)
35.189.68.162 - - [01/Aug/2026:10:51:33 -0400] "GET /.env.dev HTTP/1.1" 301 162 "-" "crusader-worker ...
show more
35.189.68.162 - - [01/Aug/2026:10:51:33 -0400] "GET /.env.dev HTTP/1.1" 301 162 "-" "crusader-worker/1.0"
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 14:39:46
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.189.68.162 (162.68.189.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.189.68.162 (162.68.189.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 10:39:41.360091 2026] [security2:error] [pid 508021:tid 508021] [client 35.189.68.162:43562] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "travelsupersonic.com"] [uri "/.env.prod"] [unique_id "am4FLT6-LrSyX-ryvJ2JhAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
SilverZippo
2026-08-01 14:13:48
(3 hours ago)
Web App Attack
Web App Attack
๐ฉ๐ช
LRob
2026-08-01 14:06:02
(3 hours ago)
CrowdSec: crowdsecurity/http-sensitive-files | req: /.env.prod | 5 distinct paths | UA: crusader-wor ...
show more
CrowdSec: crowdsecurity/http-sensitive-files | req: /.env.prod | 5 distinct paths | UA: crusader-worker/1.0
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-01 13:52:07
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.189.68.162 (162.68.189.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.189.68.162 (162.68.189.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 09:52:00.898739 2026] [security2:error] [pid 24999:tid 24999] [client 35.189.68.162:35446] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.jtdieselparts.mainstreetofficesuites.com"] [uri "/.env.backup"] [unique_id "am36AHJVKn94z-HoIeKUDQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-08-01 13:31:41
(4 hours ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 13:16:26
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.189.68.162 (162.68.189.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.189.68.162 (162.68.189.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 09:16:22.938736 2026] [security2:error] [pid 29878:tid 29878] [client 35.189.68.162:40986] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "eclipsesoftware.biz"] [uri "/.env.example"] [unique_id "am3xpuXzgomIZ9DCc-e2LQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack