🇿🇦
conure.sh
2026-08-29 12:01:51
(3 days ago)
csagent: score 20.5: secrets grab x2, 404 noise floor x2; 1 domain(s) in 0s
Web App Attack
🇺🇸
TPI-Abuse
2026-08-29 00:57:07
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 35.190.139.254 (254.139.190.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.190.139.254 (254.139.190.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 20:56:57.776481 2026] [security2:error] [pid 1533:tid 1533] [client 35.190.139.254:55240] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.bernsteinip.com"] [uri "/.env.example"] [unique_id "apIuWUSM21BAtIY2xBvO9AAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Nevermind
2026-08-28 23:46:07
(4 days ago)
35.190.139.254 - - [29/Aug/2026:01:46:07 +0200] "GET /.env.local HTTP/1.1" 403 6283 "-" "crusader-wo ...
show more
35.190.139.254 - - [29/Aug/2026:01:46:07 +0200] "GET /.env.local HTTP/1.1" 403 6283 "-" "crusader-worker/1.0"
35.190.139.254 - - [29/Aug/2026:01:46:07 +0200] "GET /.env.save HTTP/1.1" 403 6283 "-" "crusader-worker/1.0"
35.190.139.254 - - [29/Aug/2026:01:46:07 +0200] "GET /.env.prod HTTP/1.1" 403 6283 "-" "crusader-worker/1.0"
35.190.139.254 - - [29/Aug/2026:01:46:07 +0200] "GET /.env.backup HTTP/1.1" 403 6283 "-" "crusader-worker/1.0"
...
show less
Web App Attack
🇩🇪
macrob
2026-08-28 23:06:28
(4 days ago)
2026/08/28 23:06:27 [error] 4017416#4017416: *531612016 access forbidden by rule, client: 35.190.139 ...
show more
2026/08/28 23:06:27 [error] 4017416#4017416: *531612016 access forbidden by rule, client: 35.190.139.254, server: fn.binixo.es, request: "GET /.env.prod HTTP/2.0", host: "a.fastcredit.net.ua"
2026/08/28 23:06:27 [error] 4017415#4017415: *531612017 access forbidden by rule, client: 35.190.139.254, server: fn.binixo.es, request: "GET /.env.bak HTTP/2.0", host: "a.fastcredit.net.ua"
2026/08/28 23:06:27 [error] 4017415#4017415: *531612018 access forbidden by rule, client: 35.190.139.254, server: fn.binixo.es, request: "GET /.env.production HTTP/2.0", host: "a.fastcredit.net.ua"
...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-08-28 22:31:30
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 35.190.139.254 (254.139.190.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.190.139.254 (254.139.190.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 18:31:24.429242 2026] [security2:error] [pid 3810:tid 3810] [client 35.190.139.254:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.abdulhameeds.art"] [uri "/.env.example"] [unique_id "apIMPNa4dMl-PZQJ5r5BCAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
Lee Daniel
2026-08-28 22:12:14
(4 days ago)
35.190.139.254 - - [28/Aug/2026:18:12:14 -0400] "GET /.env HTTP/1.1" 403 6363 "-" "crusader-worker/1 ...
show more
35.190.139.254 - - [28/Aug/2026:18:12:14 -0400] "GET /.env HTTP/1.1" 403 6363 "-" "crusader-worker/1.0"
...
show less
DDoS Attack
Web Spam
Email Spam
Port Scan
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
homeshowdomain.nl
2026-08-28 22:02:51
(4 days ago)
Auto-ban: >3000 req/min op 2026-08-28
Web App Attack
SSH
Hacking
🇮🇹
Inartis
2026-08-28 21:55:43
(4 days ago)
35.190.139.254 - - [28/Aug/2026:23:55:42 +0200] "GET /.env.example HTTP/1.1" 403 5575 "-" "crusader- ...
show more
35.190.139.254 - - [28/Aug/2026:23:55:42 +0200] "GET /.env.example HTTP/1.1" 403 5575 "-" "crusader-worker/1.0"
35.190.139.254 - - [28/Aug/2026:23:55:42 +0200] "GET /.env.backup HTTP/1.1" 403 5575 "-" "crusader-worker/1.0"
35.190.139.254 - - [28/Aug/2026:23:55:42 +0200] "GET /.env.dev HTTP/1.1" 403 5575 "-" "crusader-worker/1.0"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-28 21:53:30
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 35.190.139.254 (254.139.190.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.190.139.254 (254.139.190.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 17:53:24.202401 2026] [security2:error] [pid 3185:tid 3185] [client 35.190.139.254:54214] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "luckypupdesigns.com"] [uri "/.env.dev"] [unique_id "apIDVBI6L25advJT54auKQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
MyGlobalFlowers
2026-08-28 21:45:48
(4 days ago)
Multiple WAF Violations
Web App Attack
🇩🇪
4server
2026-08-28 20:59:26
(4 days ago)
[FriAug2822:59:24.4930852026][security2:error][pid3172729:tid3172750][client35.190.139.254:0]ModSecu ...
show more
[FriAug2822:59:24.4930852026][security2:error][pid3172729:tid3172750][client35.190.139.254:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(\?:/\(\?:\^\|/\)\\\\\\\\.\(env\|git\|svn\|hg\|DS_Store\)\|/\(\?:wp-config\|\\\\\\\\.htaccess\|\\\\\\\\.htpasswd\)\|\\\\\\\\.\(\?:sql\|bak\|old\|log\)\$\)\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"156\"][id\"960720\"][msg\"Forbiddenfileaccessattempt\"][severity\"CRITICAL\"][hostname\"risanamento-funghi-muffa.ch\"][uri\"/wp-config.php.bak\"][unique_id\"apH2rMhcS0o8vDMd5AOH4gAAAA4\"]
show less
Port Scan
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-08-28 20:44:45
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 35.190.139.254 (254.139.190.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.190.139.254 (254.139.190.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 16:44:39.005792 2026] [security2:error] [pid 26351:tid 26351] [client 35.190.139.254:60250] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.pinecasso.com"] [uri "/.env.local"] [unique_id "apHzN-hRmU2sO9ZmsVhowwAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
BlueWire Hosting
2026-08-28 20:15:36
(4 days ago)
High-confidence malicious configuration/VCS probe
Web App Attack
🇺🇸
TPI-Abuse
2026-08-28 18:45:27
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 35.190.139.254 (254.139.190.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.190.139.254 (254.139.190.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 14:45:23.071549 2026] [security2:error] [pid 7946:tid 7946] [client 35.190.139.254:49304] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "killarneypool.org"] [uri "/.env.bak"] [unique_id "apHXQ3fEW2-AW7gWXedrHAAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-28 17:50:05
(4 days ago)
| Suspicious URL access.
Web App Attack
Hacking
SQL Injection