🇺🇸
mnsf
2026-09-04 12:05:15
(1 minute ago)
Scanning/Probing (30)
Brute-Force
Web App Attack
Anonymous
2026-09-04 11:49:55
(17 minutes ago)
[04/Sep/2026:11:49:55 +0000] host=lovelyrender.app server=lovelyrender.app ip=35.194.100.37 method=G ...
show more
[04/Sep/2026:11:49:55 +0000] host=lovelyrender.app server=lovelyrender.app ip=35.194.100.37 method=GET req=/.env uri=/index.php status=302 bytes=5 rt=0.052 urt=0.052 ref="-" ua="crusader-worker/1.0"
...
show less
Web App Attack
Bad Web Bot
🇩🇪
FeG Deutschland
2026-09-04 11:47:08
(20 minutes ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 11:44:49
(22 minutes ago)
(mod_security) mod_security (id:210492) triggered by 35.194.100.37 (37.100.194.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.194.100.37 (37.100.194.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 07:44:44.290852 2026] [security2:error] [pid 10289:tid 10289] [client 35.194.100.37:38752] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.frank-klimas.com"] [uri "/wp-config.php~"] [unique_id "apqvLLTEKGJqEf0fWcG2uQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
raph
2026-09-04 11:01:48
(1 hour ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack
🇸🇪
vaia.cloud
2026-09-04 11:00:06
(1 hour ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 10:56:50
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 35.194.100.37 (37.100.194.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.194.100.37 (37.100.194.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:56:46.316460 2026] [security2:error] [pid 1232:tid 1232] [client 35.194.100.37:57360] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bnaiisraelkearny.com"] [uri "/.env"] [unique_id "apqj7jwZ4jjaEITJrm4ChQAAACs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 10:09:48
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 35.194.100.37 (37.100.194.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.194.100.37 (37.100.194.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:09:43.591613 2026] [security2:error] [pid 31754:tid 31754] [client 35.194.100.37:39554] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jeffreycopeland.com"] [uri "/wp-config.php~"] [unique_id "apqY5__jUWBJgBObIRK8bQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-04 09:35:16
(2 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-04 09:22:40
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.194.100.37 (37.100.194.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.194.100.37 (37.100.194.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 05:22:36.661497 2026] [security2:error] [pid 11446:tid 11446] [client 35.194.100.37:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lxr.365soft.top"] [uri "/.env"] [unique_id "apqN3FTi_f2SqI2yM4uvPAAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇦
polycoda
2026-09-04 08:26:11
(3 hours ago)
AutoBlock: 🎯 Vulnerability Scanner (Non Decay-Based)
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 08:16:56
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.194.100.37 (37.100.194.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.194.100.37 (37.100.194.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 04:16:48.972916 2026] [security2:error] [pid 20141:tid 20141] [client 35.194.100.37:35390] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.zeet.es"] [uri "/wp-config.php~"] [unique_id "app-cGqWNiCc0_4YQTi4dAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
masterguru
2026-09-04 07:43:18
(4 hours ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-193)
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 07:43:00
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.194.100.37 (37.100.194.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.194.100.37 (37.100.194.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 03:42:55.103909 2026] [security2:error] [pid 13640:tid 13640] [client 35.194.100.37:38336] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "garretthillary.com"] [uri "/.env"] [unique_id "app2fyYirnxynZmuOSgBZwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 07:23:30
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.194.100.37 (37.100.194.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.194.100.37 (37.100.194.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 03:23:22.134909 2026] [security2:error] [pid 16561:tid 16561] [client 35.194.100.37:46074] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "northmyrtlebeachcondos.com"] [uri "/.env.save"] [unique_id "appx6rXhHvAjHpNgV76QSwAAACk"]
show less
Brute-Force
Bad Web Bot
Web App Attack