🇳🇱
WeCloudit-Anti-Abuse
2026-09-06 04:35:45
(15 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇩🇪
todix
2026-09-06 03:35:48
(16 hours ago)
Web App Attack Exploid from 35.194.195.85
Web App Attack
🇳🇱
Mangelot Hosting
2026-09-06 03:33:12
(16 hours ago)
(wp_config_access) srv103 WordPress wp-config Scan 35.194.195.85 (TW/Taiwan/85.195.194.35.bc.googleu ...
show more
(wp_config_access) srv103 WordPress wp-config Scan 35.194.195.85 (TW/Taiwan/85.195.194.35.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
🇬🇧
consul.to
2026-09-06 02:37:42
(17 hours ago)
Web attack/malicious scanning detected
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 02:35:41
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.194.195.85 (85.195.194.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.194.195.85 (85.195.194.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:35:33.600560 2026] [security2:error] [pid 13265:tid 13265] [client 35.194.195.85:33178] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "flemingtonmartins.com"] [uri "/.env.example"] [unique_id "apzRdVBWi4vldavdKe-92AAAAIA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-06 01:58:22
(18 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
🇳🇱
e.fierstra
2026-09-06 01:26:32
(19 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 01:09:15
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.194.195.85 (85.195.194.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.194.195.85 (85.195.194.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 21:09:11.416791 2026] [security2:error] [pid 24656:tid 24656] [client 35.194.195.85:40698] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "convtek.com"] [uri "/.env.save"] [unique_id "apy9N9z5bvPVVzbVVFLQkAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇪🇸
alferez
2026-09-06 00:33:22
(19 hours ago)
Searching .(env|sql|zip|tar|rar) files
Hacking
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 22:59:27
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.194.195.85 (85.195.194.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.194.195.85 (85.195.194.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 18:59:21.273113 2026] [security2:error] [pid 28223:tid 28223] [client 35.194.195.85:43568] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.interartny.com"] [uri "/.env.backup"] [unique_id "apyeyfhkovEjsXGaM4rI4AAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
4server
2026-09-05 22:36:58
(21 hours ago)
[SunSep0600:36:53.0355492026][security2:error][pid2094171:tid2094227][client35.194.195.85:0]ModSecur ...
show more
[SunSep0600:36:53.0355492026][security2:error][pid2094171:tid2094227][client35.194.195.85:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(\?:/\(\?:\^\|/\)\\\\\\\\.\(env\|git\|svn\|hg\|DS_Store\)\|/\(\?:wp-config\|\\\\\\\\.htaccess\|\\\\\\\\.htpasswd\)\|\\\\\\\\.\(\?:sql\|bak\|old\|log\)\$\)\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"156\"][id\"960720\"][msg\"Forbiddenfileaccessattempt\"][severity\"CRITICAL\"][hostname\"giuliani.li.136-243-54-122.cpanel.site\"][uri\"/.env.bak\"][unique_id\"apyZhSqJI7hfSTl6FAcBoQAAAJg\"]
show less
Port Scan
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 22:36:55
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.194.195.85 (85.195.194.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.194.195.85 (85.195.194.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 18:36:47.151723 2026] [security2:error] [pid 1602:tid 1602] [client 35.194.195.85:56266] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fundingworkingcapital.internetnameregistration.com"] [uri "/.env"] [unique_id "apyZf_LYqhkUlrT0fj201wAAACg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
wlt-blocker
2026-09-05 21:56:54
(22 hours ago)
Unauthorized access to webpage admin
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 21:45:05
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.194.195.85 (85.195.194.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.194.195.85 (85.195.194.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 17:44:57.791575 2026] [security2:error] [pid 31210:tid 31210] [client 35.194.195.85:51100] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "railfanfromseo.powerlinemultimedia.net"] [uri "/.env.dev"] [unique_id "apyNWQtLIAaaiHE0_dUsCQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 21:26:53
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.194.195.85 (85.195.194.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.194.195.85 (85.195.194.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 17:26:49.477890 2026] [security2:error] [pid 32609:tid 32609] [client 35.194.195.85:59394] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "aticom.net"] [uri "/.env.prod"] [unique_id "apyJGXDNgltYIFc9hGlI2gAAACU"]
show less
Brute-Force
Bad Web Bot
Web App Attack