๐ณ๐ฑ
Site.eu
2026-08-29 19:32:55
(2 days ago)
Excessive multi-domain requests
Brute-Force
๐บ๐ธ
mnsf
2026-08-29 00:08:22
(3 days ago)
Scanning/Probing (28)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 14:37:53
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 35.196.102.27 (27.102.196.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.196.102.27 (27.102.196.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 10:37:49.406803 2026] [security2:error] [pid 9035:tid 9141] [client 35.196.102.27:41880] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.stephaniemoody.com"] [uri "/@fs/app/.env"] [unique_id "apGdPcTzecUd1UvOSE8RgQAAAMk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Petros Stefanakis
2026-08-28 13:52:16
(4 days ago)
(mod_security) mod_security triggered on hostname [redacted] 35.196.102.27 (US/United States/27.102. ...
show more
(mod_security) mod_security triggered on hostname [redacted] 35.196.102.27 (US/United States/27.102.196.35.bc.googleusercontent.com)
show less
SQL Injection
๐จ๐ญ
4server
2026-08-28 13:12:58
(4 days ago)
[FriAug2815:12:55.3691962026][security2:error][pid1503591:tid1503935][client35.196.102.27:0]ModSecur ...
show more
[FriAug2815:12:55.3691962026][security2:error][pid1503591:tid1503935][client35.196.102.27:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".env\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"610\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"cpcalendars.aid-web.ch\"][uri\"/@fs/.env\"][unique_id\"apGJV_4Wq-Ctgf1sv6r-gAAAANg\"]
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 13:07:06
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 35.196.102.27 (27.102.196.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.196.102.27 (27.102.196.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 09:07:01.814489 2026] [security2:error] [pid 6080:tid 6080] [client 35.196.102.27:16894] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.robhoward.me"] [uri "/@fs/.env"] [unique_id "apGH9YBGnuA0CBCbucwOCwAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-28 12:23:45
(4 days ago)
Multiple web server 400 error codes from same source ip
Web App Attack
๐ณ๐ฑ
middelkoopcc
2026-08-28 11:59:01
(4 days ago)
2026-08-28 13:57:19 GET /@fs/..%252f..%252f..%252f..%252f..%252fapp/.env?raw?? [404] && 2026-08-28 1 ...
show more
2026-08-28 13:57:19 GET /@fs/..%252f..%252f..%252f..%252f..%252fapp/.env?raw?? [404] && 2026-08-28 13:57:19 GET /@fs/app/rootkey.csv?raw?? [404] && 2026-08-28 13:57:19 GET /@fs/home/admin/.aws/credentials?raw?? [404] && 115 more within 20 minutes
show less
Web App Attack
๐ณ๐ฑ
ConsulHosting
2026-08-28 10:36:35
(4 days ago)
Automatically blocked due to distributed attack
Hacking
๐ฉ๐ช
yitzhaq
2026-08-28 09:58:10
(4 days ago)
[site]:443 35.196.102.27 - - [28/Aug/2026:11:58:06 +0200] "GET /@fs/home/ec2-user/.aws/credentials?r ...
show more
[site]:443 35.196.102.27 - - [28/Aug/2026:11:58:06 +0200] "GET /@fs/home/ec2-user/.aws/credentials?raw?? HTTP/1.1" 503 905 "-" "Mozilla/5.0 (compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot)"
[site]:443 35.196.102.27 - - [28/Aug/2026:11:58:06 +0200] "GET /@fs/root/.aws/credentials.bak?raw?? HTTP/1.1" 503 905 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot"
[site]:443 35.196.102.27 - - [28/Aug/2026:11:58:06 +0200] "GET /@fs/home/debian/.aws/credentials?raw?? HTTP/1.1" 503 905 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot"
[site]:443 35.196.102.27 - - [28/Aug/2026:11:58:06 +0200] "GET /@fs/..%252f..%252f..%252f..%252f..%252fapp/.env?raw?? HTTP/1.1" 503 905 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.2402.27 Safari/537.36; compatible; LinkedInBot/1.0; +http://www.linkedin.com"
[s
show less
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-28 08:51:37
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 35.196.102.27 (27.102.196.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.196.102.27 (27.102.196.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 04:51:31.159375 2026] [security2:error] [pid 12290:tid 12290] [client 35.196.102.27:30766] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.rotarymagnetics.com"] [uri "/@fs/.env"] [unique_id "apFME49sWZK8FfcMyy777wAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 07:07:40
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 35.196.102.27 (27.102.196.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.196.102.27 (27.102.196.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 03:07:32.695149 2026] [security2:error] [pid 3237:tid 3239] [client 35.196.102.27:60536] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.jupitermaturin.com.venezuelaguia.com"] [uri "/@fs/.env"] [unique_id "apEztHC-VrC2Ff6I5UqU5AAAAIA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 06:24:37
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 35.196.102.27 (27.102.196.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.196.102.27 (27.102.196.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 02:24:32.195319 2026] [security2:error] [pid 18429:tid 18429] [client 35.196.102.27:22592] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.bigheartskitchen.com"] [uri "/@fs/app/.env"] [unique_id "apEpoCNuG43f4QPIEYNhAAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 06:07:31
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 35.196.102.27 (27.102.196.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.196.102.27 (27.102.196.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 02:07:26.270959 2026] [security2:error] [pid 15096:tid 15096] [client 35.196.102.27:1304] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.esneuro.net"] [uri "/@fs/.env"] [unique_id "apElnhEezQTG6bLLt8688AAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 05:50:58
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 35.196.102.27 (27.102.196.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.196.102.27 (27.102.196.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 01:50:50.694726 2026] [security2:error] [pid 18164:tid 18164] [client 35.196.102.27:11476] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.webuydinwiddiehouses.com"] [uri "/@fs/app/.env"] [unique_id "apEhumkbfz-SX5-tst4k5gAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack