๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-08-28 18:41:22
(1 hour ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-28 18:35:01
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 35.196.127.124 (124.127.196.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.196.127.124 (124.127.196.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 14:34:51.079588 2026] [security2:error] [pid 13781:tid 13781] [client 35.196.127.124:33122] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.randlephoto.com.gregorii.com"] [uri "/.env.prod"] [unique_id "apHUy6WCP_j5ZyIkXvkiDQAAADg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 17:44:23
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 35.196.127.124 (124.127.196.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.196.127.124 (124.127.196.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 13:44:16.064086 2026] [security2:error] [pid 12251:tid 12251] [client 35.196.127.124:52356] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "viajeofdesign.bond"] [uri "/.env.dev"] [unique_id "apHI8FzSSZ8MzLkF3VH9twAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
NihiliousMonk
2026-08-28 17:30:24
(2 hours ago)
Fail2Ban report from jail npm-scanners
Bad Web Bot
Web App Attack
๐บ๐ธ
azminawwar
2026-08-28 17:02:44
(2 hours ago)
[35.196.127.124] triggered by honeypot on port [80], Timestamp [2026-08-28T17:02:43Z]METHOD=GET PATH ...
show more
[35.196.127.124] triggered by honeypot on port [80], Timestamp [2026-08-28T17:02:43Z]METHOD=GET PATH=/.env HTTP=HTTP/1.1 UA="crusader-worker/1.0" HOST="38.45.65.187" REF="-"
show less
Port Scan
Hacking
๐ซ๐ฎ
paissangroup
2026-08-28 16:41:42
(3 hours ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 16:33:30
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.196.127.124 (124.127.196.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.196.127.124 (124.127.196.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 12:33:25.945316 2026] [security2:error] [pid 25729:tid 25729] [client 35.196.127.124:42546] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "havilahmalone.com"] [uri "/.env"] [unique_id "apG4VcxpZ5Tdwr2oiBXGRQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-28 16:23:32
(3 hours ago)
(config_exploit_scan) Configuratie Scanner / Nep GPTBot 35.196.127.124 (US/United States/124.127.196 ...
show more
(config_exploit_scan) Configuratie Scanner / Nep GPTBot 35.196.127.124 (US/United States/124.127.196.35.bc.googleusercontent.com): 3 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 35.196.127.124 - - [28/Aug/2026:18:23:28 +0200] "GET /.env.backup HTTP/1.1" 406 4831 "-" "crusader-worker/1.0"
35.196.127.124 - - [28/Aug/2026:18:23:28 +0200] "GET /.env.bak HTTP/1.1" 406 4831 "-" "crusader-worker/1.0"
35.196.127.124 - - [28/Aug/2026:18:23:28 +0200] "GET /.env.production HTTP/1.1" 406 4831 "-" "crusader-worker/1.0"
show less
Port Scan
๐บ๐ธ
nyt
2026-08-28 16:12:18
(3 hours ago)
Sensitive File Probe, WP Config Probe
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-08-28 16:11:42
(3 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 15:45:57
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.196.127.124 (124.127.196.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.196.127.124 (124.127.196.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 11:45:52.210075 2026] [security2:error] [pid 10927:tid 10980] [client 35.196.127.124:57714] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.worldecom.aafm.us"] [uri "/.env.local"] [unique_id "apGtMIUXMKUZ2_QkMQ5A6QAAAcM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 15:19:42
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.196.127.124 (124.127.196.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.196.127.124 (124.127.196.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 11:19:37.735069 2026] [security2:error] [pid 22339:tid 22339] [client 35.196.127.124:60298] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.saudigreenrecycling.com"] [uri "/.env.example"] [unique_id "apGnCSATq7uEZmwFvQaRFgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
UnixPrime
2026-08-28 15:18:38
(4 hours ago)
35.196.127.124 - - [28/Aug/2026:17:18:37 +0200] "GET /.env.bak HTTP/1.1" 404 146 "-" "crusader-worke ...
show more
35.196.127.124 - - [28/Aug/2026:17:18:37 +0200] "GET /.env.bak HTTP/1.1" 404 146 "-" "crusader-worker/1.0"
35.196.127.124 - - [28/Aug/2026:17:18:37 +0200] "GET /.env.example HTTP/1.1" 404 146 "-" "crusader-worker/1.0"
...
show less
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-08-28 14:52:20
(4 hours ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 14:37:40
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.196.127.124 (124.127.196.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.196.127.124 (124.127.196.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 10:37:34.223927 2026] [security2:error] [pid 6466:tid 6466] [client 35.196.127.124:49728] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lahamradio.com"] [uri "/.env.save"] [unique_id "apGdLp_TCMZINmXVEGtu6gAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack