🇺🇸
factor1
2026-09-09 18:29:55
(1 hour ago)
CrowdSec at apollo Reports Abuse
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 18:13:34
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 35.196.181.242 (242.181.196.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.196.181.242 (242.181.196.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 14:13:28.166079 2026] [security2:error] [pid 30750:tid 30750] [client 35.196.181.242:11528] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.gfsprod.com"] [uri "/@fs/../../.env"] [unique_id "aqGhyMjzJtEAR-oaDNzoQwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
mnsf
2026-09-09 18:05:16
(1 hour ago)
Scanning/Probing (20)
Brute-Force
Web App Attack
Anonymous
2026-09-09 17:13:48
(2 hours ago)
Portscan: TCP/8080 (2x), TCP/8443 (2x), TCP/443, TCP/80
Port Scan
🇩🇪
LRob
2026-09-09 16:30:06
(3 hours ago)
Enumerating paths that do not exist (scanning) | method: GET | path: /@fs/root/.env (+6 more) | ua: ...
show more
Enumerating paths that do not exist (scanning) | method: GET | path: /@fs/root/.env (+6 more) | ua: Mozilla/5.0 (iPhone; CPU iPhone OS 17_5 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko; compatible; Twitterbot/1.0) Vers (+6 more) | 2026-09-09 16:30 UTC
show less
Port Scan
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 15:37:20
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.196.181.242 (242.181.196.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.196.181.242 (242.181.196.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 11:37:14.903568 2026] [security2:error] [pid 16434:tid 16460] [client 35.196.181.242:45036] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.rosendalsateri.com"] [uri "/@fs/.env"] [unique_id "aqF9KpYPuQ9nRoAEXZ-44wAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
pm33
2026-09-09 15:13:52
(4 hours ago)
Excessive crawling HTTP 404
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 13:51:13
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.196.181.242 (242.181.196.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.196.181.242 (242.181.196.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 09:51:07.199009 2026] [security2:error] [pid 12939:tid 12939] [client 35.196.181.242:38506] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.cossey.me"] [uri "/@fs/app/.env"] [unique_id "aqFkS9Mu7Zawxnrl6eYEKgAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 12:40:46
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.196.181.242 (242.181.196.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.196.181.242 (242.181.196.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 08:40:40.012079 2026] [security2:error] [pid 17596:tid 17596] [client 35.196.181.242:43546] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.walkenfeld.com"] [uri "/@fs/.env.production"] [unique_id "aqFTyK4DXIOfz21P4VkL2AAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 11:32:05
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.196.181.242 (242.181.196.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.196.181.242 (242.181.196.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 07:32:01.804783 2026] [security2:error] [pid 25734:tid 25734] [client 35.196.181.242:3322] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.emilybrass.com"] [uri "/@fs/app/.env"] [unique_id "aqFDsfuVd7deHlupwKztMgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
FD-IX
2026-09-09 11:28:35
(8 hours ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 11:15:26
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.196.181.242 (242.181.196.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.196.181.242 (242.181.196.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 07:15:18.163064 2026] [security2:error] [pid 8116:tid 8116] [client 35.196.181.242:33002] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.sagebrush.us"] [uri "/@fs/.env"] [unique_id "aqE_xi_BFxlVsmBgWU4A8AAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇸🇪
vaia.cloud
2026-09-09 11:00:03
(8 hours ago)
crowdsecurity/http-probing
Brute-Force
Web App Attack
🇳🇱
debestelapp
2026-09-09 10:50:13
(8 hours ago)
Web App Attack
🇫🇷
masterguru
2026-09-09 10:40:39
(9 hours ago)
Restricted File Access Attempt. Matched phrase "/@fs/" at REQUEST_FILENAME. (930130-197)
Hacking
Web App Attack