🇩🇪
grassau.com
2026-09-06 13:54:56
(4 hours ago)
*Port Scan* detected from 35.196.229.193 (US/United States/South Carolina/North Charleston/193.229.1 ...
show more
*Port Scan* detected from 35.196.229.193 (US/United States/South Carolina/North Charleston/193.229.196.35.bc.googleusercontent.com).
show less
Port Scan
🇧🇷
SOC-BR
2026-09-06 07:25:29
(11 hours ago)
Attack detected by Fortinet - applications3: Spring.Boot.Actuator.Unauthorized.Access - 2026-09-05 2 ...
show more
Attack detected by Fortinet - applications3: Spring.Boot.Actuator.Unauthorized.Access - 2026-09-05 23:44:24 - Source Port 55496
show less
Port Scan
Hacking
Anonymous
2026-09-06 06:22:38
(12 hours ago)
Web application attack detected.
Web App Attack
🇬🇧
openstrike.co.uk
2026-09-06 05:12:59
(13 hours ago)
13 attacks on env grabbing URLs, PHP URLs:
GET /.env HTTP/1.1
GET /wp-config.php~ HTTP/1.1
Hacking
Web App Attack
🇩🇪
FD-IX
2026-09-06 03:24:53
(15 hours ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 03:00:55
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.196.229.193 (193.229.196.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.196.229.193 (193.229.196.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:00:49.524238 2026] [security2:error] [pid 27548:tid 27548] [client 35.196.229.193:59190] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.cassandramari.com"] [uri "/.env"] [unique_id "apzXYU4mUNnYqHP363GEAgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 02:31:07
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.196.229.193 (193.229.196.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.196.229.193 (193.229.196.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:31:02.609489 2026] [security2:error] [pid 15087:tid 15087] [client 35.196.229.193:55616] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sircain.net"] [uri "/.env"] [unique_id "apzQZjlaGKvy2HRLiqKH8wAAAEM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
dynamix
2026-09-06 02:24:34
(16 hours ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 01:49:48
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.196.229.193 (193.229.196.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.196.229.193 (193.229.196.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 21:49:43.630614 2026] [security2:error] [pid 15045:tid 15045] [client 35.196.229.193:37680] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ryanlowenstein.com"] [uri "/.env.dev"] [unique_id "apzGt_JtZ7vub8qOditAyAAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇪
AutosOnShow
2026-09-06 01:25:06
(17 hours ago)
blocked for webapp attack | path requested: / | seen at 2026-09-06 01:24:36.012 |
Web App Attack
🇩🇪
paissangroup
2026-09-06 01:21:30
(17 hours ago)
Multiple WAF Violations
Web App Attack
🇮🇹
Inartis
2026-09-06 00:42:23
(17 hours ago)
35.196.229.193 - - [06/Sep/2026:02:42:22 +0200] "GET /.env.save HTTP/1.1" 302 5234 "-" "crusader-wor ...
show more
35.196.229.193 - - [06/Sep/2026:02:42:22 +0200] "GET /.env.save HTTP/1.1" 302 5234 "-" "crusader-worker/1.0"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 00:40:42
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.196.229.193 (193.229.196.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.196.229.193 (193.229.196.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 20:40:36.286273 2026] [security2:error] [pid 7085:tid 7085] [client 35.196.229.193:56188] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hometechllc.com"] [uri "/.env.save"] [unique_id "apy2hE7dqyM9Z09qeq4RyQAAADw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 00:02:29
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.196.229.193 (193.229.196.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.196.229.193 (193.229.196.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 20:02:23.145859 2026] [security2:error] [pid 30389:tid 30389] [client 35.196.229.193:38750] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jewers.org"] [uri "/.env.prod"] [unique_id "apytj7oaxe9OMR3sKXOnIAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
e.fierstra
2026-09-05 22:54:28
(19 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack