๐ณ๐ฑ
Mangelot Hosting
2026-08-27 22:28:44
(7 minutes ago)
(modsecurity) srv103 ModSecurity 35.196.34.124 (US/United States/124.34.196.35.bc.googleusercontent. ...
show more
(modsecurity) srv103 ModSecurity 35.196.34.124 (US/United States/124.34.196.35.bc.googleusercontent.com): 30 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
Anonymous
2026-08-27 22:22:52
(13 minutes ago)
35.196.34.124 - - [28/Aug/2026:00:22:10 +0200] "GET HTTP/1.1" 403 1852 "-" "Mozilla/5.0 AppleWebKit ...
show more
35.196.34.124 - - [28/Aug/2026:00:22:10 +0200] "GET HTTP/1.1" 403 1852 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; LinkedInBot/1.0; +http://www.linkedin.com"
show less
Web Spam
Blog Spam
Brute-Force
Web App Attack
๐ณ๐ฑ
Alboweb B.V.
2026-08-27 22:11:10
(25 minutes ago)
Bad web bot activity detected by Fail2Ban in plesk-apache-badbot jail
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-08-27 21:41:25
(55 minutes ago)
(mod_security) mod_security (id:210492) triggered by 35.196.34.124 (124.34.196.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.196.34.124 (124.34.196.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 17:41:17.627647 2026] [security2:error] [pid 9715:tid 9715] [client 35.196.34.124:41156] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.ralserve.net"] [uri "/@fs/.env"] [unique_id "apCu_fISU5fDKnfD7A65zQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
WellSpring
2026-08-27 21:27:40
(1 hour ago)
env leak on 574.today/@fs/usr/src/app/.env โ WellSpr.ing/NetSentinel civic-AI security layer
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 21:23:06
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 35.196.34.124 (124.34.196.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.196.34.124 (124.34.196.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 17:23:01.450709 2026] [security2:error] [pid 19609:tid 19609] [client 35.196.34.124:21022] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ltrinc.com"] [uri "/@fs/root/.env"] [unique_id "apCqtd0QjMEsacNdCLr7EAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 20:49:04
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 35.196.34.124 (124.34.196.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.196.34.124 (124.34.196.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 16:49:00.420369 2026] [security2:error] [pid 15656:tid 15656] [client 35.196.34.124:54958] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.generationedm.com"] [uri "/@fs/root/.env"] [unique_id "apCivGsGtSirjsrIkrycRAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 20:29:07
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.196.34.124 (124.34.196.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.196.34.124 (124.34.196.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 16:29:00.827446 2026] [security2:error] [pid 24654:tid 24654] [client 35.196.34.124:50396] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.lawson-insurance.com"] [uri "/@fs/root/.env"] [unique_id "apCeDFobLdGPUU6IN25mQwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 20:07:03
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.196.34.124 (124.34.196.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.196.34.124 (124.34.196.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 16:06:57.882389 2026] [security2:error] [pid 3364195:tid 3364278] [client 35.196.34.124:21098] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.property-management.company"] [uri "/@fs/../../.env"] [unique_id "apCY4aE9v3ZLmkSxwf5f3gAAAYw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-08-27 19:45:10
(2 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
Anonymous
2026-08-27 19:36:16
(3 hours ago)
Multiple web server 400 error codes from same source ip
Web App Attack
๐ฉ๐ช
Hazzard
2026-08-27 19:35:19
(3 hours ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted]): (CF_ENABLE)
Bad Web Bot
๐จ๐ญ
Origon
2026-08-27 19:35:11
(3 hours ago)
http-probing - IP: 35.196.34.124 - time="2026-08-27T21:35:11+02:00" level=info msg="(555f66b4f6a745 ...
show more
http-probing - IP: 35.196.34.124 - time="2026-08-27T21:35:11+02:00" level=info msg="(555f66b4f6a74558bc11e3f93469658es8App0Mcc0TKEeje/crowdsec) crowdsecurity/http-probing by ip 35.196.34.124 (US/396982) : 4h ban on Ip 35.196.34.124" module=db
show less
Web App Attack
๐ณ๐ฑ
maxxsense
2026-08-27 19:03:52
(3 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 35.196.34.124 (US/United States/124.34. ...
show more
(mod_security) mod_security triggered on hostname [redacted] 35.196.34.124 (US/United States/124.34.196.35.bc.googleusercontent.com)
show less
SQL Injection
๐ฆ๐บ
2000cn.com.au
2026-08-27 19:02:22
(3 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking