Anonymous
2026-09-06 03:10:03
(1 hour ago)
| Suspicious URL access.
Web App Attack
Hacking
SQL Injection
🇬🇧
Aetherweb Ark
2026-09-06 02:31:54
(2 hours ago)
(mod_security) mod_security (id:949110) triggered by 35.196.81.247 (US/United States/247.81.196.35.b ...
show more
(mod_security) mod_security (id:949110) triggered by 35.196.81.247 (US/United States/247.81.196.35.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
🇫🇷
dynamix
2026-09-06 02:28:40
(2 hours ago)
Multiple WAF Violations
Web App Attack
🇩🇪
seal
2026-09-06 01:31:41
(3 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
SSH
Brute-Force
🇺🇸
TPI-Abuse
2026-09-06 01:09:52
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.196.81.247 (247.81.196.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.196.81.247 (247.81.196.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 21:09:44.366297 2026] [security2:error] [pid 1817:tid 1817] [client 35.196.81.247:39258] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.movafagh.com"] [uri "/wp-config.php~"] [unique_id "apy9WCRAmluV0tJBBjpIcgAAACc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Philister11
2026-09-06 00:06:38
(4 hours ago)
CrowdSec: crowdsecurity/http-probing (US/AS396982)
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-05 23:53:36
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.196.81.247 (247.81.196.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.196.81.247 (247.81.196.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 19:53:29.574001 2026] [security2:error] [pid 6983:tid 6983] [client 35.196.81.247:47086] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.megaandina.com"] [uri "/.env.local"] [unique_id "apyreSrUdz0whXeYquKgHgAAAEg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 23:22:07
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.196.81.247 (247.81.196.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.196.81.247 (247.81.196.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 19:22:01.764838 2026] [security2:error] [pid 24444:tid 24444] [client 35.196.81.247:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kryptonome.com"] [uri "/.env.dev"] [unique_id "apykGaUyJ2givruDy7daagAAAGs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 22:54:46
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.196.81.247 (247.81.196.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.196.81.247 (247.81.196.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 18:54:39.865033 2026] [security2:error] [pid 31420:tid 31420] [client 35.196.81.247:39964] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.shirtzz.com"] [uri "/.env.old"] [unique_id "apydr87TISIDgiomGS7FLAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-05 22:37:22
(6 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-05 22:16:31
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.196.81.247 (247.81.196.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.196.81.247 (247.81.196.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 18:16:27.735665 2026] [security2:error] [pid 10544:tid 10544] [client 35.196.81.247:52456] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "darkcodeverse.com.darkcodedesign.net"] [uri "/.env.old"] [unique_id "apyUu41NuooXz_r3lty2-gAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
COMAITE
2026-09-05 22:15:21
(6 hours ago)
Suspicious URL access.
Web App Attack
🇳🇴
jad-abuse
2026-09-05 22:06:34
(6 hours ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: ai_secret ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: ai_secrets, env_probe. Observed by 1 sensor(s); 20 hits.
show less
Web App Attack
🇮🇹
VHosting
2026-09-05 22:05:03
(6 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇦🇺
AWW-Admin
2026-09-05 21:55:09
(7 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 35.196.81.247 (US/United States/247.81. ...
show more
(mod_security) mod_security triggered on hostname [redacted] 35.196.81.247 (US/United States/247.81.196.35.bc.googleusercontent.com)
show less
SQL Injection