🇫🇮
danskefilm.dk
2026-09-04 15:00:01
(4 hours ago)
wordpress login attempts
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 14:48:23
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.199.126.198 (198.126.199.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.199.126.198 (198.126.199.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 10:48:18.722643 2026] [security2:error] [pid 14855:tid 14855] [client 35.199.126.198:56890] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cgautomatizacion.com"] [uri "/.env.bak"] [unique_id "apraMvJnVh26L6lRlkyCcAAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
wlt-blocker
2026-09-04 14:37:52
(4 hours ago)
Unauthorized access to webpage admin
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 14:12:00
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.199.126.198 (198.126.199.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.199.126.198 (198.126.199.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 10:11:52.102757 2026] [security2:error] [pid 23004:tid 23139] [client 35.199.126.198:43606] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.annthornycroft.com"] [uri "/.env"] [unique_id "aprRqM4Kl8MzvCwEZxJ4YAAAAJA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 11:55:01
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.199.126.198 (198.126.199.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.199.126.198 (198.126.199.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 07:54:56.494687 2026] [security2:error] [pid 15179:tid 15179] [client 35.199.126.198:55882] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "streetfightfilm.com"] [uri "/.env.old"] [unique_id "apqxkG5zF9E1wFuW2AM3twAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 11:17:21
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.199.126.198 (198.126.199.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.199.126.198 (198.126.199.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 07:17:16.492209 2026] [security2:error] [pid 8789:tid 8789] [client 35.199.126.198:49068] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.barigby.com"] [uri "/.env.prod"] [unique_id "apqovMxXSSpiNnrXCZhC2AAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
mnsf
2026-09-04 11:05:57
(7 hours ago)
Scanning/Probing (20)
Brute-Force
Web App Attack
🇬🇧
consul.to
2026-09-04 10:39:14
(8 hours ago)
Web attack/malicious scanning detected
Web App Attack
🇫🇷
masterguru
2026-09-04 10:23:29
(8 hours ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 35.199.126.198 (BR/Brazil/198.126.199 ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 35.199.126.198 (BR/Brazil/198.126.199.35.bc.googleusercontent.com): 2 in the last 3600 secs (0-196)
show less
Hacking
🇺🇸
TPI-Abuse
2026-09-04 10:22:13
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.199.126.198 (198.126.199.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.199.126.198 (198.126.199.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:22:04.968330 2026] [security2:error] [pid 19893:tid 19893] [client 35.199.126.198:55586] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "notimallinckrodt.com.ar.misterflores.com"] [uri "/.env"] [unique_id "apqbzFNQXr_atf9nxEOwPwAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 10:06:24
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.199.126.198 (198.126.199.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.199.126.198 (198.126.199.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:06:18.793873 2026] [security2:error] [pid 22621:tid 22621] [client 35.199.126.198:46938] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.pandahh.com"] [uri "/.env.save"] [unique_id "apqYGjSIiqFqCkbkQRKErQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
mail.avx.gr
2026-09-04 10:06:12
(8 hours ago)
(nginxENVSCAN) nginx environment-file scanner detected from 35.199.126.198 (BR/Brazil/São Paulo/São ...
show more
(nginxENVSCAN) nginx environment-file scanner detected from 35.199.126.198 (BR/Brazil/São Paulo/São Paulo/198.126.199.35.bc.googleusercontent.com)
show less
Hacking
🇹🇼
kk_it_man
2026-09-04 09:13:03
(9 hours ago)
ET INFO Request to Hidden Environment File - Inbound
ET WEB_SERVER Tilde in URI - potential .php~ ...
show more
ET INFO Request to Hidden Environment File - Inbound
ET WEB_SERVER Tilde in URI - potential .php~ source disclosure vulnerability
show less
Port Scan
🇫🇷
masterguru
2026-09-04 08:29:20
(10 hours ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-193)
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 07:52:07
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.199.126.198 (198.126.199.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.199.126.198 (198.126.199.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 03:52:00.124720 2026] [security2:error] [pid 10309:tid 10309] [client 35.199.126.198:49958] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "synergystudios.org"] [uri "/.env.local"] [unique_id "app4oHmcV76rJFzNDIUXSwAAADo"]
show less
Brute-Force
Bad Web Bot
Web App Attack