🇿🇦
conure.sh
2026-08-29 12:01:44
(1 day ago)
csagent: score 20.0: secrets grab x2; 1 domain(s) in 0s
Web App Attack
🇺🇸
TPI-Abuse
2026-08-29 03:46:41
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 35.199.17.41 (41.17.199.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 35.199.17.41 (41.17.199.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 23:46:37.074268 2026] [security2:error] [pid 16398:tid 16398] [client 35.199.17.41:56930] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.discord.rustyog.net|F|2"] [data ".env.old"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.discord.rustyog.net"] [uri "/.env.old"] [unique_id "apJWHV9LszlFf349CYSqOwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
masterguru
2026-08-29 03:44:53
(1 day ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 35.199.17.41 (US/United States/41.17. ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 35.199.17.41 (US/United States/41.17.199.35.bc.googleusercontent.com): 1 in the last 3600 secs (0-195)
show less
Hacking
🇺🇸
TPI-Abuse
2026-08-29 03:25:34
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.199.17.41 (41.17.199.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.199.17.41 (41.17.199.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 23:25:24.806820 2026] [security2:error] [pid 17891:tid 17891] [client 35.199.17.41:42052] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dmbarlow.us"] [uri "/.env.bak"] [unique_id "apJRJCDVrRo4S9eokll0ywAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-29 02:43:08
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.199.17.41 (41.17.199.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.199.17.41 (41.17.199.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 22:43:02.410210 2026] [security2:error] [pid 27166:tid 27166] [client 35.199.17.41:45294] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sierrablue.ecuablue.farm"] [uri "/.env.old"] [unique_id "apJHNnqDE28FAE7QccTEaAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-29 01:48:02
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.199.17.41 (41.17.199.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.199.17.41 (41.17.199.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 21:47:57.236256 2026] [security2:error] [pid 13145:tid 13145] [client 35.199.17.41:51710] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "theblindmantylertx.com"] [uri "/.env.old"] [unique_id "apI6Ta4plEhJeXtqxGEfLgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
e.fierstra
2026-08-29 01:44:35
(1 day ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇩🇪
patrisei
2026-08-29 01:28:52
(1 day ago)
You are now banned for 10 years by Schiffdorf-West Patrol. Trigger: crowdsecurity/http-probing
Port Scan
Web App Attack
🇬🇧
andypiper
2026-08-29 01:00:35
(1 day ago)
CrowdSec ban for AbuseIPDB Top List
Brute-Force
Web App Attack
🇷🇺
DZBOT
2026-08-29 00:15:52
(1 day ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
🇺🇸
mnsf
2026-08-29 00:09:01
(1 day ago)
Abuse Detected (18)
Brute-Force
Web App Attack
🇦🇺
2000cn.com.au
2026-08-29 00:02:03
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-08-28 23:44:29
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.199.17.41 (41.17.199.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.199.17.41 (41.17.199.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 19:44:21.125038 2026] [security2:error] [pid 15130:tid 15130] [client 35.199.17.41:46828] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.achillespress.com.tandm.us"] [uri "/.env.example"] [unique_id "apIdVTn25Cpn1S4royJInQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-28 23:17:32
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.199.17.41 (41.17.199.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.199.17.41 (41.17.199.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 19:17:26.964413 2026] [security2:error] [pid 27679:tid 27679] [client 35.199.17.41:45336] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "abilityimprinting.com"] [uri "/.env.prod"] [unique_id "apIXBrhxBLT0nxJdLIU3PQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-28 22:45:32
(1 day ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack