Anonymous
2026-09-08 20:22:11
(1 day ago)
Bot / seems abusive / Apache connections: 22
DDoS Attack
Web Spam
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 19:48:29
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.200.104.200 (200.104.200.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.200.104.200 (200.104.200.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 15:48:22.355269 2026] [security2:error] [pid 20918:tid 20918] [client 35.200.104.200:29718] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "andrewweigel.name"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252froot/.env"] [unique_id "aqBmhvhASjWG8TSUrz03ywAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 19:31:37
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.200.104.200 (200.104.200.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.200.104.200 (200.104.200.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 15:31:30.201375 2026] [security2:error] [pid 23552:tid 23552] [client 35.200.104.200:46858] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "concertosupport.com.accordionclub.org"] [uri "/@fs/../../.env"] [unique_id "aqBikv3JLxGPYZxWfzfRIQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 18:29:48
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.200.104.200 (200.104.200.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.200.104.200 (200.104.200.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 14:29:44.610021 2026] [security2:error] [pid 27283:tid 27283] [client 35.200.104.200:58598] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.wisdomwfm.com"] [uri "/@fs/.env.production"] [unique_id "aqBUGGzl3S2qWbUhVLwa2QAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
LRob
2026-09-08 18:15:41
(1 day ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /@fs/.env (+12 more) | 2026-09-08 18:15 UTC
show less
Hacking
Web App Attack
🇸🇪
vaia.cloud
2026-09-08 18:00:03
(1 day ago)
crowdsecurity/http-probing
Brute-Force
Web App Attack
🇺🇸
factor1
2026-09-08 17:58:06
(1 day ago)
CrowdSec at apollo Reports Abuse
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 17:36:09
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.200.104.200 (200.104.200.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.200.104.200 (200.104.200.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 13:36:03.976540 2026] [security2:error] [pid 23965:tid 23965] [client 35.200.104.200:46760] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.teenaarunoceans.com"] [uri "/@fs/.env.local"] [unique_id "aqBHgwM4yEhTZnps_coLYwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 16:49:34
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.200.104.200 (200.104.200.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.200.104.200 (200.104.200.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 12:49:29.410063 2026] [security2:error] [pid 3899028:tid 3899028] [client 35.200.104.200:8822] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "water.ic1.biz"] [uri "/@fs/../../.env"] [unique_id "aqA8maZ17-zaOKxFMztrqgAAAC0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-09-08 16:33:33
(1 day ago)
Web attack/malicious scanning detected
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 16:27:50
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.200.104.200 (200.104.200.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.200.104.200 (200.104.200.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 12:27:46.255656 2026] [security2:error] [pid 19159:tid 19159] [client 35.200.104.200:61188] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.leighcunningham.com"] [uri "/@fs/.env.local"] [unique_id "aqA3gs9EwOlJ_cwSMQSKdwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
e.fierstra
2026-09-08 16:12:49
(1 day ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 16:00:19
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.200.104.200 (200.104.200.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.200.104.200 (200.104.200.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 12:00:09.717633 2026] [security2:error] [pid 32479:tid 32479] [client 35.200.104.200:51672] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.supaskills.gregorii.com"] [uri "/@fs/src/.env"] [unique_id "aqAxCWmiDn0yiTrYy5FViQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Site.eu
2026-09-08 15:04:32
(2 days ago)
Excessive multi-domain requests
Brute-Force
🇫🇷
COMAITE
2026-09-08 14:52:57
(2 days ago)
Common web attack from 35.200.104.200.
Web App Attack