๐ฎ๐ช
Coolnagour
2026-07-31 06:21:08
(10 hours ago)
http-probing: /config/secrets.yml
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-31 05:16:27
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.200.89.40 (40.89.200.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.200.89.40 (40.89.200.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 01:16:21.274862 2026] [security2:error] [pid 2589697:tid 2589718] [client 35.200.89.40:31386] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sunshinepumpers.com"] [uri "/.env.local"] [unique_id "amwvpV4KEsw7lcP1L-vlBwAAAVM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
netclix.gr
2026-07-31 04:52:33
(12 hours ago)
(aggressive_scan) Aggressive Web Exploit Scan 35.200.89.40 (JP/Japan/40.89.200.35.bc.googleuserconte ...
show more
(aggressive_scan) Aggressive Web Exploit Scan 35.200.89.40 (JP/Japan/40.89.200.35.bc.googleusercontent.com): 5 in the last 4600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 35.200.89.40 - - [31/Jul/2026:07:52:21 +0300] "GET /wp-config.php HTTP/1.1" 404 808 "-" "anthropic-ai"
35.200.89.40 - - [31/Jul/2026:07:52:21 +0300] "GET /config.inc.php HTTP/1.1" 404 808 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot"
35.200.89.40 - - [31/Jul/2026:07:52:21 +0300] "GET /.env.local.php HTTP/1.1" 404 808 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; GPTBot/1.4; +https://openai.com/gptbot)"
35.200.89.40 - - [31/Jul/2026:07:52:21 +0300] "GET /.env.production.php HTTP/1.1" 404 808 "-" "CCBot/2.0 (https://commoncrawl.org/faq/)"
35.200.89.40 - - [31/Jul/2026:07:52:21 +0300] "GET /.env.php HTTP/1.1" 404 808 "-" "TLM-Audit-Scanner/1.0"
show less
Port Scan
๐ฉ๐ช
zumbo.net
2026-07-31 04:45:08
(12 hours ago)
[Fri Jul 31 07:45:00.825756 2026] [proxy_fcgi:error] [pid 2236581:tid 2236602] [client 35.200.89.40: ...
show more
[Fri Jul 31 07:45:00.825756 2026] [proxy_fcgi:error] [pid 2236581:tid 2236602] [client 35.200.89.40:0] AH01071: Got error 'Primary script unknown'
[Fri Jul 31 07:45:00.911847 2026] [proxy_fcgi:error] [pid 2236580:tid 2236624] [client 35.200.89.40:0] AH01071: Got error 'Primary script unknown'
[Fri Jul 31 07:45:00.933753 2026] [proxy_fcgi:error] [pid 2236580:tid 2236615] [client 35.200.89.40:0] AH01071: Got error 'Primary script unknown'
[Fri Jul 31 07:45:07.862994 2026] [proxy_fcgi:error] [pid 2236581:tid 2236636] [client 35.200.89.40:0] AH01071: Got error 'Primary script unknown'
[Fri Jul 31 07:45:07.867905 2026] [proxy_fcgi:error] [pid 2236581:tid 2236634] [client 35.200.89.40:0] AH01071: Got error 'Primary script unknown'
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-31 03:30:41
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.200.89.40 (40.89.200.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.200.89.40 (40.89.200.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 30 23:30:37.558021 2026] [security2:error] [pid 167299:tid 167299] [client 35.200.89.40:41402] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.blosoms.org"] [uri "/.env.local"] [unique_id "amwW3WUgFeXvFoEV3-eRrgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-31 03:08:16
(13 hours ago)
Multiple web server 400 error codes from same source ip
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-31 02:32:40
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.200.89.40 (40.89.200.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.200.89.40 (40.89.200.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 30 22:32:36.801525 2026] [security2:error] [pid 2012613:tid 2012613] [client 35.200.89.40:42382] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.caddydad.com"] [uri "/.env.development"] [unique_id "amwJRH9-McUnAAWSZ3UvFAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
Roper123
2026-07-31 02:18:30
(14 hours ago)
Web exploits
Hacking
Web App Attack
๐ณ๐ฟ
Antinson
2026-07-31 02:07:25
(14 hours ago)
Scraping with a high error ratio and request rate
Bad Web Bot
๐ฉ๐ช
lolyay
2026-07-31 02:02:21
(14 hours ago)
35.200.89.40 - - [31/Jul/2026:02:02:20 +0000] "GET /.env.production HTTP/1.1" 403 185 "-" "Mozilla/5 ...
show more
35.200.89.40 - - [31/Jul/2026:02:02:20 +0000] "GET /.env.production HTTP/1.1" 403 185 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; GPTBot/1.4; +https://openai.com/gptbot)"
35.200.89.40 - - [31/Jul/2026:02:02:20 +0000] "GET /.env HTTP/1.1" 403 185 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; [email protected] )"
...
show less
Web App Attack
Bad Web Bot
๐ณ๐ฑ
debestelapp
2026-07-31 02:00:05
(14 hours ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-31 01:53:58
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.200.89.40 (40.89.200.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.200.89.40 (40.89.200.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 30 21:53:54.304280 2026] [security2:error] [pid 503390:tid 503390] [client 35.200.89.40:2174] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.ianmagarzo.com"] [uri "/.env.old"] [unique_id "amwAMm-H_iT_8V9FFmSD1AAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-31 01:25:44
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.200.89.40 (40.89.200.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.200.89.40 (40.89.200.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 30 21:25:38.697603 2026] [security2:error] [pid 1986347:tid 1986347] [client 35.200.89.40:37362] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tvr77.garyrankin.com"] [uri "/.env.old"] [unique_id "amv5kpSqXe4DBDrC1HXvgAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-31 01:10:07
(15 hours ago)
CVE-2020-5902 - DIRECTORY TRAVERSAL EXPLOIT - HTTP (REQUEST)
Hacking
๐ป๐ณ
trung.fun
2026-07-30 23:56:02
(16 hours ago)
DDoS, Hack, Brute Force, Web Attack
...
DDoS Attack
Web Spam
Hacking
Brute-Force
Web App Attack