🇧🇪
cmbplf
2026-09-08 23:38:49
(6 hours ago)
265 requests with url.path */@fs/*
Brute-Force
Bad Web Bot
🇩🇪
FD-IX
2026-09-08 20:22:15
(10 hours ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 19:40:34
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.200.9.82 (82.9.200.35.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 35.200.9.82 (82.9.200.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 15:40:28.947421 2026] [security2:error] [pid 17660:tid 17660] [client 35.200.9.82:57630] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.nhgrange.org"] [uri "/@fs/app/.env"] [unique_id "aqBkrAQ8URzVtNAJdlfltgAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 18:38:57
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.200.9.82 (82.9.200.35.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 35.200.9.82 (82.9.200.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 14:38:51.220198 2026] [security2:error] [pid 25649:tid 25649] [client 35.200.9.82:36652] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.fixmywellwater.com"] [uri "/@fs/root/.env"] [unique_id "aqBWO7t6aIs72znG6QnHlQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇿
Antinson
2026-09-08 18:23:31
(12 hours ago)
Scraping with a high error ratio and request rate
Bad Web Bot
🇩🇪
akasolutions.de
2026-09-08 17:37:57
(12 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 35.200.9.82 (JP/Japan/82.9.200.35.bc.go ...
show more
(mod_security) mod_security triggered on hostname [redacted] 35.200.9.82 (JP/Japan/82.9.200.35.bc.googleusercontent.com)
show less
SQL Injection
🇺🇸
TPI-Abuse
2026-09-08 16:56:17
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.200.9.82 (82.9.200.35.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 35.200.9.82 (82.9.200.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 12:56:09.926855 2026] [security2:error] [pid 24088:tid 24088] [client 35.200.9.82:40702] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.julisaadams.com"] [uri "/@fs/app/.env"] [unique_id "aqA-KevuJ2ZRLm6y2wXoPQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
Octopuce
2026-09-08 16:42:36
(13 hours ago)
Aggressive web search of vulnerable pages: /v1/.env /assets../.env /.docker/.env /img../.env /upload ...
show more
Aggressive web search of vulnerable pages: /v1/.env /assets../.env /.docker/.env /img../.env /uploads../.env ...
show less
Web App Attack
🇳🇱
Savvii
2026-09-08 16:35:34
(13 hours ago)
20 attempts against mh_ha-misbehave-ban on pf102956
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 16:28:35
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.200.9.82 (82.9.200.35.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 35.200.9.82 (82.9.200.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 12:28:27.889855 2026] [security2:error] [pid 18525:tid 18525] [client 35.200.9.82:35822] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.dualspiralsystems.com"] [uri "/@fs/.env"] [unique_id "aqA3q69jTeLTN_89LclWWAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-08 16:14:49
(14 hours ago)
Aggressive web scan
Web App Attack
🇩🇪
raph
2026-09-08 16:08:22
(14 hours ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack
🇳🇱
Site.eu
2026-09-08 16:03:42
(14 hours ago)
Excessive multi-domain requests
Brute-Force
🇺🇸
TPI-Abuse
2026-09-08 15:56:04
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.200.9.82 (82.9.200.35.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 35.200.9.82 (82.9.200.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 11:55:56.026230 2026] [security2:error] [pid 24617:tid 24617] [client 35.200.9.82:47014] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.francisautodetailing.com"] [uri "/@fs/root/.env"] [unique_id "aqAwDO7uw0We3spkHyVE-QAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇦🇺
Bay13
2026-09-08 15:36:51
(14 hours ago)
CrowdSec:custom/http-probing
Web App Attack