🇺🇸
TPI-Abuse
2026-09-04 03:17:08
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 35.201.134.218 (218.134.201.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.201.134.218 (218.134.201.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 23:17:00.288329 2026] [security2:error] [pid 5447:tid 5447] [client 35.201.134.218:5100] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.possmartterminal.com"] [uri "/@fs/src/.env"] [unique_id "apo4LNk-HrDu5bkuqyHLMgAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 02:50:19
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 35.201.134.218 (218.134.201.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.201.134.218 (218.134.201.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 22:50:13.262046 2026] [security2:error] [pid 16908:tid 16908] [client 35.201.134.218:33912] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jawsite.org"] [uri "/@fs/app/.env"] [unique_id "apox5RC_yGDeYKxupIlQIgAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 02:15:49
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.201.134.218 (218.134.201.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.201.134.218 (218.134.201.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 22:15:41.061063 2026] [security2:error] [pid 6476:tid 6476] [client 35.201.134.218:55522] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.saudigreenrecycling.com"] [uri "/@fs/app/.env"] [unique_id "apopzbYM2mPOyZZwJpLwyAAAAIg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
masterguru
2026-09-04 01:59:17
(2 hours ago)
Restricted File Access Attempt. Matched phrase "/@fs/" at REQUEST_FILENAME. (930130-201)
Hacking
Web App Attack
Anonymous
2026-09-04 01:48:15
(2 hours ago)
Web application attack detected.
Web App Attack
Anonymous
2026-09-04 01:34:36
(3 hours ago)
35.201.134.218 - - [04/Sep/2026:01:34:22 +0000] "GET /@fs/../../.env?raw?? HTTP/1.1" 400 166 "-" "-" ...
show more
35.201.134.218 - - [04/Sep/2026:01:34:22 +0000] "GET /@fs/../../.env?raw?? HTTP/1.1" 400 166 "-" "-"
35.201.134.218 - - [04/Sep/2026:01:34:35 +0000] "GET /@fs/..%2f..%2f..%2f..%2f..%2froot/.env?raw?? HTTP/1.1" 400 166 "-" "-"
35.201.134.218 - - [04/Sep/2026:01:34:35 +0000] "GET /@fs/..%2f..%2f..%2f..%2f..%2fapp/.env?raw?? HTTP/1.1" 400 166 "-" "-"
...
show less
Brute-Force
🇬🇧
andypiper
2026-09-04 01:01:24
(3 hours ago)
CrowdSec ban for AbuseIPDB Top List
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 00:39:41
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.201.134.218 (218.134.201.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.201.134.218 (218.134.201.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 20:39:37.387104 2026] [security2:error] [pid 6820:tid 6820] [client 35.201.134.218:26704] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.tiln.org"] [uri "/@fs/root/.env"] [unique_id "apoTSUTI0luKFaI0hjnCvgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 00:14:04
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.201.134.218 (218.134.201.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.201.134.218 (218.134.201.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 20:14:00.313386 2026] [security2:error] [pid 12508:tid 12508] [client 35.201.134.218:30298] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "washburns.liftreading.com"] [uri "/@fs/src/.env"] [unique_id "apoNSLmMXbKRuxAQlZhISgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
WebNiraj
2026-09-03 23:18:14
(5 hours ago)
(mod_security) mod_security (id:949110) triggered by 35.201.134.218 (TW/Taiwan/218.134.201.35.bc.goo ...
show more
(mod_security) mod_security (id:949110) triggered by 35.201.134.218 (TW/Taiwan/218.134.201.35.bc.googleusercontent.com): 5 in the last 3600 secs [SIGMA]
show less
Brute-Force
🇺🇸
TPI-Abuse
2026-09-03 22:47:46
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.201.134.218 (218.134.201.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.201.134.218 (218.134.201.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 18:47:41.834401 2026] [security2:error] [pid 27291:tid 27291] [client 35.201.134.218:5820] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.qcyprus.com"] [uri "/@fs/app/.env"] [unique_id "apn5DX4SXpm7u3HIgb6DxQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
FeG Deutschland
2026-09-03 22:44:49
(5 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 1247
Exploited Host
Web App Attack
🇪🇸
alferez
2026-09-03 22:12:58
(6 hours ago)
Searching .(env|sql|zip|tar|rar) files
Hacking
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2026-09-03 22:12:43
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.201.134.218 (218.134.201.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.201.134.218 (218.134.201.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 18:12:38.555791 2026] [security2:error] [pid 23085:tid 23085] [client 35.201.134.218:22124] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.jrpiano.com"] [uri "/@fs/root/.env"] [unique_id "apnw1qqc6ELESvIRa9ujAgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
dynamix
2026-09-03 22:10:12
(6 hours ago)
Multiple WAF Violations
Web App Attack