🇺🇸
TPI-Abuse
2026-09-08 13:00:25
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.201.241.140 (140.241.201.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.201.241.140 (140.241.201.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 09:00:20.749042 2026] [security2:error] [pid 32296:tid 32296] [client 35.201.241.140:53282] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ftp.infraredcoatings.com"] [uri "/.env.production"] [unique_id "aqAG5JKEkRm1J5WBlaI8VAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 07:57:09
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.201.241.140 (140.241.201.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.201.241.140 (140.241.201.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 03:57:01.448165 2026] [security2:error] [pid 21305:tid 21305] [client 35.201.241.140:48562] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.brainwavecenters.com"] [uri "/.env"] [unique_id "ap-_zdO4NGX2XU_4-Cxk7gAAAFU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 06:06:01
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.201.241.140 (140.241.201.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.201.241.140 (140.241.201.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 02:05:56.279574 2026] [security2:error] [pid 24301:tid 24301] [client 35.201.241.140:36568] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ftp.donzie.com"] [uri "/.env.bak"] [unique_id "ap-lxKZuxfHo2x5mwZJwEQAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇾
shopmax
2026-09-07 20:10:04
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇩🇪
FeG Deutschland
2026-09-06 03:39:46
(3 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
🇩🇪
FD-IX
2026-09-06 03:23:31
(3 days ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
🇺🇸
MatCat
2026-09-06 03:05:16
(3 days ago)
Banned by fail2ban: apache-webprobe
Port Scan
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-06 03:04:21
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.201.241.140 (140.241.201.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.201.241.140 (140.241.201.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:04:14.818060 2026] [security2:error] [pid 24943:tid 24943] [client 35.201.241.140:52968] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wildrosestudios.tv"] [uri "/wp-config.php.bak"] [unique_id "apzYLvmqIcNz_sBVUjhPcgAAAH0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇱🇻
garmtech.com
2026-09-06 02:56:28
(3 days ago)
Attempted access to sensitive endpoint (/.env.local) detected. Automated scan or unauthorized probin ...
show more
Attempted access to sensitive endpoint (/.env.local) detected. Automated scan or unauthorized probing.
show less
Web App Attack
🇫🇷
masterguru
2026-09-06 02:44:56
(3 days ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-197)
Hacking
Web App Attack
🇨🇭
leo1305
2026-09-06 02:44:23
(3 days ago)
CrowdSec detection | scenario: http-sensitive-files
Web App Attack
Exploited Host
🇺🇸
Rocky Mountain Bioengineering Symposium
2026-09-06 01:47:59
(3 days ago)
[Sat Sep 05 19:47:59.452246 2026] [authz_core:error] [pid 26875:tid 139766263694912] [client 35.201. ...
show more
[Sat Sep 05 19:47:59.452246 2026] [authz_core:error] [pid 26875:tid 139766263694912] [client 35.201.241.140:32814] AH01630: client denied by server configuration: /var/www/horde/wp-config.php.swp
[Sat Sep 05 19:47:59.465385 2026] [authz_core:error] [pid 27271:tid 139766154655296] [client 35.201.241.140:32866] AH01630: client denied by server configuration: /var/www/horde/wp-config.php~
[Sat Sep 05 19:47:59.470376 2026] [authz_core:error] [pid 26876:tid 139766263694912] [client 35.201.241.140:32898] AH01630: client denied by server configuration: /var/www/horde/.env.bak
...
show less
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-06 01:45:18
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.201.241.140 (140.241.201.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.201.241.140 (140.241.201.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 21:45:12.449626 2026] [security2:error] [pid 12150:tid 12150] [client 35.201.241.140:39778] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ftp.rkevinschneider.com"] [uri "/.env"] [unique_id "apzFqFG4ROUR-ZRaeoN0AwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
LRNP
2026-09-06 00:52:58
(3 days ago)
experiments.lpoujol.fr:443 35.201.241.140 - - [06/Sep/2026:00:52:57 +0000] "GET /.env HTTP/1.1" 404 ...
show more
experiments.lpoujol.fr:443 35.201.241.140 - - [06/Sep/2026:00:52:57 +0000] "GET /.env HTTP/1.1" 404 146 "-" "crusader-worker/1.0"
...
show less
Bad Web Bot
Web App Attack
🇫🇷
dynamix
2026-09-06 00:31:58
(3 days ago)
Multiple WAF Violations
Web App Attack