🇺🇸
TPI-Abuse
2026-09-04 13:00:04
(57 minutes ago)
(mod_security) mod_security (id:210492) triggered by 35.203.173.251 (251.173.203.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.203.173.251 (251.173.203.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 08:59:57.203348 2026] [security2:error] [pid 23012:tid 23012] [client 35.203.173.251:59612] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "questionnairehints.banis-associates.com"] [uri "/@fs/src/.env"] [unique_id "aprAzXnPrss3MhiWeXZt-wAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 12:12:19
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 35.203.173.251 (251.173.203.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.203.173.251 (251.173.203.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 08:12:14.116058 2026] [security2:error] [pid 19045:tid 19045] [client 35.203.173.251:54118] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.hotdamnsam.com"] [uri "/@fs/.env"] [unique_id "apq1nqLw0DPrFMBLyxFNmgAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
dan.gordon
2026-09-04 12:05:04
(1 hour ago)
Auto-reported by ASOWorks!: 1 API_ABUSE bursts (most-hit endpoint: /api/settings). Repeated unauthen ...
show more
Auto-reported by ASOWorks!: 1 API_ABUSE bursts (most-hit endpoint: /api/settings). Repeated unauthenticated 401 probing of authentication API.
show less
Bad Web Bot
Web App Attack
🇩🇪
itsolon
2026-09-04 11:39:24
(2 hours ago)
[04/Sep/2026:13:39:21 +0200] 178852196150.713420 35.203.173.251 0 217.154.7.177 443
[04/Sep/2026:13: ...
show more
[04/Sep/2026:13:39:21 +0200] 178852196150.713420 35.203.173.251 0 217.154.7.177 443
[04/Sep/2026:13:39:21 +0200] 17885219614.639268 35.203.173.251 0 217.154.7.177 443
[04/Sep/2026:13:39:21 +0200] 178852196119.069909 35.203.173.251 0 217.154.7.177 443
[04/Sep/2026:13:39:21 +0200] 178852196176.084219 35.203.173.251 0 217.154.7.177 443
[04/Sep/2026:13:39:21 +0200] 178852196123.296195 35.203.173.251 0 217.154.7.177 443
...
show less
Port Scan
Hacking
Brute-Force
Web App Attack
🇫🇷
masterguru
2026-09-04 11:15:06
(2 hours ago)
Restricted File Access Attempt. Matched phrase "/@fs/" at REQUEST_FILENAME. (930130-201)
Hacking
Web App Attack
🇩🇪
FeG Deutschland
2026-09-04 10:48:37
(3 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 127
Exploited Host
Web App Attack
🇸🇪
vaia.cloud
2026-09-04 10:05:02
(3 hours ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
🇳🇱
middelkoopcc
2026-09-04 09:56:00
(4 hours ago)
2026-09-04 11:54:33 AH10244: invalid URI path (/@fs/../../.env?raw??) && 2026-09-04 11:54:47 AH10244 ...
show more
2026-09-04 11:54:33 AH10244: invalid URI path (/@fs/../../.env?raw??) && 2026-09-04 11:54:47 AH10244: invalid URI path (/@fs/../../../../../proc/self/environ?raw??) && 2026-09-04 11:54:47 AH10244: invalid URI path (/@fs/../../../../../root/.env?raw??) && 100 more within 20 minutes
show less
Web App Attack
🇩🇪
netclix.gr
2026-09-04 09:54:20
(4 hours ago)
(c5_sensitive_scan) Custom5 Sensitive File Exploit Blocked 35.203.173.251 (US/United States/251.173. ...
show more
(c5_sensitive_scan) Custom5 Sensitive File Exploit Blocked 35.203.173.251 (US/United States/251.173.203.35.bc.googleusercontent.com): 1 in the last 4600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: default:80 35.203.173.251 - - [04/Sep/2026:12:54:18 +0300] "GET /@fs/root/.aws/credentials.bak?raw?? HTTP/1.1" 403 407 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; [email protected] )"
show less
Port Scan
🇦🇺
rubixstudios
2026-09-04 08:59:02
(4 hours ago)
Excessive HTTP requests consistent with automated attack behaviour detected by Imunify360
DDoS Attack
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 08:29:42
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.203.173.251 (251.173.203.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.203.173.251 (251.173.203.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 04:29:36.703434 2026] [security2:error] [pid 2951:tid 2951] [client 35.203.173.251:53340] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.mldlnn.com"] [uri "/@fs/.env"] [unique_id "apqBcDgbN1fYZg5fji5CXAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇪🇸
alferez
2026-09-04 08:22:19
(5 hours ago)
Searching .(env|sql|zip|tar|rar) files
Hacking
Exploited Host
Web App Attack
🇳🇱
e.fierstra
2026-09-04 08:09:38
(5 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇬🇧
Aetherweb Ark
2026-09-04 07:16:18
(6 hours ago)
(mod_security) mod_security (id:949110) triggered by 35.203.173.251 (US/United States/251.173.203.35 ...
show more
(mod_security) mod_security (id:949110) triggered by 35.203.173.251 (US/United States/251.173.203.35.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 06:17:03
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.203.173.251 (251.173.203.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.203.173.251 (251.173.203.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 02:16:56.750439 2026] [security2:error] [pid 7131:tid 7131] [client 35.203.173.251:2610] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.bankcardtexas.com"] [uri "/@fs/.env"] [unique_id "appiWGnkGsv0ras5LuvNjAAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack