๐บ๐ธ
TPI-Abuse
2026-08-01 17:06:51
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 35.203.28.200 (200.28.203.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.203.28.200 (200.28.203.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 13:06:45.981763 2026] [security2:error] [pid 652575:tid 652575] [client 35.203.28.200:47990] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.malta-boat-registration.com.boatregistrationdelaware.com"] [uri "/.env.save"] [unique_id "am4npe8pLDnd41v-ylsfDgAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 16:41:34
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.203.28.200 (200.28.203.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.203.28.200 (200.28.203.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 12:41:30.051514 2026] [security2:error] [pid 2585834:tid 2585834] [client 35.203.28.200:57702] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "internationalconnect.herecometheplanes.com"] [uri "/.env.production"] [unique_id "am4huo1Lz-URUEtyIomZPQAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-08-01 16:13:48
(2 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
Anonymous
2026-08-01 16:07:05
(2 hours ago)
Automated web scanner. Requested suspicious paths: /.env.save | /.env.production | /.env.example | / ...
show more
Automated web scanner. Requested suspicious paths: /.env.save | /.env.production | /.env.example | /.env | /.env.local | /.env.backup | /.env.prod | /.env.bak | /.env.dev | /.env.old. UTC: 2026-08-01 15:31:40.
show less
Web App Attack
๐ง๐ช
boxed-it
2026-08-01 15:53:34
(2 hours ago)
GET /.env (Tarpitted for 2m10s, wasted 7.73kB)
Web App Attack
๐ฉ๐ช
seal
2026-08-01 15:41:47
(3 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
SSH
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-08-01 15:39:05
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.203.28.200 (200.28.203.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.203.28.200 (200.28.203.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 11:38:58.498696 2026] [security2:error] [pid 2391:tid 2391] [client 35.203.28.200:38620] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "virginialakes395.com"] [uri "/.env.local"] [unique_id "am4TEuVPiBl4QeEefBEFXQAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
todix
2026-08-01 15:32:33
(3 hours ago)
Web App Attack Exploid from 35.203.28.200
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 15:22:31
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.203.28.200 (200.28.203.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.203.28.200 (200.28.203.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 11:22:23.359568 2026] [security2:error] [pid 1447182:tid 1447182] [client 35.203.28.200:56648] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "toybud.com"] [uri "/.env.dev"] [unique_id "am4PL1C_1N4P2YYSYcGIkAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-01 14:28:35
(4 hours ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 14:18:42
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.203.28.200 (200.28.203.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.203.28.200 (200.28.203.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 10:18:37.698208 2026] [security2:error] [pid 2330498:tid 2330498] [client 35.203.28.200:32948] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "k-h-w.com"] [uri "/.env.bak"] [unique_id "am4APUMcdtQViUo6au-88wAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
ecode hosting
2026-08-01 14:03:04
(4 hours ago)
Domain : oztekintel.com
Rule : env
2026-08-01 14:01:35 10.100.1.20 GET /.env.backup - 80 - 35.203.28 ...
show more
Domain : oztekintel.com
Rule : env
2026-08-01 14:01:35 10.100.1.20 GET /.env.backup - 80 - 35.203.28.200 HTTP/1.1 crusader-worker/1.0 - www.oztekintel.com 301 0 0 343 101 139 - -
show less
Hacking
SQL Injection
๐ฉ๐ช
4server
2026-08-01 13:38:40
(5 hours ago)
[SatAug0115:38:37.8376362026][security2:error][pid1564874:tid1564960][client35.203.28.200:0]ModSecur ...
show more
[SatAug0115:38:37.8376362026][security2:error][pid1564874:tid1564960][client35.203.28.200:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(\?:/\(\?:\^\|/\)\\\\\\\\.\(env\|git\|svn\|hg\|DS_Store\)\|/\(\?:wp-config\|\\\\\\\\.htaccess\|\\\\\\\\.htpasswd\)\|\\\\\\\\.\(\?:sql\|bak\|old\|log\)\$\)\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"156\"][id\"960720\"][msg\"Forbiddenfileaccessattempt\"][severity\"CRITICAL\"][hostname\"feldenkraisticino.ch.136-243-54-122.cpanel.site\"][uri\"/.env.bak\"][unique_id\"am323ex41xcnL0noih920AAAAJY\"]
show less
Port Scan
Brute-Force
Web App Attack
๐ฒ๐พ
Rizzy
2026-08-01 13:32:17
(5 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐จ๐ญ
Origon
2026-08-01 13:16:10
(5 hours ago)
http-sensitive-files - IP: 35.203.28.200 - time="2026-08-01T15:16:09+02:00" level=info msg="(555f66 ...
show more
http-sensitive-files - IP: 35.203.28.200 - time="2026-08-01T15:16:09+02:00" level=info msg="(555f66b4f6a74558bc11e3f93469658es8App0Mcc0TKEeje/crowdsec) crowdsecurity/http-sensitive-files by ip 35.203.28.200 (CA/396982) : 4h ban on Ip 35.203.28.200" module=db
show less
Web App Attack