🇿🇦
conure.sh
2026-09-09 12:16:30
(1 day ago)
csagent: score 19.9: secrets grab x2; 1 domain(s) in 9s
Web App Attack
🇬🇧
bensmithurst
2026-09-08 19:51:19
(2 days ago)
35.204.59.124 - - [08/Sep/2026:19:51:08 +0000] "GET /@fs/../../.env?raw?? HTTP/1.1" 400 150 "-" "-"
...
show more
35.204.59.124 - - [08/Sep/2026:19:51:08 +0000] "GET /@fs/../../.env?raw?? HTTP/1.1" 400 150 "-" "-"
35.204.59.124 - - [08/Sep/2026:19:51:19 +0000] "GET /@fs/..%2f..%2f..%2f..%2f..%2froot/.env?raw?? HTTP/1.1" 400 150 "-" "-"
35.204.59.124 - - [08/Sep/2026:19:51:19 +0000] "GET /@fs/../../../../../app/.env?raw?? HTTP/1.1" 400 150 "-" "-"
35.204.59.124 - - [08/Sep/2026:19:51:19 +0000] "GET /@fs/../../../../../proc/self/environ?raw?? HTTP/1.1" 400 150 "-" "-"
35.204.59.124 - - [08/Sep/2026:19:51:19 +0000] "GET /@fs/..%2f..%2f..%2f..%2f..%2fapp/.env?raw?? HTTP/1.1" 400 150 "-" "-"
... [host=LAN***]
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 19:40:55
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.204.59.124 (124.59.204.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.204.59.124 (124.59.204.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 15:40:47.950355 2026] [security2:error] [pid 23236:tid 23377] [client 35.204.59.124:1904] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.bioscada.com"] [uri "/@fs/app/.env"] [unique_id "aqBkvxj_zFGcbTMsRpgIMgAAAkM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇿🇦
conure.sh
2026-09-08 18:59:06
(2 days ago)
csagent: score 19.9: secrets grab x1, spoofed crawler UA x1; 1 domain(s) in 9s
Web App Attack
🇳🇱
Savvii
2026-09-08 18:24:55
(2 days ago)
20 attempts against mh-misbehave-ban on ceres
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 18:12:45
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.204.59.124 (124.59.204.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.204.59.124 (124.59.204.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 14:12:39.848656 2026] [security2:error] [pid 16752:tid 16752] [client 35.204.59.124:10108] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.sendera.mx"] [uri "/@fs/.env"] [unique_id "aqBQFyMq2ZO8utFdJUJZuQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 17:34:04
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.204.59.124 (124.59.204.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.204.59.124 (124.59.204.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 13:33:58.381798 2026] [security2:error] [pid 22025:tid 22025] [client 35.204.59.124:7588] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.ncparanormalresearch.com"] [uri "/@fs/.env"] [unique_id "aqBHBj1snbi2iXyDYc99dQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇪
cmbplf
2026-09-08 17:02:31
(2 days ago)
6.390 4xx requests in 1 hour (5d1h59s)
Brute-Force
Bad Web Bot
🇦🇺
screwlooseit.com.au
2026-09-08 16:55:44
(2 days ago)
Blocked by CSF 13 firewall - Rule: 124.59.204.35.bc.googleusercontent.com
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 16:54:52
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.204.59.124 (124.59.204.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.204.59.124 (124.59.204.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 12:54:45.765471 2026] [security2:error] [pid 9662:tid 9662] [client 35.204.59.124:55122] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.pro-fitinvestment.com"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252fapp/.env"] [unique_id "aqA91QGjgyggar9LwB1TVAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-08 16:49:40
(2 days ago)
Aggressive web scan
Web App Attack
Anonymous
2026-09-08 16:44:30
(2 days ago)
Multiple web server 400 error codes from same source ip
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 16:21:12
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.204.59.124 (124.59.204.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.204.59.124 (124.59.204.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 12:21:00.542252 2026] [security2:error] [pid 17144:tid 17144] [client 35.204.59.124:21110] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.shipthunder.com"] [uri "/@fs/../../.env"] [unique_id "aqA17ATY4T_dSK_smiQ9PgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇹🇷
hostopya.com
2026-09-08 16:15:44
(2 days ago)
[plesk-apache] 6 failed attempt(s). Log: [Tue Sep 08 19:15:27.130786 2026] [authz_core:error] [pid 2 ...
show more
[plesk-apache] 6 failed attempt(s). Log: [Tue Sep 08 19:15:27.130786 2026] [authz_core:error] [pid 2925922] [client 35.204.59.124:0] AH01630: client denied by server configuration: /usr/share/psa-roundcube/config/database.yml|[Tue Sep 08 19:15:27.155892 2026] [authz_core:error] [pid 2926001] [client 35.204.59.124:0] AH01630: client denied by server configuration: /usr/share/psa-roundcube/config/secrets.yml|[Tue Sep 08 19:15:35.334434 2026] [authz_core:error] [pid 2925921] [client 35.204.59.124:0] AH01630: client denied by server configuration: /usr/share/psa-roundcube/.htpasswd|[Tue Sep 08 19:15:39.179846 2026] [authz_core:error] [pid 2925921] [client 35.204.59.124:0] AH01630: client denied by server configuration: /usr/share/psa-roundcube/config/master.key|[Tue Sep 08 19:15:43.768507 2026] [authz_core:error] [pid 2926001] [client 35.204.59.124:0] AH01630: client denied by server configuration: /usr/share/psa-roundcube/config/openai.json
show less
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 16:00:09
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.204.59.124 (124.59.204.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.204.59.124 (124.59.204.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 12:00:01.110290 2026] [security2:error] [pid 20197:tid 20197] [client 35.204.59.124:10594] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "brittb.com"] [uri "/@fs/.env"] [unique_id "aqAxAcCaGkiHTHsoU5tj-gAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack