🇺🇸
TPI-Abuse
2026-09-04 15:13:58
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.221.15.137 (137.15.221.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.221.15.137 (137.15.221.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 11:13:51.891853 2026] [security2:error] [pid 6302:tid 6302] [client 35.221.15.137:34078] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.goikopro.com"] [uri "/wp-config.php.bak"] [unique_id "aprgL5Za2BZnwXRSorJQEgAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 14:15:07
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.221.15.137 (137.15.221.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.221.15.137 (137.15.221.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 10:15:00.846115 2026] [security2:error] [pid 4355:tid 4368] [client 35.221.15.137:58818] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.vote4joegardner.com"] [uri "/.env.example"] [unique_id "aprSZMKZoYaNsgIbwhvDyQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 13:22:00
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.221.15.137 (137.15.221.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.221.15.137 (137.15.221.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 09:21:53.058644 2026] [security2:error] [pid 11549:tid 11549] [client 35.221.15.137:49492] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "coffeewitheinstein.com"] [uri "/.env.production"] [unique_id "aprF8c6qYPBxgUF6Ns7R0QAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 13:05:24
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.221.15.137 (137.15.221.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.221.15.137 (137.15.221.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 09:05:17.007948 2026] [security2:error] [pid 25822:tid 25822] [client 35.221.15.137:55616] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "shawnlayne.com"] [uri "/wp-config.php.swp"] [unique_id "aprCDcB1Cy4VXU50iYAb0QAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 11:01:25
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.221.15.137 (137.15.221.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.221.15.137 (137.15.221.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 07:01:20.996527 2026] [security2:error] [pid 22993:tid 22993] [client 35.221.15.137:41666] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "howardherrell.com"] [uri "/.env.prod"] [unique_id "apqlADZ4X2hVgepktJihhAAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇭
zynex
2026-09-04 10:58:50
(10 hours ago)
URL Probing: /.env
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 10:20:42
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.221.15.137 (137.15.221.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.221.15.137 (137.15.221.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:20:35.180053 2026] [security2:error] [pid 2239:tid 2239] [client 35.221.15.137:53652] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "page-wide.computersraleigh.com"] [uri "/.env.local"] [unique_id "apqbc1NiVQ1vVv3H98Up5AAAAEw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 10:01:40
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.221.15.137 (137.15.221.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.221.15.137 (137.15.221.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:01:34.474070 2026] [security2:error] [pid 2824998:tid 2825102] [client 35.221.15.137:42700] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bacchus.productions"] [uri "/.env.backup"] [unique_id "apqW_g1OtXLqWHx1GpG3pwAAAJY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 09:24:22
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.221.15.137 (137.15.221.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.221.15.137 (137.15.221.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 05:24:17.816555 2026] [security2:error] [pid 3251:tid 3251] [client 35.221.15.137:59080] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.innovacionesnimba.com"] [uri "/.env.backup"] [unique_id "apqOQdY1r4_KCjeGcSleFAAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Bedios GmbH
2026-09-04 09:12:48
(12 hours ago)
Login credentials theft attempt
Hacking
🇺🇸
TPI-Abuse
2026-09-04 08:43:27
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.221.15.137 (137.15.221.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.221.15.137 (137.15.221.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 04:43:20.878191 2026] [security2:error] [pid 475:tid 475] [client 35.221.15.137:39448] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "redlitephotos.com"] [uri "/.env.dev"] [unique_id "apqEqMKrY7BmnmtxRSeUSQAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 08:23:14
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.221.15.137 (137.15.221.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.221.15.137 (137.15.221.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 04:23:10.463353 2026] [security2:error] [pid 15462:tid 15462] [client 35.221.15.137:58362] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.satanisdead.com"] [uri "/.env"] [unique_id "app_7q8dPtODt-IDmzZKTQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-04 08:16:03
(13 hours ago)
Bot / scanning and/or hacking attempts: GET /.env.production HTTP/1.1, GET /storage/logs/laravel.log ...
show more
Bot / scanning and/or hacking attempts: GET /.env.production HTTP/1.1, GET /storage/logs/laravel.log HTTP/1.1, GET /.env.bak HTTP/1.1, GET /_ignition/health-check HTTP/1.1, GET /.env.dev HTTP/1.1, GET /.env.prod HTTP/1.1, GET /.env.save HTTP/1.1, GET /.env.backup HTTP/1.1, GET /crusader-404-probe HTTP/1.1, GET /wp-config.php.bak HTTP/1.1
show less
Hacking
Web App Attack
🇿🇦
conure.sh
2026-09-04 08:12:55
(13 hours ago)
csagent: score 20.8: 404 noise floor x3, secrets grab x2; 1 domain(s) in 0s
Web App Attack
🇩🇪
yitzhaq
2026-09-04 07:23:15
(13 hours ago)
35.221.15.137 - - [04/Sep/2026:09:23:12 +0200] "GET /wp-config.php.bak HTTP/1.1" 403 4651 "-" "crusa ...
show more
35.221.15.137 - - [04/Sep/2026:09:23:12 +0200] "GET /wp-config.php.bak HTTP/1.1" 403 4651 "-" "crusader-worker/1.0"
35.221.15.137 - - [04/Sep/2026:09:23:12 +0200] "GET /wp-config.php~ HTTP/1.1" 403 4651 "-" "crusader-worker/1.0"
35.221.15.137 - - [04/Sep/2026:09:23:12 +0200] "GET /actuator/env HTTP/1.1" 403 4651 "-" "crusader-worker/1.0"
35.221.15.137 - - [04/Sep/2026:09:23:12 +0200] "GET /env HTTP/1.1" 403 4650 "-" "crusader-worker/1.0"
35.221.15.137 - - [04/Sep/2026:09:23:12 +0200] "GET /actuator/configprops HTTP/1.1" 403 4651 "-" "crusader-worker/1.0"
35.221.15.137 - - [04/Sep/2026:09:23:12 +0200] "GET /.env.local HTTP/1.1" 403 4651 "-" "crusader-worker/1.0"
35.221.15.137 - - [04/Sep/2026:09:23:12 +0200] "GET /.env.save HTTP/1.1" 403 4651 "-" "crusader-worker/1.0"
35.221.15.137 - - [04/Sep/2026:09:23:12 +0200] "GET /.env.example HTTP/1.1" 403 4651 "-" "crusader-worker/1.0"
35.221.15.137 - - [04/Sep/2026:09:23:12 +0200] "GET /storage/logs/laravel.log HTTP/1.1" 403 4651 "-" "crusader-
show less
Web App Attack
Brute-Force