🇦🇺
Bay13
2026-09-09 19:28:16
(5 minutes ago)
CrowdSec:custom/modsecurity
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 19:02:48
(31 minutes ago)
(mod_security) mod_security (id:210492) triggered by 35.221.166.70 (70.166.221.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.221.166.70 (70.166.221.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 15:02:41.041873 2026] [security2:error] [pid 4388:tid 4388] [client 35.221.166.70:12098] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "linnardfinancial.com"] [uri "/@fs/.env"] [unique_id "aqGtUbIW1hiXvlMLF_V70wAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
oja
2026-09-09 18:51:37
(42 minutes ago)
Aggressive web scanner
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 15:33:03
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.221.166.70 (70.166.221.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.221.166.70 (70.166.221.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 11:32:59.858811 2026] [security2:error] [pid 10055:tid 10055] [client 35.221.166.70:16000] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.andrewrmarshall.com"] [uri "/@fs/.env"] [unique_id "aqF8K3h-i4E7TUQPD9RNrAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇦🇺
rubixstudios
2026-09-09 15:12:02
(4 hours ago)
Excessive HTTP requests consistent with automated attack behaviour detected by Imunify360
DDoS Attack
Brute-Force
Web App Attack
Anonymous
2026-09-09 13:22:58
(6 hours ago)
XSS Attempt
Hacking
🇺🇸
TPI-Abuse
2026-09-09 13:06:07
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.221.166.70 (70.166.221.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.221.166.70 (70.166.221.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 09:06:02.995489 2026] [security2:error] [pid 20415:tid 20415] [client 35.221.166.70:48408] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.usaenquirer.com"] [uri "/@fs/app/.env"] [unique_id "aqFZugvgLXxSF9QsdJWZrgAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇪
taivas.nl
2026-09-09 12:32:03
(7 hours ago)
Wordpress_Attack
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 11:54:07
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.221.166.70 (70.166.221.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.221.166.70 (70.166.221.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 07:54:01.020758 2026] [security2:error] [pid 23215:tid 23215] [client 35.221.166.70:46580] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.wichita-massacre.com"] [uri "/@fs/.env"] [unique_id "aqFI2UxW9JbMoU-nIgTcIwAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 11:29:29
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.221.166.70 (70.166.221.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.221.166.70 (70.166.221.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 07:29:24.768501 2026] [security2:error] [pid 29230:tid 29230] [client 35.221.166.70:7236] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.creeation.com"] [uri "/@fs/.env.local"] [unique_id "aqFDFC70Dpsw3qXPPtUlPgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 11:03:31
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.221.166.70 (70.166.221.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.221.166.70 (70.166.221.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 07:03:23.807707 2026] [security2:error] [pid 2880:tid 2880] [client 35.221.166.70:38504] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.thinkerblox.com"] [uri "/@fs/.env"] [unique_id "aqE8-zHEba8cxNXzUha17QAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 10:46:53
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.221.166.70 (70.166.221.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.221.166.70 (70.166.221.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 06:46:47.071438 2026] [security2:error] [pid 20839:tid 20839] [client 35.221.166.70:53260] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.cycontechnology.com"] [uri "/@fs/../.env"] [unique_id "aqE5F3x7a1TT49AimcJ5PgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 09:36:23
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.221.166.70 (70.166.221.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.221.166.70 (70.166.221.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 05:36:18.360849 2026] [security2:error] [pid 2051:tid 2051] [client 35.221.166.70:24282] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.vaccines4all.net"] [uri "/@fs/app/.env"] [unique_id "aqEoks-3QbgOwofg_RF56QAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-09 09:07:06
(10 hours ago)
(config_exploit_scan) Configuratie Scanner / Nep GPTBot 35.221.166.70 (TW/Taiwan/70.166.221.35.bc.go ...
show more
(config_exploit_scan) Configuratie Scanner / Nep GPTBot 35.221.166.70 (TW/Taiwan/70.166.221.35.bc.googleusercontent.com): 3 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 35.221.166.70 - - [09/Sep/2026:11:07:02 +0200] "GET /@fs/root/.env?raw?? HTTP/1.1" 406 991 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; +https://www.anthropic.com/claude-user) Chrome/124.0.5808.49 Safari/537.36"
35.221.166.70 - - [09/Sep/2026:11:07:02 +0200] "GET /@fs/.env?raw?? HTTP/1.1" 406 991 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; Claude-User/1.0; +https://www.anthropic.com/claude-user"
35.221.166.70 - - [09/Sep/2026:11:07:02 +0200] "GET /@fs/../.env?raw?? HTTP/1.1" 406 991 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Discordbot/2.0; +https://discordapp.com)"
show less
Port Scan
🇬🇧
Apache
2026-09-09 08:28:35
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.221.166.70 (TW/Taiwan/70.166.221.35.bc.googl ...
show more
(mod_security) mod_security (id:210492) triggered by 35.221.166.70 (TW/Taiwan/70.166.221.35.bc.googleusercontent.com): 5 in the last 300 secs (CF_ENABLE)
show less
Brute-Force
Web App Attack