🇺🇸
TPI-Abuse
2026-09-10 00:03:05
(38 minutes ago)
(mod_security) mod_security (id:210492) triggered by 35.221.178.24 (24.178.221.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.221.178.24 (24.178.221.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 20:02:57.049863 2026] [security2:error] [pid 12282:tid 12282] [client 35.221.178.24:55948] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.dezdezero.com"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252froot/.env"] [unique_id "aqHzsSOevyb3Idk1-WKwJwAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇭
Peter-Johann Sarbach
2026-09-09 22:03:39
(2 hours ago)
Hacking website
Hacking
Anonymous
2026-09-09 20:05:07
(4 hours ago)
WAF repeated trigger detected by Fail2Ban
Web App Attack
🇬🇧
Mendip_Defender
2026-09-09 19:24:15
(5 hours ago)
[09/Sep/2026:20:24:28.398681 +0100] aqGybEFyH0q5roLW5N9AQAAAAAs 35.221.178.24 59258 188.246.206.60 7 ...
show more
[09/Sep/2026:20:24:28.398681 +0100] aqGybEFyH0q5roLW5N9AQAAAAAs 35.221.178.24 59258 188.246.206.60 7080
[09/Sep/2026:20:24:28.399994 +0100] aqGybEFyH0q5roLW5N9AQQAAAAQ 35.221.178.24 59272 188.246.206.60 7080
...
show less
Brute-Force
🇦🇹
penguin-solutions.at
2026-09-09 18:14:03
(6 hours ago)
Excessive 403/404 errors
...
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 17:40:46
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.221.178.24 (24.178.221.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.221.178.24 (24.178.221.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 13:40:41.801100 2026] [security2:error] [pid 19159:tid 19159] [client 35.221.178.24:51100] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.javierreinoso.com"] [uri "/@fs/.env"] [unique_id "aqGaGWBiEGq-dGRXPkpf_gAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇿🇦
vanderhost
2026-09-09 17:26:53
(7 hours ago)
[Laravel HoneypotPlus] Automated report - Honeypot access detected on path: /.env.js via rule: regex ...
show more
[Laravel HoneypotPlus] Automated report - Honeypot access detected on path: /.env.js via rule: regex:/^\/\.env/i
show less
Web App Attack
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-09 16:20:42
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.221.178.24 (24.178.221.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.221.178.24 (24.178.221.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 12:20:37.495559 2026] [security2:error] [pid 14046:tid 14046] [client 35.221.178.24:14920] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.aapmracing.com"] [uri "/@fs/app/.env"] [unique_id "aqGHVdFOj_iwscPGBQHIagAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 15:32:38
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.221.178.24 (24.178.221.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.221.178.24 (24.178.221.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 11:32:31.940393 2026] [security2:error] [pid 505:tid 505] [client 35.221.178.24:28572] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mrepoch.art"] [uri "/@fs/src/.env"] [unique_id "aqF8Dyy99FglOad5fY5HcQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 15:00:57
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.221.178.24 (24.178.221.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.221.178.24 (24.178.221.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 11:00:51.794982 2026] [security2:error] [pid 9369:tid 9369] [client 35.221.178.24:24416] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.behrooz.org"] [uri "/@fs/src/.env"] [unique_id "aqF0o2nVyQk0ZuJn8-bHVgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
Marten Mark
2026-09-09 14:20:34
(10 hours ago)
35.221.178.24 - - [09/Sep/2026:14:20:33 +0000] "GET /@fs/home/node/.aws/credentials?raw?? HTTP/2.0" ...
show more
35.221.178.24 - - [09/Sep/2026:14:20:33 +0000] "GET /@fs/home/node/.aws/credentials?raw?? HTTP/2.0" 301 0 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; LinkedInBot/1.0; +http://www.linkedin.com"
...
show less
Web App Attack
Bad Web Bot
🇸🇪
vaia.cloud
2026-09-09 14:00:03
(10 hours ago)
crowdsecurity/http-path-traversal-probing
Brute-Force
Web App Attack
🇬🇧
venus.launch.bz
2026-09-09 13:05:36
(11 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 35.221.178.24 (TW/Taiwan/24.178.221.35. ...
show more
(mod_security) mod_security triggered on hostname [redacted] 35.221.178.24 (TW/Taiwan/24.178.221.35.bc.googleusercontent.com)
show less
SQL Injection
🇳🇱
ConsulHosting
2026-09-09 12:46:17
(11 hours ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 12:28:29
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.221.178.24 (24.178.221.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.221.178.24 (24.178.221.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 08:28:25.551905 2026] [security2:error] [pid 2990:tid 2990] [client 35.221.178.24:50486] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.oneselect.com.hk"] [uri "/@fs/.env"] [unique_id "aqFQ6c2WIUhwlU216iJrlwAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack