🇧🇾
lns.bz
2026-09-06 06:37:53
(6 hours ago)
Too many 404 requests [BY]
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 06:32:22
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.221.59.195 (195.59.221.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.221.59.195 (195.59.221.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 02:32:17.839769 2026] [security2:error] [pid 21810:tid 21810] [client 35.221.59.195:43902] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.harborcomputer.com"] [uri "/.env"] [unique_id "ap0I8XfX0fwzI0OBFAaUNwAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇭
ca
2026-09-06 06:19:17
(6 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-06 03:52:00
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.221.59.195 (195.59.221.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.221.59.195 (195.59.221.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:51:56.387869 2026] [security2:error] [pid 32344:tid 32344] [client 35.221.59.195:43572] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.tech-servusa.com"] [uri "/.env.bak"] [unique_id "apzjXEtWCPAmJlFB307-YQAAAEk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-06 03:30:01
(9 hours ago)
suspicious request in access.log
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 02:59:38
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.221.59.195 (195.59.221.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.221.59.195 (195.59.221.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:59:31.558639 2026] [security2:error] [pid 9901:tid 9901] [client 35.221.59.195:45856] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.paulshorrock.com"] [uri "/wp-config.php~"] [unique_id "apzXE0wN1I7b6Om_kbB13gAAACQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-09-06 02:30:40
(10 hours ago)
Web attack/malicious scanning detected
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-06 02:02:17
(11 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-06 00:58:12
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.221.59.195 (195.59.221.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.221.59.195 (195.59.221.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 20:58:07.395770 2026] [security2:error] [pid 20623:tid 20623] [client 35.221.59.195:54654] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thesexysketch.com"] [uri "/.env"] [unique_id "apy6n1qBNYxvC6AgsDR43gAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
✨
2026-09-06 00:29:15
(12 hours ago)
Domain : vanzo-tech.com
Rule : env
2026-09-06 00:27:46 217.194.212.5 GET /.env.save - 443 - 35.221.5 ...
show more
Domain : vanzo-tech.com
Rule : env
2026-09-06 00:27:46 217.194.212.5 GET /.env.save - 443 - 35.221.59.195 HTTP/1.1 crusader-worker/1.0 - vanzo-tech.com 404 0 2 1560 95 75 - -
show less
Hacking
SQL Injection
🇦🇺
2000cn.com.au
2026-09-06 00:19:23
(12 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇩🇪
Philister11
2026-09-06 00:01:39
(13 hours ago)
CrowdSec: crowdsecurity/http-probing (US/AS396982)
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-05 23:56:35
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.221.59.195 (195.59.221.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.221.59.195 (195.59.221.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 19:56:29.207419 2026] [security2:error] [pid 25131:tid 25131] [client 35.221.59.195:46344] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "b2c-llc.com"] [uri "/.env.local"] [unique_id "apysLVTB7zmBb7q8yCE86wAAAEE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-05 22:59:34
(14 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-05 22:50:06
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.221.59.195 (195.59.221.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.221.59.195 (195.59.221.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 18:49:58.948403 2026] [security2:error] [pid 31660:tid 31660] [client 35.221.59.195:39254] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "drpeppard.com"] [uri "/wp-config.php.bak"] [unique_id "apyclgVZtscDd0ecT0SNBQAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack