🇺🇸
TPI-Abuse
2026-09-07 10:34:04
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.222.27.219 (219.27.222.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.222.27.219 (219.27.222.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 06:34:00.174294 2026] [security2:error] [pid 893:tid 893] [client 35.222.27.219:29850] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nchsfootballgolfouting.com"] [uri "/@fs/.env.production"] [unique_id "ap6TGIu3fi1bJ7sOBXA11wAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
LRob
2026-09-07 09:37:54
(1 day ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /@fs/.env | 2026-09-07 09:37 UTC
show less
Hacking
Web App Attack
🇮🇹
VHosting
2026-09-07 09:30:04
(1 day ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 09:08:38
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.222.27.219 (219.27.222.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.222.27.219 (219.27.222.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 05:08:32.939487 2026] [security2:error] [pid 1533:tid 1533] [client 35.222.27.219:56520] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.shapevscolour.com"] [uri "/@fs/.env"] [unique_id "ap5_EMAJR54QNINR01z0-QAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
alecj.com
2026-09-07 08:58:55
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/appsec-vpatch
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 08:43:59
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.222.27.219 (219.27.222.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.222.27.219 (219.27.222.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 04:43:51.877631 2026] [security2:error] [pid 14376:tid 14376] [client 35.222.27.219:34242] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.disloyalunion.com"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252fapp/.env"] [unique_id "ap55R0zvH2YbIqUNcVs2OQAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 07:41:24
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 35.222.27.219 (219.27.222.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.222.27.219 (219.27.222.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 03:41:16.871010 2026] [security2:error] [pid 25029:tid 25029] [client 35.222.27.219:43536] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||www.robcohn.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.robcohn.com"] [uri "/@fs/etc/apache2/apache2.conf"] [unique_id "ap5qnOgBt1Xc-8ZPuW2tDwAAAB8"], referer: http://robertcohn.org/@fs/etc/apache2/apache2.conf?raw??
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 07:15:51
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.222.27.219 (219.27.222.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.222.27.219 (219.27.222.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 03:15:44.431074 2026] [security2:error] [pid 2937:tid 2961] [client 35.222.27.219:23874] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "vintage.deathbyaudio.com"] [uri "/@fs/.env.local"] [unique_id "ap5koL0W7F8lDO3UKxnp5QAAAFU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-07 06:44:29
(1 day ago)
Aggressive web scan
Web App Attack
🇧🇪
cmbplf
2026-09-07 06:36:35
(1 day ago)
493 requests with url.path *.azure/*
145 requests with url.path */auth.json
Brute-Force
Bad Web Bot
🇳🇱
WeCloudit-Anti-Abuse
2026-09-07 06:18:24
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-07 05:40:58
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.222.27.219 (219.27.222.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.222.27.219 (219.27.222.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 01:40:54.889707 2026] [security2:error] [pid 3400:tid 3400] [client 35.222.27.219:11546] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "desoucey.com"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252froot/.env"] [unique_id "ap5OZjubKcSk70om9P03wQAAAF4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 05:09:23
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.222.27.219 (219.27.222.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.222.27.219 (219.27.222.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 01:09:15.893047 2026] [security2:error] [pid 18749:tid 18749] [client 35.222.27.219:36752] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.waggonerfinancial.com"] [uri "/@fs/.env.local"] [unique_id "ap5G-6_PyCOdmTetEhGHRQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 04:49:08
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.222.27.219 (219.27.222.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.222.27.219 (219.27.222.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 00:49:04.543544 2026] [security2:error] [pid 399:tid 399] [client 35.222.27.219:3846] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.sweetbailey.com"] [uri "/@fs/.env.local"] [unique_id "ap5CQE2y1FREjxv3ahXU0QAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-09-07 04:36:34
(1 day ago)
Web attack/malicious scanning detected
Web App Attack