🇳🇱
e.fierstra
2026-09-07 10:42:07
(10 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇫🇷
Octopuce
2026-09-07 10:17:21
(10 hours ago)
Aggressive web search of vulnerable pages: /v1/.env /uploads../.env /v2/.env /.docker/.env /assets.. ...
show more
Aggressive web search of vulnerable pages: /v1/.env /uploads../.env /v2/.env /.docker/.env /assets../.env ...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 09:43:19
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.223.43.131 (131.43.223.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.223.43.131 (131.43.223.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 05:43:11.610121 2026] [security2:error] [pid 27424:tid 27424] [client 35.223.43.131:60282] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "diamenty.info"] [uri "/@fs/.env.development"] [unique_id "ap6HL-g-ztxS5ULdL20SXgAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-07 09:14:38
(11 hours ago)
Aggressive web scan
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 09:01:42
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.223.43.131 (131.43.223.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.223.43.131 (131.43.223.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 05:01:35.652022 2026] [security2:error] [pid 20822:tid 20822] [client 35.223.43.131:52398] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.clients.kinareemagazine.com"] [uri "/@fs/.env.development"] [unique_id "ap59bxG3IOYZ2-yqFvi40wAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-07 08:50:12
(12 hours ago)
Bot / seems abusive / Apache connections: 30
DDoS Attack
Web Spam
Bad Web Bot
Web App Attack
🇨🇭
backslash
2026-09-07 05:42:01
(15 hours ago)
block ruleset WAF detection and high score on abuseIPDB 149EB1B42C242111FADBBC2EF8F90219570691E1
Bad Web Bot
🇺🇸
IndigoRidge
2026-09-07 05:37:43
(15 hours ago)
[07/Sep/2026:01:37:42.253729 --0400] ap5NppOb1TZn2PAf0uwkwgAAAsg 35.223.43.131 58360 205.233.18.17 7 ...
show more
[07/Sep/2026:01:37:42.253729 --0400] ap5NppOb1TZn2PAf0uwkwgAAAsg 35.223.43.131 58360 205.233.18.17 7081
[07/Sep/2026:01:37:42.262262 --0400] ap5NppOb1TZn2PAf0uwkxAAAAsw 35.223.43.131 58436 205.233.18.17 7081
[07/Sep/2026:01:37:42.263047 --0400] ap5NppOb1TZn2PAf0uwkxQAAAtA 35.223.43.131 58430 205.233.18.17 7081
[07/Sep/2026:01:37:42.264233 --0400] ap5NppOb1TZn2PAf0uwkxwAAAtY 35.223.43.131 58408 205.233.18.17 7081
[07/Sep/2026:01:37:42.266175 --0400] ap5NppOb1TZn2PAf0uwkyQAAAsU 35.223.43.131 58376 205.233.18.17 7081
...
show less
Hacking
Anonymous
2026-09-07 05:35:47
(15 hours ago)
Multiple web server 400 error codes from same source ip
Web App Attack
🇳🇱
Savvii
2026-09-07 05:23:01
(15 hours ago)
20 attempts against mh-misbehave-ban on eris
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Site.eu
2026-09-07 05:21:34
(15 hours ago)
Excessive multi-domain requests
Brute-Force
🇺🇸
TPI-Abuse
2026-09-07 05:14:21
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.223.43.131 (131.43.223.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.223.43.131 (131.43.223.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 01:14:13.481705 2026] [security2:error] [pid 7952:tid 7952] [client 35.223.43.131:1204] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.bridgenevercrossed.banis-associates.com"] [uri "/@fs/src/.env"] [unique_id "ap5IJe7Yl6-1nHQg-rKBoAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
iGroupware
2026-09-07 05:07:57
(15 hours ago)
{"req/ip"=>{:discriminator=>"35.223.43.131", :count=>501, :period=>180, :limit=>500, :epoch_time=>17 ...
show more
{"req/ip"=>{:discriminator=>"35.223.43.131", :count=>501, :period=>180, :limit=>500, :epoch_time=>1788757677}}
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 04:45:58
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.223.43.131 (131.43.223.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.223.43.131 (131.43.223.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 00:45:52.374832 2026] [security2:error] [pid 1044:tid 1044] [client 35.223.43.131:59640] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.safetyfastclub.com"] [uri "/@fs/.env.production"] [unique_id "ap5BgISH_pJzbWzmFQBKegAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 04:17:00
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.223.43.131 (131.43.223.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.223.43.131 (131.43.223.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 00:16:54.282664 2026] [security2:error] [pid 29371:tid 29371] [client 35.223.43.131:4540] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.naturalpozzolanassociation.org"] [uri "/@fs/../.env"] [unique_id "ap46thu5tpXfVRhNkiXeRgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack