๐บ๐ธ
TPI-Abuse
2026-09-01 13:48:17
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.225.34.116 (116.34.225.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.225.34.116 (116.34.225.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 09:48:13.632287 2026] [security2:error] [pid 17582:tid 17582] [client 35.225.34.116:44406] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.tech-servusa.com"] [uri "/.env.production"] [unique_id "apbXnXVCCDEq7FZntFcp7AAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
dbmwebdesign
2026-09-01 12:45:03
(3 hours ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
๐ฉ๐ช
LRob
2026-09-01 12:31:39
(3 hours ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.env.old (+10 more) | 2026-09-01 12:31 UTC
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 12:18:27
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.225.34.116 (116.34.225.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.225.34.116 (116.34.225.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 08:18:20.078126 2026] [security2:error] [pid 15486:tid 15486] [client 35.225.34.116:54554] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "scorpio01.com"] [uri "/wp-config.php.bak"] [unique_id "apbCjHNMjVorvRUeJ2j_xAAAAGA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 11:18:47
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.225.34.116 (116.34.225.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.225.34.116 (116.34.225.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 07:18:44.271250 2026] [security2:error] [pid 30420:tid 30420] [client 35.225.34.116:51668] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "windtime.com"] [uri "/.env.old"] [unique_id "apa0lJTv8jSVHGElBQsYbQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 11:02:33
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.225.34.116 (116.34.225.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.225.34.116 (116.34.225.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 07:02:25.737629 2026] [security2:error] [pid 18441:tid 18441] [client 35.225.34.116:38814] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdryer.com"] [uri "/.env.dev"] [unique_id "apawwbs8P0zUFXwpgsniXQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-09-01 10:53:39
(5 hours ago)
[01/Sep/2026:13:53:38 +0300] -- 35.225.34.116 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.env ...
show more
[01/Sep/2026:13:53:38 +0300] -- 35.225.34.116 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.env.old HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐ฟ๐ฆ
conure.sh
2026-09-01 09:19:39
(6 hours ago)
csagent: score 20.0: wp-config backup grab x2; 1 domain(s) in 0s
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 08:48:43
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.225.34.116 (116.34.225.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.225.34.116 (116.34.225.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 04:48:36.220425 2026] [security2:error] [pid 17063:tid 17063] [client 35.225.34.116:55970] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sendera.imerka.com.mx"] [uri "/.env.production"] [unique_id "apaRZNUZTyGwtDfvC2PN2AAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
pscriptos
2026-09-01 08:48:12
(7 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐ซ๐ฎ
paissangroup
2026-09-01 08:17:32
(7 hours ago)
Multiple WAF Violations
Web App Attack
๐จ๐ญ
zynex
2026-09-01 07:11:02
(9 hours ago)
URL Probing: /wp-config.php.bak
Web App Attack
๐ฌ๐ง
Aetherweb Ark
2026-09-01 06:28:11
(9 hours ago)
(mod_security) mod_security (id:949110) triggered by 35.225.34.116 (US/United States/116.34.225.35.b ...
show more
(mod_security) mod_security (id:949110) triggered by 35.225.34.116 (US/United States/116.34.225.35.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 06:12:46
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.225.34.116 (116.34.225.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.225.34.116 (116.34.225.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 02:12:39.541293 2026] [security2:error] [pid 11969:tid 11969] [client 35.225.34.116:52678] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "llaira.com"] [uri "/.env.dev"] [unique_id "apZs122jeu8cN06WnMUz7AAAADE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
tentwentyfour
2026-09-01 05:43:28
(10 hours ago)
Blocked for probing for sensitive web application components
Brute-Force
Web App Attack