πΊπΈ
TPI-Abuse
2026-08-27 19:04:39
(1 minute ago)
(mod_security) mod_security (id:210492) triggered by 35.226.148.10 (10.148.226.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.226.148.10 (10.148.226.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 15:04:33.890029 2026] [security2:error] [pid 3364195:tid 3364286] [client 35.226.148.10:44780] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.staging.torreydc.com"] [uri "/.env.prod"] [unique_id "apCKQaE9v3ZLmkSxwf5ZaQAAAZQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-27 18:30:03
(36 minutes ago)
| Suspicious URL access.
Web App Attack
Hacking
SQL Injection
πΊπΈ
TPI-Abuse
2026-08-27 18:03:05
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 35.226.148.10 (10.148.226.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.226.148.10 (10.148.226.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 14:02:58.176241 2026] [security2:error] [pid 28300:tid 28300] [client 35.226.148.10:40128] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.cyberv.info.networkmediasoftware.com"] [uri "/.env.backup"] [unique_id "apB70rxrEfQ3z-xGk4SQOAAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΈπͺ
vaia.cloud
2026-08-27 16:10:01
(2 hours ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-27 15:58:34
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.226.148.10 (10.148.226.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.226.148.10 (10.148.226.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 11:58:26.629955 2026] [security2:error] [pid 20373:tid 20373] [client 35.226.148.10:35978] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gp-cm.com"] [uri "/.env.save"] [unique_id "apBeojNsQLyaax6OaUlEDgAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-27 15:33:36
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.226.148.10 (10.148.226.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.226.148.10 (10.148.226.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 11:33:28.107450 2026] [security2:error] [pid 21925:tid 21925] [client 35.226.148.10:42240] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kaleidoscope-glass.com"] [uri "/wp-config.php~"] [unique_id "apBYyCv4rqaLyoxl5vI-UwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
GabrielJST
2026-08-27 14:47:51
(4 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 35.226.148.10 (US/United States/10.148. ...
show more
(mod_security) mod_security triggered on hostname [redacted] 35.226.148.10 (US/United States/10.148.226.35.bc.googleusercontent.com): (CF_ENABLE)
show less
SQL Injection
π«π·
COMAITE
2026-08-27 14:40:27
(4 hours ago)
Suspicious URL access.
Web App Attack
π«π·
breubit
2026-08-27 13:56:52
(5 hours ago)
35.226.148.10 - - [27/Aug/2026:15:56:51 +0200] "GET /.env.old HTTP/1.1" 403 4468 "-" "crusader-worke ...
show more
35.226.148.10 - - [27/Aug/2026:15:56:51 +0200] "GET /.env.old HTTP/1.1" 403 4468 "-" "crusader-worker/1.0"
...
show less
Web App Attack
πΊπΈ
magnetosphere-tarpit
2026-08-27 13:53:02
(5 hours ago)
Automated web scanner: repeatedly probed for .env, .git, wp-admin and PHP webshell paths that do not ...
show more
Automated web scanner: repeatedly probed for .env, .git, wp-admin and PHP webshell paths that do not exist on this host. Tarpitted, then banned: 10 requests within 24h0m0s
show less
Port Scan
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-27 13:45:19
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.226.148.10 (10.148.226.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.226.148.10 (10.148.226.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 09:45:06.527779 2026] [security2:error] [pid 10122:tid 10122] [client 35.226.148.10:54836] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "emilybaotrannguyen.com"] [uri "/.env"] [unique_id "apA_YszAoQfHpuLNAANDIwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¨π
Origon
2026-08-27 13:40:56
(5 hours ago)
http-sensitive-files - IP: 35.226.148.10 - time="2026-08-27T15:40:55+02:00" level=info msg="(555f66 ...
show more
http-sensitive-files - IP: 35.226.148.10 - time="2026-08-27T15:40:55+02:00" level=info msg="(555f66b4f6a74558bc11e3f93469658es8App0Mcc0TKEeje/crowdsec) crowdsecurity/http-sensitive-files by ip 35.226.148.10 (US/396982) : 4h ban on Ip 35.226.148.10" module=db
show less
Web App Attack
πΊπΈ
Lee Daniel
2026-08-27 13:04:13
(6 hours ago)
35.226.148.10 - - [27/Aug/2026:09:04:13 -0400] "GET /.env HTTP/1.1" 403 6287 "-" "crusader-worker/1. ...
show more
35.226.148.10 - - [27/Aug/2026:09:04:13 -0400] "GET /.env HTTP/1.1" 403 6287 "-" "crusader-worker/1.0"
...
show less
DDoS Attack
Web Spam
Email Spam
Port Scan
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-27 12:28:44
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.226.148.10 (10.148.226.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.226.148.10 (10.148.226.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 08:28:38.669968 2026] [security2:error] [pid 4865:tid 4865] [client 35.226.148.10:39656] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.evinify.marshvineyards.com"] [uri "/.env.production"] [unique_id "apAtdjDzCET0PjQNBWr22AAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π·π΄
iulianh
2026-08-27 12:25:32
(6 hours ago)
80,443
Brute-Force
SSH