🇹🇷
Threat.live
2026-09-05 06:45:02
(36 minutes ago)
Suspicious Connection Attempts
Brute-Force
🇺🇸
TPI-Abuse
2026-09-04 15:15:09
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.228.15.127 (127.15.228.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.228.15.127 (127.15.228.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 11:15:05.502835 2026] [security2:error] [pid 5892:tid 5892] [client 35.228.15.127:43510] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.idonthaveawebpage.com"] [uri "/.env.old"] [unique_id "aprgeXK0_tMB9gE5g92thwAAACg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇲🇾
Rizzy
2026-09-04 15:00:02
(16 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 14:08:28
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.228.15.127 (127.15.228.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.228.15.127 (127.15.228.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 10:08:22.059374 2026] [security2:error] [pid 23462:tid 23462] [client 35.228.15.127:42034] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wavecomputers.com"] [uri "/.env.example"] [unique_id "aprQ1vGEEndfDGGm5dMaaAAAAFA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 13:28:25
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.228.15.127 (127.15.228.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.228.15.127 (127.15.228.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 09:28:19.837449 2026] [security2:error] [pid 21226:tid 21226] [client 35.228.15.127:43828] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "solporpoise.com"] [uri "/.env.production"] [unique_id "aprHc2fgENaXR0hpidksrAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 12:31:57
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.228.15.127 (127.15.228.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.228.15.127 (127.15.228.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 08:31:53.528385 2026] [security2:error] [pid 6408:tid 6408] [client 35.228.15.127:53626] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "globalaccessadvisors.com.salsberggroup.com"] [uri "/.env.bak"] [unique_id "apq6OfR4U53I_y_uYw8EDAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
debestelapp
2026-09-04 11:50:11
(19 hours ago)
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 11:34:26
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.228.15.127 (127.15.228.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.228.15.127 (127.15.228.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 07:34:20.081383 2026] [security2:error] [pid 3858:tid 3858] [client 35.228.15.127:49150] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "edenberg.com"] [uri "/.env.production"] [unique_id "apqsvA02YYHC18DSYiqumwAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-09-04 11:34:04
(19 hours ago)
Web attack/malicious scanning detected
Web App Attack
🇭🇺
miszterx.hu
2026-09-04 11:05:15
(20 hours ago)
XORP (haproxy): 3x HTTP 404/403/500 or handshake failure in 24h. Automated report from log_check_ipt ...
show more
XORP (haproxy): 3x HTTP 404/403/500 or handshake failure in 24h. Automated report from log_check_iptables_generator.sh (xorp.hu)
show less
Web App Attack
🇩🇪
BlueWire Hosting
2026-09-04 10:44:39
(20 hours ago)
High-confidence malicious configuration/VCS probe
Web App Attack
🇩🇪
Gwyneth Llewelyn
2026-09-04 10:23:31
(20 hours ago)
2026/09/04 11:23:24 [error] 380596#380596: *2761600 access forbidden by rule, client: 35.228.15.127, ...
show more
2026/09/04 11:23:24 [error] 380596#380596: *2761600 access forbidden by rule, client: 35.228.15.127, server: operadotejo.org, request: "GET /.env HTTP/2.0", host: "operadotejo.org"
35.228.15.127 - - [04/Sep/2026:11:23:24 +0100] "GET /.env HTTP/2.0" 403 95 "-" "crusader-worker/1.0"
2026/09/04 11:23:28 [error] 380596#380596: *2761600 access forbidden by rule, client: 35.228.15.127, server: operadotejo.org, request: "GET //.env HTTP/2.0", host: "operadotejo.org"
show less
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 10:18:02
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.228.15.127 (127.15.228.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.228.15.127 (127.15.228.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:17:58.983007 2026] [security2:error] [pid 19057:tid 19057] [client 35.228.15.127:52470] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ourcritterguy.azcrittergetter.com"] [uri "/.env.example"] [unique_id "apqa1i7inwtL8n4NWPufgAAAAFA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-04 10:07:03
(21 hours ago)
Automated web scanner. Requested suspicious paths: /actuator/env | /.env.bak | /actuator/configprops ...
show more
Automated web scanner. Requested suspicious paths: /actuator/env | /.env.bak | /actuator/configprops | /.env.local | /_ignition/health-check | /.env.example | /.env.prod | /.env.production | /.env.backup | /.env | /.env.save | /.env.dev. UTC: 2026-09-04 09:34:40.
show less
Web App Attack
🇨🇭
zynex
2026-09-04 09:58:47
(21 hours ago)
URL Probing: /wp-config.php~
Web App Attack