🇺🇸
TPI-Abuse
2026-09-04 15:17:44
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.228.54.211 (211.54.228.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.228.54.211 (211.54.228.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 11:17:36.640599 2026] [security2:error] [pid 1068:tid 1068] [client 35.228.54.211:55076] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.starcrestsales.com"] [uri "/.env.production"] [unique_id "aprhEJ0CevdKqd-Hmkv7KAAAAD8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
dynamix
2026-09-04 14:57:17
(7 hours ago)
Multiple WAF Violations
Web App Attack
🇳🇱
debestelapp
2026-09-04 14:40:11
(7 hours ago)
Web App Attack
🇩🇪
benou2
2026-09-04 14:00:09
(8 hours ago)
crowdsecurity/http-sensitive-files
Port Scan
Hacking
🇩🇪
FD-IX
2026-09-04 12:53:52
(9 hours ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 10:55:21
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.228.54.211 (211.54.228.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.228.54.211 (211.54.228.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:55:16.462066 2026] [security2:error] [pid 31451:tid 31451] [client 35.228.54.211:49164] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "naacd.com"] [uri "/wp-config.php~"] [unique_id "apqjlAQzL2PfuPQuaiW86QAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 10:08:01
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.228.54.211 (211.54.228.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.228.54.211 (211.54.228.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:07:56.659944 2026] [security2:error] [pid 2824996:tid 2825033] [client 35.228.54.211:57908] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jessewallaceart.aussiepens.com"] [uri "/.env.local"] [unique_id "apqYfB0fUXAXMoF-M9ve7wAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
big-cloud.nl
2026-09-04 10:05:01
(12 hours ago)
Try to access /.env
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-04 08:23:59
(14 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇫🇷
masterguru
2026-09-04 08:03:12
(14 hours ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-196)
Hacking
Web App Attack
🇿🇦
conure.sh
2026-09-04 08:02:21
(14 hours ago)
csagent: score 20.0: secrets grab x2; 1 domain(s) in 0s
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 07:44:42
(14 hours ago)
(mod_security) mod_security (id:949110) triggered by 35.228.54.211 (211.54.228.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:949110) triggered by 35.228.54.211 (211.54.228.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 03:44:36.327740 2026] [security2:error] [pid 18142:tid 18142] [client 35.228.54.211:54844] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "ftp.maricotippett.com"] [uri "/.env.save"] [unique_id "app25J3Th4ICTVibDpu98gAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
masterguru
2026-09-04 07:19:16
(15 hours ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-195)
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 07:15:09
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.228.54.211 (211.54.228.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.228.54.211 (211.54.228.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 03:15:04.215900 2026] [security2:error] [pid 26099:tid 26099] [client 35.228.54.211:34604] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "curtchristian.us"] [uri "/.env.production"] [unique_id "appv-GyUJStDqVBuaup9igAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
XICTRON
2026-09-04 07:05:06
(15 hours ago)
ModSecurity rule violation detected by Fail2Ban
Web App Attack