🇺🇸
TPI-Abuse
2026-08-29 03:08:53
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.229.111.107 (107.111.229.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.229.111.107 (107.111.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 23:08:49.446875 2026] [security2:error] [pid 24699:tid 24699] [client 35.229.111.107:43446] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "furbabieslivesmatter.com"] [uri "/.env.bak"] [unique_id "apJNQUAKF0JyPw8X_FDVUQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
patrisei
2026-08-29 03:04:13
(16 hours ago)
You are now banned for 10 years by Schiffdorf-West Patrol. Trigger: crowdsecurity/http-sensitive-fil ...
show more
You are now banned for 10 years by Schiffdorf-West Patrol. Trigger: crowdsecurity/http-sensitive-files
show less
Port Scan
Web App Attack
🇺🇸
Lee Daniel
2026-08-29 02:59:33
(16 hours ago)
35.229.111.107 - - [28/Aug/2026:22:59:33 -0400] "GET /.env HTTP/1.1" 403 6296 "-" "crusader-worker/1 ...
show more
35.229.111.107 - - [28/Aug/2026:22:59:33 -0400] "GET /.env HTTP/1.1" 403 6296 "-" "crusader-worker/1.0"
...
show less
DDoS Attack
Web Spam
Email Spam
Port Scan
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
FeG Deutschland
2026-08-29 01:45:13
(17 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 1247
Exploited Host
Web App Attack
🇫🇮
paissangroup
2026-08-29 00:38:16
(18 hours ago)
Multiple WAF Violations
Web App Attack
Anonymous
2026-08-29 00:07:02
(19 hours ago)
Automated web scanner. Requested suspicious paths: /.env.bak | /storage/logs/laravel.log | /.env.bac ...
show more
Automated web scanner. Requested suspicious paths: /.env.bak | /storage/logs/laravel.log | /.env.backup | /.env.prod | /.env.example | /crusader-404-probe | /.env.dev | /.env, /.env.old | /storage/logs/laravel.log | /.env.backup | /.env.prod | /.env.example | /crusader-404-probe | /.env.dev | /.env. UTC: 2026-08-28 23:22:52.
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-08-28 23:32:38
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.229.111.107 (107.111.229.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.229.111.107 (107.111.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 19:32:30.138491 2026] [security2:error] [pid 1646:tid 1646] [client 35.229.111.107:48398] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.globaldentalservices.com"] [uri "/.env"] [unique_id "apIajkwgSdSd9APMPxBt9wAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-28 23:11:04
(20 hours ago)
Fail2Ban: 2026/08/28 23:11:04 [info] 18779#18779: *32453 client sent no required SSL certificate whi ...
show more
Fail2Ban: 2026/08/28 23:11:04 [info] 18779#18779: *32453 client sent no required SSL certificate while reading client request headers, client: 35.229.111.107, server: dash.ddns.schauwecker.eu, request: "GET /.env.save HTTP/1.1", host: "dash.ddns.schauwecker.eu"
2026/08/28 23:11:04 [info] 18780#18780: *32458 client sent no required SSL certificate while reading client request headers, client: 35.229.111.107, server: dash.ddns.schauwecker.eu, request: "GET /.env.old HTTP/1.1", host: "dash.ddns.schauwecker.eu"
2026/08/28 23:11:04 [info] 18784#18784: *32454 client sent no required SSL certificate while reading client request headers, client: 35.229.111.107, server: dash.ddns.schauwecker.eu, request: "GET /actuator/env HTTP/1.1", host: "dash.ddns.schauwecker.eu"
show less
Hacking
🇺🇸
TPI-Abuse
2026-08-28 20:58:32
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.229.111.107 (107.111.229.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.229.111.107 (107.111.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 16:58:26.078511 2026] [security2:error] [pid 32323:tid 32323] [client 35.229.111.107:44916] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.notariaramirez.cl.tecnoconce.com"] [uri "/.env.dev"] [unique_id "apH2ci1jWzkElrepoDgEegAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇾
lns.bz
2026-08-28 20:24:59
(23 hours ago)
Too many 404 requests [BY]
Web App Attack
🇺🇸
TPI-Abuse
2026-08-28 20:02:54
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.229.111.107 (107.111.229.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.229.111.107 (107.111.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 16:02:49.131286 2026] [security2:error] [pid 30930:tid 30930] [client 35.229.111.107:34890] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "leirstein.com"] [uri "/.env.prod"] [unique_id "apHpaX0RY9rJszr5DK-aOwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇲🇾
Rizzy
2026-08-28 19:56:47
(23 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack
🇺🇸
kosada.com
2026-08-28 19:38:58
(23 hours ago)
Web vulnerability probing: /.env.production
Web App Attack
🇫🇷
Little Iguana
2026-08-28 19:12:47
(1 day ago)
Attempt to hack Wordpress Login, XMLRPC or other login
Hacking
🇩🇪
itsolon
2026-08-28 19:07:04
(1 day ago)
[28/Aug/2026:21:07:03 +0200] 178794402340.307904 35.229.111.107 33696 217.154.7.177 443
[28/Aug/2026 ...
show more
[28/Aug/2026:21:07:03 +0200] 178794402340.307904 35.229.111.107 33696 217.154.7.177 443
[28/Aug/2026:21:07:03 +0200] 178794402349.956531 35.229.111.107 33608 217.154.7.177 443
[28/Aug/2026:21:07:03 +0200] 178794402338.982720 35.229.111.107 33754 217.154.7.177 443
[28/Aug/2026:21:07:03 +0200] 178794402399.829383 35.229.111.107 33664 217.154.7.177 443
[28/Aug/2026:21:07:03 +0200] 178794402356.674706 35.229.111.107 33680 217.154.7.177 443
...
show less
Port Scan
Hacking
Brute-Force
Web App Attack