🇺🇸
SYSMarshal
2026-09-04 15:08:05
(2 hours ago)
SYSMarshal detection: Port Scanning, Web Application Attack, DDoS Attack, DNS Attack, Bad Bot [Port: ...
show more
SYSMarshal detection: Port Scanning, Web Application Attack, DDoS Attack, DNS Attack, Bad Bot [Port:443, Proto:TCP, EventID:5152]
show less
Port Scan
Web App Attack
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-04 14:09:53
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.229.157.54 (54.157.229.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.229.157.54 (54.157.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 10:09:44.937698 2026] [security2:error] [pid 8296:tid 8307] [client 35.229.157.54:58598] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wakhan-adventure.com"] [uri "/.env.old"] [unique_id "aprRKKhTWN4V_haVdZmJeQAAAEU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 13:38:28
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.229.157.54 (54.157.229.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.229.157.54 (54.157.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 09:38:25.338727 2026] [security2:error] [pid 3832:tid 3832] [client 35.229.157.54:51564] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fitzcosound.com"] [uri "/.env.production"] [unique_id "aprJ0QEEiQxij8dVuMdeIwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
e.fierstra
2026-09-04 13:28:58
(4 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇩🇪
LRob
2026-09-04 12:57:06
(5 hours ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /wp-config.php.bak (+12 more) | 2026-09-04 12:57 UTC
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 11:16:59
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.229.157.54 (54.157.229.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.229.157.54 (54.157.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 07:16:52.308235 2026] [security2:error] [pid 15385:tid 15385] [client 35.229.157.54:60862] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.cdromline.com"] [uri "/.env.prod"] [unique_id "apqopNTRHw135UVNIi6VtAAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 09:34:57
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.229.157.54 (54.157.229.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.229.157.54 (54.157.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 05:34:50.210339 2026] [security2:error] [pid 21854:tid 21854] [client 35.229.157.54:60466] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "randebrewer.com"] [uri "/.env.prod"] [unique_id "apqQuv-PjNoqOluAKnyWIQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
dynamix
2026-09-04 09:13:04
(8 hours ago)
Multiple WAF Violations
Web App Attack
🇬🇧
consul.to
2026-09-04 08:42:23
(9 hours ago)
Web attack/malicious scanning detected
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 08:38:47
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.229.157.54 (54.157.229.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.229.157.54 (54.157.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 04:38:41.564710 2026] [security2:error] [pid 3678:tid 3678] [client 35.229.157.54:36014] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rebelhollowfarm.com"] [uri "/.env"] [unique_id "apqDkcNmsqQQMjmaOdkx5QAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
masterguru
2026-09-04 08:28:44
(9 hours ago)
Attempt to access a backup or working file. Pattern match "\\\\. (920500-193)
Hacking
🇳🇱
WeCloudit-Anti-Abuse
2026-09-04 08:26:21
(9 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-04 08:18:55
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.229.157.54 (54.157.229.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.229.157.54 (54.157.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 04:18:50.202537 2026] [security2:error] [pid 4612:tid 4612] [client 35.229.157.54:60458] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.madisonjazzorchestra.com"] [uri "/wp-config.php.bak"] [unique_id "app-6k-BWPhWBk1i4FDlEAAAADc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇸🇪
vaia.cloud
2026-09-04 07:45:07
(10 hours ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 07:30:41
(10 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.229.157.54 (54.157.229.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.229.157.54 (54.157.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 03:30:33.209979 2026] [security2:error] [pid 19299:tid 19299] [client 35.229.157.54:55408] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||brbcar.usaangelinvestors.com|F|2"] [data ".env.old"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "brbcar.usaangelinvestors.com"] [uri "/.env.old"] [unique_id "appzmUwwkbBNYU1_oMG-lwAAAGY"]
show less
Brute-Force
Bad Web Bot
Web App Attack