🇺🇸
TPI-Abuse
2026-09-04 15:14:47
(22 minutes ago)
(mod_security) mod_security (id:210492) triggered by 35.229.233.209 (209.233.229.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.229.233.209 (209.233.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 11:14:39.665199 2026] [security2:error] [pid 22288:tid 22358] [client 35.229.233.209:41698] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.degreesoflove.com"] [uri "/.env.backup"] [unique_id "aprgX-rYmpX3tlK6b6xz8gAAAYk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
Sling
2026-09-04 14:59:42
(37 minutes ago)
Automated detection: IP accessed 7 sensitive endpoints within 30s on pprox.slingexe.com. Paths: /.en ...
show more
Automated detection: IP accessed 7 sensitive endpoints within 30s on pprox.slingexe.com. Paths: /.env.example, /.env.local, /.env.production, /storage/logs/laravel.log, /.env.backup, /env, /.env.dev. UA: crusader-worker/1.0.
show less
Web App Attack
Bad Web Bot
Hacking
🇩🇪
macrob
2026-09-04 14:57:40
(39 minutes ago)
2026/09/04 14:57:39 [error] 754821#754821: *556221554 access forbidden by rule, client: 35.229.233.2 ...
show more
2026/09/04 14:57:39 [error] 754821#754821: *556221554 access forbidden by rule, client: 35.229.233.209, server: fn.binixo.es, request: "GET /.env.save HTTP/2.0", host: "pop3.fastcredit.net.ua"
2026/09/04 14:57:39 [error] 754821#754821: *556221553 access forbidden by rule, client: 35.229.233.209, server: fn.binixo.es, request: "GET /.env HTTP/2.0", host: "pop3.fastcredit.net.ua"
2026/09/04 14:57:39 [error] 754818#754818: *556221557 access forbidden by rule, client: 35.229.233.209, server: fn.binixo.es, request: "GET /.env.backup HTTP/2.0", host: "pop3.fastcredit.net.ua"
...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 14:11:40
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 35.229.233.209 (209.233.229.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.229.233.209 (209.233.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 10:11:37.071647 2026] [security2:error] [pid 4008:tid 4008] [client 35.229.233.209:55654] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.boat-registration-hong-kong.com"] [uri "/.env.backup"] [unique_id "aprRmUMio9Zryc9iX36YyQAAAFw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Hazzard
2026-09-04 13:45:56
(1 hour ago)
(mod_security) mod_security triggered on hostname [redacted]): (CF_ENABLE)
SQL Injection
🇫🇮
YF
2026-09-04 13:00:41
(2 hours ago)
WordPress config file probe
Web App Attack
🇩🇪
maxpower
2026-09-04 12:42:29
(2 hours ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 35.229.233.209 (TW/Taiwan/209.233.229.35 ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 35.229.233.209 (TW/Taiwan/209.233.229.35.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 35.229.233.209 - - [04/Sep/2026:14:42:26 +0200] "GET /wp-config.php.bak HTTP/1.1" 403 146 "-" "crusader-worker/1.0" "-" host=51.89.20.64
show less
Port Scan
🇺🇸
TPI-Abuse
2026-09-04 12:26:56
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.229.233.209 (209.233.229.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.229.233.209 (209.233.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 08:26:53.059085 2026] [security2:error] [pid 12683:tid 12683] [client 35.229.233.209:40470] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "zorina.com"] [uri "/.env"] [unique_id "apq5DQgFInJ6Dp_Uo_L2AwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
on-com
2026-09-04 11:47:41
(3 hours ago)
URL scan
Brute-Force
Web App Attack
🇩🇪
FD-IX
2026-09-04 11:21:41
(4 hours ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
🇬🇧
Celtic
2026-09-04 10:50:46
(4 hours ago)
Blocked by Fail2Ban with Jail (plesk-modsecurity)
Brute-Force
SSH
🇺🇸
TPI-Abuse
2026-09-04 10:48:11
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.229.233.209 (209.233.229.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.229.233.209 (209.233.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:48:03.462127 2026] [security2:error] [pid 14153:tid 14153] [client 35.229.233.209:41358] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "virginians.com"] [uri "/wp-config.php.bak"] [unique_id "apqh47GEmcwZU80C33THNQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
masterguru
2026-09-04 10:41:08
(4 hours ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-196)
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 10:11:12
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.229.233.209 (209.233.229.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.229.233.209 (209.233.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:11:05.958125 2026] [security2:error] [pid 20885:tid 20885] [client 35.229.233.209:42054] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kathyquan.com"] [uri "/wp-config.php.swp"] [unique_id "apqZOWZQ5lgeroTYpcn3OAAAADg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
dtorrer
2026-09-04 09:20:10
(6 hours ago)
General vulnerability scan.
Port Scan