🇧🇾
lns.bz
2026-09-07 09:59:41
(4 hours ago)
Too many 404 requests [BY]
Web App Attack
🇺🇸
superflea2828
2026-09-07 08:22:50
(6 hours ago)
35.229.54.39 - - [07/Sep/2026:08:22:48 +0000] "GET /admin/phpinfo.php HTTP/1.1" 404 476 "-" "Mozilla ...
show more
35.229.54.39 - - [07/Sep/2026:08:22:48 +0000] "GET /admin/phpinfo.php HTTP/1.1" 404 476 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0 Safari/537.36"
...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 03:52:42
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.229.54.39 (39.54.229.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.229.54.39 (39.54.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:52:37.037750 2026] [security2:error] [pid 11165:tid 11175] [client 35.229.54.39:35022] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.dhsandberg.com"] [uri "/wp-config.php~"] [unique_id "apzjhf1pRt8N7QnZBIknqAAAAEc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 03:01:38
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.229.54.39 (39.54.229.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.229.54.39 (39.54.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:01:33.012774 2026] [security2:error] [pid 4679:tid 4679] [client 35.229.54.39:59164] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wingblade.net"] [uri "/wp-config.php~"] [unique_id "apzXjaWmjRdH0TgRIDbR2wAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 01:09:19
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.229.54.39 (39.54.229.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.229.54.39 (39.54.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 21:09:13.050109 2026] [security2:error] [pid 21293:tid 21293] [client 35.229.54.39:38608] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.infraredovens.net"] [uri "/.env.backup"] [unique_id "apy9Ocr6UPQ7gp42C3Dz4AAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
raph
2026-09-05 23:58:02
(1 day ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 23:55:07
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.229.54.39 (39.54.229.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.229.54.39 (39.54.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 19:55:01.947763 2026] [security2:error] [pid 10632:tid 10632] [client 35.229.54.39:43626] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.cosplayculture.com"] [uri "/.env.local"] [unique_id "apyr1XabfRcuruT89OAJegAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
mnsf
2026-09-05 23:06:00
(1 day ago)
Scanning/Probing (20)
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 22:55:04
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.229.54.39 (39.54.229.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.229.54.39 (39.54.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 18:54:59.742215 2026] [security2:error] [pid 11579:tid 11579] [client 35.229.54.39:37920] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.kemela.com"] [uri "/.env"] [unique_id "apydw19JcXHsF153uyIrYwAAACk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 22:36:15
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.229.54.39 (39.54.229.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.229.54.39 (39.54.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 18:36:08.445119 2026] [security2:error] [pid 27129:tid 27129] [client 35.229.54.39:60038] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ftp.oceanicpier.com"] [uri "/.env.production"] [unique_id "apyZWPS8OK5mZugPFS7ufQAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-09-05 22:23:00
(1 day ago)
Web attack/malicious scanning detected
Web App Attack
🇨🇭
ca
2026-09-05 22:17:25
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-crawl-non_statics
Web App Attack
Bad Web Bot
🇳🇱
homeshowdomain.nl
2026-09-05 21:59:18
(1 day ago)
Auto-ban: >3000 req/min op 2026-09-05
Web App Attack
SSH
Hacking
🇺🇸
TPI-Abuse
2026-09-05 21:43:14
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.229.54.39 (39.54.229.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.229.54.39 (39.54.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 17:43:07.379967 2026] [security2:error] [pid 10283:tid 10283] [client 35.229.54.39:46168] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "radtraininginc.radtraininginc.net"] [uri "/.env.local"] [unique_id "apyM61jT3BoEvQZICtJfmgAAAC8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
FD-IX
2026-09-05 21:28:15
(1 day ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack