🇺🇸
TPI-Abuse
2026-09-04 12:03:04
(18 minutes ago)
(mod_security) mod_security (id:210492) triggered by 35.230.91.248 (248.91.230.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.230.91.248 (248.91.230.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 08:02:57.236749 2026] [security2:error] [pid 20241:tid 20241] [client 35.230.91.248:40430] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tecnoconce.cl"] [uri "/wp-config.php.bak"] [unique_id "apqzcUlb59a8VtVHQliOGAAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 11:44:32
(37 minutes ago)
(mod_security) mod_security (id:210492) triggered by 35.230.91.248 (248.91.230.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.230.91.248 (248.91.230.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 07:44:27.326804 2026] [security2:error] [pid 31118:tid 31118] [client 35.230.91.248:51998] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.aangfl.com"] [uri "/.env.local"] [unique_id "apqvG3cFDnMBA8iaWs5kjgAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 11:16:15
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 35.230.91.248 (248.91.230.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.230.91.248 (248.91.230.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 07:16:10.887094 2026] [security2:error] [pid 6413:tid 6413] [client 35.230.91.248:58652] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.computersraleigh.com"] [uri "/.env.example"] [unique_id "apqoenbDOY1RLi4gYDrwhAAAAEQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 10:37:29
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 35.230.91.248 (248.91.230.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.230.91.248 (248.91.230.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:37:23.569750 2026] [security2:error] [pid 13424:tid 13424] [client 35.230.91.248:60728] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "angeladuffin.com"] [uri "/.env"] [unique_id "apqfY8X4TiWmxSCe897E7gAAAGo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
arnisolutions
2026-09-04 10:33:37
(1 hour ago)
Vulnerability scanning (requests for admin panels, shells, backup files etc.) against a production s ...
show more
Vulnerability scanning (requests for admin panels, shells, backup files etc.) against a production server. Observed on 1 day(s) between 2026-09-04 and 2026-09-04 (UTC). Sample request: GET /.env.save HTTP/2.0
show less
Web App Attack
Hacking
Anonymous
2026-09-04 10:15:01
(2 hours ago)
suspicious request in access.log
Web App Attack
🇩🇪
raph
2026-09-04 10:10:39
(2 hours ago)
[Wordpress] crawler /wp-admin/*, /wp-content/*, etc.
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 08:37:50
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.230.91.248 (248.91.230.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.230.91.248 (248.91.230.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 04:37:45.105348 2026] [security2:error] [pid 11451:tid 11451] [client 35.230.91.248:40210] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "redvers.net"] [uri "/.env.old"] [unique_id "apqDWaqvFqenDmd_zithCgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-04 08:31:45
(3 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇳🇴
jad-abuse
2026-09-04 08:15:42
(4 hours ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: source_ba ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: source_backup, scanner_ua, env_probe, actuator, config_backup, ignition_debug. Observed by 1 sensor(s); 19 hits.
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 08:00:28
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.230.91.248 (248.91.230.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.230.91.248 (248.91.230.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 04:00:21.602685 2026] [security2:error] [pid 4691:tid 4789] [client 35.230.91.248:53134] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "veganfiestas.com.teritemme.com"] [uri "/.env.production"] [unique_id "app6lYZiW6PqWYUwGvUUUQAAAQg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
zwebvigil
2026-09-04 07:46:01
(4 hours ago)
35.230.91.248 [04/Sep/2026:00:46:01 -0700] "GET /wp-config.php~ HTTP/1.1" 404 2693 "-" port=39390 " ...
show more
35.230.91.248 [04/Sep/2026:00:46:01 -0700] "GET /wp-config.php~ HTTP/1.1" 404 2693 "-" port=39390 "crusader-worker/1.0" "-" "-" "<host>" 3104
35.230.91.248 [04/Sep/2026:00:46:01 -0700] "GET /storage/logs/laravel.log HTTP/1.1" 404 2713 "-" port=39530 "crusader-worker/1.0" "-" "-" "<host>" 2300
35.230.91.248 [04/Sep/2026:00:46:01 -0700] "GET /.env HTTP/1.1" 404 2673 "-" port=39494 "crusader-worker/1.0" "-" "-" "<host>" 3270
35.230.91.248 [04/Sep/2026:00:46:01 -0700] "GET /.env.old HTTP/1.1" 404 2681 "-" port=39386 "crusader-worker/1.0" "-" "-" "<host>" 3864
35.230.91.248 [04/Sep/2026:00:46:01 -0700] "GET /.env.production HTTP/1.1" 404 2695 "-" port=39454 "crusader-worker/1.0" "-" "-" "<host>" 2559
35.230.91.248 [04/Sep/2026:00:46:01 -0700] "GET /.env.dev HTTP/1.1" 404 2681 "-" port=39414 "crusader-worker/1.0" "-" "
show less
Web App Attack
🇬🇧
consul.to
2026-09-04 07:36:52
(4 hours ago)
Web attack/malicious scanning detected
Web App Attack
Anonymous
2026-09-04 05:49:57
(6 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
🇮🇹
VHosting
2026-09-04 04:35:03
(7 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack