🇺🇸
TPI-Abuse
2026-09-06 02:53:51
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.234.154.24 (24.154.234.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.234.154.24 (24.154.234.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:53:46.685137 2026] [security2:error] [pid 18452:tid 18452] [client 35.234.154.24:59556] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "partyblockbaby.com"] [uri "/.env.prod"] [unique_id "apzVukmeV5ZpqDPOQB3yHQAAAHk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
raph
2026-09-06 02:43:45
(8 hours ago)
[Wordpress] crawler /wp-admin/*, /wp-content/*, etc.
Bad Web Bot
Web App Attack
🇩🇪
ddobko
2026-09-06 02:26:46
(8 hours ago)
Bad Web Bot
Web App Attack
🇩🇪
neckaralb-admin.de
2026-09-06 02:08:38
(9 hours ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 00:46:00
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.234.154.24 (24.154.234.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.234.154.24 (24.154.234.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 20:45:54.377441 2026] [security2:error] [pid 12885:tid 12885] [client 35.234.154.24:33640] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "abbeygardensllandudno.com"] [uri "/.env.bak"] [unique_id "apy3wj3UEEElg4me-eiTdgAAAHc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
mnsf
2026-09-06 00:05:37
(11 hours ago)
Scanning/Probing (20)
Brute-Force
Web App Attack
🇬🇧
Celtic
2026-09-05 23:53:26
(11 hours ago)
Blocked by Fail2Ban with Jail (plesk-modsecurity)
Brute-Force
SSH
🇬🇧
consul.to
2026-09-05 23:27:47
(11 hours ago)
Web attack/malicious scanning detected
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 23:21:53
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.234.154.24 (24.154.234.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.234.154.24 (24.154.234.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 19:21:48.902266 2026] [security2:error] [pid 16947:tid 16947] [client 35.234.154.24:46020] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kratka.com"] [uri "/.env.save"] [unique_id "apykDMbNustQ49o7Tz0adQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 22:56:45
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.234.154.24 (24.154.234.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.234.154.24 (24.154.234.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 18:56:40.828745 2026] [security2:error] [pid 23349:tid 23349] [client 35.234.154.24:60786] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.homecheckinmaine.com"] [uri "/.env.old"] [unique_id "apyeKPcn-a_dvo84VpLOHAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
lavnet.net
2026-09-05 22:41:40
(12 hours ago)
35.234.154.24 - - [05/Sep/2026:22:41:39 +0000] "GET /.env.local HTTP/1.1" 404 6087 "-" "crusader-wor ...
show more
35.234.154.24 - - [05/Sep/2026:22:41:39 +0000] "GET /.env.local HTTP/1.1" 404 6087 "-" "crusader-worker/1.0"
35.234.154.24 - - [05/Sep/2026:22:41:39 +0000] "GET /.env.backup HTTP/1.1" 404 6087 "-" "crusader-worker/1.0"
35.234.154.24 - - [05/Sep/2026:22:41:39 +0000] "GET /.env.prod HTTP/1.1" 404 6089 "-" "crusader-worker/1.0"
35.234.154.24 - - [05/Sep/2026:22:41:39 +0000] "GET /.env.production HTTP/1.1" 404 6088 "-" "crusader-worker/1.0"
35.234.154.24 - - [05/Sep/2026:22:41:39 +0000] "GET /.env.dev HTTP/1.1" 404 6088 "-" "crusader-worker/1.0"
35.234.154.24 - - [05/Sep/2026:22:41:39 +0000] "GET /actuator/configprops HTTP/1.1" 404 6088 "-" "crusader-worker/1.0"
...
show less
Brute-Force
Anonymous
2026-09-05 22:15:24
(12 hours ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 22:13:10
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.234.154.24 (24.154.234.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.234.154.24 (24.154.234.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 18:13:04.123724 2026] [security2:error] [pid 3505773:tid 3505848] [client 35.234.154.24:59664] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mysavvygourmet.meanmouse.com"] [uri "/.env.example"] [unique_id "apyT8CcrIQhcuqFjqhXEHQAAAVI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
SilverZippo
2026-09-05 22:03:07
(13 hours ago)
Web App Attack
Web App Attack
🇺🇦
URAN Publishing Service
2026-09-05 22:01:44
(13 hours ago)
[06/Sep/2026:01:01:44 +0300] -- 35.234.154.24 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET / ...
show more
[06/Sep/2026:01:01:44 +0300] -- 35.234.154.24 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET /.env HTTP/1.1
show less
Bad Web Bot
Web App Attack