🇺🇸
TPI-Abuse
2026-09-08 03:19:52
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.234.86.249 (249.86.234.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.234.86.249 (249.86.234.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 23:19:46.219463 2026] [security2:error] [pid 5605:tid 5698] [client 35.234.86.249:49608] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.oftv.xyz"] [uri "/.env.production"] [unique_id "ap9-0j2YA4KZBVkn7lN4lgAAAEA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
hxsain
2026-09-07 13:49:40
(16 hours ago)
Automated report from CrowdSec: probing for exposed configuration and credential files. 5 events obs ...
show more
Automated report from CrowdSec: probing for exposed configuration and credential files. 5 events observed.
show less
Hacking
Web App Attack
🇳🇱
homeshowdomain.nl
2026-09-06 22:02:49
(1 day ago)
Auto-ban: >3000 req/min op 2026-09-06
Web App Attack
SSH
Hacking
🇩🇪
heyzg
2026-09-06 06:35:37
(2 days ago)
HTTP secret_harvesting (observed): 19 HTTP
Brute-Force
🇩🇪
pscriptos
2026-09-06 06:08:07
(2 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-06 03:02:55
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.234.86.249 (249.86.234.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.234.86.249 (249.86.234.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:02:48.376016 2026] [security2:error] [pid 256171:tid 256185] [client 35.234.86.249:60308] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.tomithai.com"] [uri "/.env.production"] [unique_id "apzX2ChFH94LSFzdoC17fgAAAMk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 02:47:16
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.234.86.249 (249.86.234.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.234.86.249 (249.86.234.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:47:12.282000 2026] [security2:error] [pid 19634:tid 19634] [client 35.234.86.249:36238] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ageh.com"] [uri "/.env.dev"] [unique_id "apzUMIMvwUQPe9O6tuJQkQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 02:10:12
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.234.86.249 (249.86.234.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.234.86.249 (249.86.234.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:09:59.173020 2026] [security2:error] [pid 993:tid 993] [client 35.234.86.249:38186] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "server.adamsclothiers.com"] [uri "/wp-config.php~"] [unique_id "apzLd1QHmmuOm28rMRSEpQAAADM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 01:31:08
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.234.86.249 (249.86.234.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.234.86.249 (249.86.234.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 21:31:03.387910 2026] [security2:error] [pid 8224:tid 8224] [client 35.234.86.249:33870] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "midwayisland.com"] [uri "/wp-config.php.swp"] [unique_id "apzCV1gPAkGf-4BZF-ByEAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-06 01:20:03
(2 days ago)
suspicious request in access.log
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 01:05:32
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.234.86.249 (249.86.234.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.234.86.249 (249.86.234.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 21:05:26.674172 2026] [security2:error] [pid 5013:tid 5013] [client 35.234.86.249:48282] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "30daysout.com.kronrod.com"] [uri "/.env.local"] [unique_id "apy8VgnQxjmllQvD9VaspgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
e.fierstra
2026-09-06 00:30:27
(2 days ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇳🇱
MyGlobalFlowers
2026-09-06 00:17:45
(2 days ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 00:04:04
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.234.86.249 (249.86.234.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.234.86.249 (249.86.234.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 20:04:00.023887 2026] [security2:error] [pid 28694:tid 28694] [client 35.234.86.249:49024] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "barigby.com"] [uri "/.env.bak"] [unique_id "apyt8MBri5nemKegY-r-HwAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-09-05 23:37:30
(2 days ago)
Web attack/malicious scanning detected
Web App Attack