🇺🇸
mnsf
2026-09-09 14:05:33
(59 minutes ago)
Scanning/Probing (18)
Brute-Force
Web App Attack
🇩🇪
Petros Stefanakis
2026-09-09 14:05:23
(1 hour ago)
(mod_security) mod_security triggered on hostname [redacted] 35.236.245.15 (US/United States/15.245. ...
show more
(mod_security) mod_security triggered on hostname [redacted] 35.236.245.15 (US/United States/15.245.236.35.bc.googleusercontent.com)
show less
SQL Injection
🇺🇸
TPI-Abuse
2026-09-09 13:52:10
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 35.236.245.15 (15.245.236.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.236.245.15 (15.245.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 09:52:04.769051 2026] [security2:error] [pid 22409:tid 22423] [client 35.236.245.15:19854] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.cwpianolessons.com"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252fapp/.env"] [unique_id "aqFkhAdkqZ2L2tVLc8CZ7QAAAEk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 13:32:33
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 35.236.245.15 (15.245.236.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.236.245.15 (15.245.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 09:32:27.750803 2026] [security2:error] [pid 23734:tid 23734] [client 35.236.245.15:53218] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.genesis-group.ggisoftware.com"] [uri "/@fs/app/.env"] [unique_id "aqFf6-Wfb0e-1eZ63lfvwAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 12:47:20
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.236.245.15 (15.245.236.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.236.245.15 (15.245.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 08:47:13.504653 2026] [security2:error] [pid 7514:tid 7514] [client 35.236.245.15:27676] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.rwcartoons.com"] [uri "/@fs/app/.env"] [unique_id "aqFVUW0z_WRTxfHinnda_QAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
akasolutions.de
2026-09-09 12:31:04
(2 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 35.236.245.15 (US/United States/15.245. ...
show more
(mod_security) mod_security triggered on hostname [redacted] 35.236.245.15 (US/United States/15.245.236.35.bc.googleusercontent.com)
show less
SQL Injection
🇩🇪
FeG Deutschland
2026-09-09 12:26:35
(2 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 1247
Exploited Host
Web App Attack
🇧🇾
lns.bz
2026-09-09 11:55:18
(3 hours ago)
Too many 404 requests [BY]
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 11:46:44
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.236.245.15 (15.245.236.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.236.245.15 (15.245.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 07:46:38.124743 2026] [security2:error] [pid 11683:tid 11683] [client 35.236.245.15:55770] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "srich.com"] [uri "/@fs/.env"] [unique_id "aqFHHj_2MWf9EVf7JF6dZgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Viveronese
2026-09-09 11:09:23
(3 hours ago)
HTTP vulnerability scanning
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 10:50:48
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.236.245.15 (15.245.236.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.236.245.15 (15.245.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 06:50:44.250100 2026] [security2:error] [pid 1281204:tid 1281228] [client 35.236.245.15:3682] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "store.emehache.com"] [uri "/@fs/../../.env"] [unique_id "aqE6BEXhnUeFhK3ivOlGRwAAARY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-09 10:37:41
(4 hours ago)
Blocked by ModSec and CSF
Port Scan
🇺🇸
TPI-Abuse
2026-09-09 10:01:15
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.236.245.15 (15.245.236.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.236.245.15 (15.245.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 06:01:08.888669 2026] [security2:error] [pid 24967:tid 24967] [client 35.236.245.15:37198] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.andrewmcgrath.com"] [uri "/@fs/../../.env"] [unique_id "aqEuZLYdM-BrBjE3HE2hvAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 08:33:41
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.236.245.15 (15.245.236.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.236.245.15 (15.245.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 04:33:35.861964 2026] [security2:error] [pid 22884:tid 22884] [client 35.236.245.15:26354] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.graydortmotors.com"] [uri "/@fs/root/.env"] [unique_id "aqEZ31_Y1x_f6KsLCEgdXgAAADE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
neckaralb-admin.de
2026-09-09 08:23:11
(6 hours ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack