π·πΈ
pexodelic
2026-09-22 03:35:02
(2 days ago)
Automated report from web, SSH and FTP server logs: 1706 requests probing for exposed secrets (.env, ...
show more
Automated report from web, SSH and FTP server logs: 1706 requests probing for exposed secrets (.env, .git, config files); 433 distinct non-existent paths requested (wordlist scanning); 5192 HTTP 4xx responses. First reported 2026-09-21 16:05 UTC, last reported 2026-09-22 05:35 UTC; counts cover the current log rotation window.
show less
Hacking
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-22 02:02:51
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.237.248.25 (25.248.237.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.237.248.25 (25.248.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 22:02:47.523159 2026] [security2:error] [pid 3991:tid 3991] [client 35.237.248.25:51482] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.medenseden.com"] [uri "/@fs/app/.env"] [unique_id "arHhx4C7KXAlSFJDtUgbaAAAAC0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π§πͺ
cmbplf
2026-09-22 01:55:28
(3 days ago)
129 requests with url.path */@fs/*
Brute-Force
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-09-22 01:23:46
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 35.237.248.25 (25.248.237.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.237.248.25 (25.248.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 21:23:41.217760 2026] [security2:error] [pid 28842:tid 28842] [client 35.237.248.25:60054] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.micaden.com.marshvineyards.com|F|2"] [data ".micaden.com.marshvineyards.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.micaden.com.marshvineyards.com"] [uri "/z9x8c7v6b5-debug-trigger-www.micaden.com.marshvineyards.com"] [unique_id "arHYndhVzhPn4zROvoAiUwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
Philister11
2026-09-22 00:38:49
(3 days ago)
CrowdSec: LePresidente/http-generic-403-bf (US/AS396982)
Web App Attack
Brute-Force
π¨π¦
Mediashaker
2026-09-22 00:03:16
(3 days ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 35.237.248.25 (US/Un ...
show more
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 35.237.248.25 (US/United States/25.248.237.35.bc.googleusercontent.com)
show less
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-09-21 23:57:41
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.237.248.25 (25.248.237.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.237.248.25 (25.248.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 19:57:36.547023 2026] [security2:error] [pid 6217:tid 6217] [client 35.237.248.25:39094] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.megaandina.com"] [uri "/data/.env"] [unique_id "arHEcCFIwe6ug1Byl7EWYAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-21 23:39:51
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.237.248.25 (25.248.237.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.237.248.25 (25.248.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 19:39:43.104896 2026] [security2:error] [pid 934:tid 934] [client 35.237.248.25:41264] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.michaelcarrollgreen.com"] [uri "/.env"] [unique_id "arHAP9Nt80oFj51Q3g8wvQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-21 22:12:18
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.237.248.25 (25.248.237.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.237.248.25 (25.248.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 18:12:12.539033 2026] [security2:error] [pid 18811:tid 18854] [client 35.237.248.25:50712] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.michaelrandon.com"] [uri "/@fs/app/.env"] [unique_id "arGrvDY03XcogaDCUw2drAAAAdc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-21 21:49:53
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.237.248.25 (25.248.237.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.237.248.25 (25.248.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 17:49:49.338629 2026] [security2:error] [pid 14533:tid 14533] [client 35.237.248.25:59676] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.mccarterestates.com"] [uri "/src/.env"] [unique_id "arGmfar_YUBYgGviLJoN_QAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-21 21:12:40
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.237.248.25 (25.248.237.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.237.248.25 (25.248.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 17:12:36.261510 2026] [security2:error] [pid 19929:tid 19929] [client 35.237.248.25:44444] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.michael-beasley.com"] [uri "/.env.js"] [unique_id "arGdxJ2Fvy9VfL-1O4gEKAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-21 20:53:10
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.237.248.25 (25.248.237.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.237.248.25 (25.248.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 16:53:06.266145 2026] [security2:error] [pid 714947:tid 714947] [client 35.237.248.25:50640] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.theholographicseed.com"] [uri "/frontend/.env"] [unique_id "arGZMsDMT8uhmxw9otkOswAAADM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-21 19:08:46
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.237.248.25 (25.248.237.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.237.248.25 (25.248.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 15:08:38.458117 2026] [security2:error] [pid 13172:tid 13172] [client 35.237.248.25:44790] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.mijnlevensverhaal.com"] [uri "/admin/.env"] [unique_id "arGAtsBQ8JldFLBdpEblbwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
demomodule
2026-09-21 18:54:59
(3 days ago)
PrestaShop Security Module: suspicious probe path detected (/.env)
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-21 18:35:13
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.237.248.25 (25.248.237.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.237.248.25 (25.248.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 14:35:09.876432 2026] [security2:error] [pid 32617:tid 32617] [client 35.237.248.25:51226] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.nyemdr.com"] [uri "/.env.production"] [unique_id "arF43WSFc3A5rY6GXVXBUwAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack