๐บ๐ธ
TPI-Abuse
2026-09-01 13:48:11
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 35.240.91.140 (140.91.240.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.240.91.140 (140.91.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 09:48:03.577614 2026] [security2:error] [pid 10176:tid 10176] [client 35.240.91.140:51640] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.barigby.com"] [uri "/.env.example"] [unique_id "apbXk1NR-LMQiYHm1B4FcwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 12:03:34
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.240.91.140 (140.91.240.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.240.91.140 (140.91.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 08:03:27.905280 2026] [security2:error] [pid 23421:tid 23421] [client 35.240.91.140:39596] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "deafinitely.com"] [uri "/.env.production"] [unique_id "apa_D1icjnEgBWbuSILzxAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FD-IX
2026-09-01 11:19:21
(3 hours ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
๐บ๐ธ
MatCat
2026-09-01 11:05:13
(3 hours ago)
Banned by fail2ban: apache-webprobe
Port Scan
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-01 10:57:58
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.240.91.140 (140.91.240.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.240.91.140 (140.91.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 06:57:52.389692 2026] [security2:error] [pid 24671:tid 24671] [client 35.240.91.140:44446] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.peakagronomysolutions.com"] [uri "/.env.production"] [unique_id "apavsD4IcxR8DT8V3VvRAwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 10:21:53
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.240.91.140 (140.91.240.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.240.91.140 (140.91.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 06:21:48.864610 2026] [security2:error] [pid 6957:tid 6957] [client 35.240.91.140:33446] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "aktkaro.com"] [uri "/.env.old"] [unique_id "apanPH7V77uUT-ra1Uyr5wAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-01 10:08:50
(4 hours ago)
CrowdSec ban: crowdsecurity/http-sensitive-files
Port Scan
๐ซ๐ท
masterguru
2026-09-01 09:31:53
(5 hours ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 35.240.91.140 (BE/Belgium/140.91.240. ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 35.240.91.140 (BE/Belgium/140.91.240.35.bc.googleusercontent.com): 2 in the last 3600 secs (0-196)
show less
Hacking
๐น๐ญ
MWA SOC
2026-09-01 09:25:16
(5 hours ago)
Hacking
๐ต๐ฑ
webadmin
2026-09-01 09:17:18
(5 hours ago)
2026-09-01T11:17:17.356553+02:00 tytan mobile-sai-api[4129]: [error] client: 35.240.91.140 server: s ...
show more
2026-09-01T11:17:17.356553+02:00 tytan mobile-sai-api[4129]: [error] client: 35.240.91.140 server: startapp.sai.pl, request: "GET", url: http://startapp.sai.pl/actuator/env [404]: Not Found
2026-09-01T11:17:17.356553+02:00 tytan mobile-sai-api[4129]: [error] client: 35.240.91.140 server: startapp.sai.pl, request: "GET", url: http://startapp.sai.pl/wp-config.php~ [404]: Not Found
2026-09-01T11:17:17.356553+02:00 tytan mobile-sai-api[4129]: [error] client: 35.240.91.140 server: startapp.sai.pl, request: "GET", url: http://startapp.sai.pl/.env.bak [404]: Not Found
2026-09-01T11:17:17.356553+02:00 tytan mobile-sai-api[4129]: [error] client: 35.240.91.140 server: startapp.sai.pl, request: "GET", url: http://startapp.sai.pl/crusader-404-probe [404]: Not Found
show less
Web App Attack
๐ฉ๐ช
gadix
2026-09-01 08:54:08
(6 hours ago)
[01/Sep/2026:10:54:07.933667 +0200] apaSp47gw4UCWgJHZpfS8wAAABY 35.240.91.140 45534 127.0.0.1 7081
[ ...
show more
[01/Sep/2026:10:54:07.933667 +0200] apaSp47gw4UCWgJHZpfS8wAAABY 35.240.91.140 45534 127.0.0.1 7081
[01/Sep/2026:10:54:07.936319 +0200] apaSp5vcE3gkp4zUnokyRgAAAFA 35.240.91.140 45518 127.0.0.1 7081
[01/Sep/2026:10:54:08.026914 +0200] apaSp47gw4UCWgJHZpfS9AAAABI 35.240.91.140 45558 127.0.0.1 7081
...
show less
Web App Attack
๐ฌ๐ง
consul.to
2026-09-01 07:50:32
(7 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐ฉ๐ช
LRob
2026-09-01 07:32:30
(7 hours ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /wp-config.php~ (+12 more) | 2026-09-01 07:32 UTC
show less
Hacking
Web App Attack
๐ฌ๐ง
relianoid.com
2026-09-01 07:16:56
(7 hours ago)
404 Errors Abuse detected by Relianoid OSS Load Balancer - relianoid.com
Web App Attack
๐ช๐ธ
alferez
2026-09-01 07:13:01
(7 hours ago)
Searching .(env|sql|zip|tar|rar) files
Hacking
Exploited Host
Web App Attack