🇧🇪
cmbplf
2026-09-08 21:30:48
(1 day ago)
385 requests with url.path *.config/*
149 requests with url.path *.ssh/*
Brute-Force
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-08 20:09:16
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.243.117.232 (232.117.243.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.243.117.232 (232.117.243.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 16:09:08.320530 2026] [security2:error] [pid 3103:tid 3103] [client 35.243.117.232:19874] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.ppcspetsitting.com"] [uri "/@fs/.env"] [unique_id "aqBrZG2gxFcJDkmi-TsSugAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 19:39:10
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.243.117.232 (232.117.243.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.243.117.232 (232.117.243.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 15:39:05.689003 2026] [security2:error] [pid 32019:tid 32019] [client 35.243.117.232:53168] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.buynorthwest.com"] [uri "/@fs/.env"] [unique_id "aqBkWfs4mlHB6e9raR1tyAAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-08 19:08:10
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
🇺🇸
mnsf
2026-09-08 19:05:35
(1 day ago)
Scanning/Probing (25)
Brute-Force
Web App Attack
🇫🇷
Octopuce
2026-09-08 19:04:08
(1 day ago)
Aggressive web search of vulnerable pages: /assets../.env /v2/.env /.docker/.env /backend/.env /admi ...
show more
Aggressive web search of vulnerable pages: /assets../.env /v2/.env /.docker/.env /backend/.env /admin/.env ...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 18:48:20
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.243.117.232 (232.117.243.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.243.117.232 (232.117.243.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 14:48:15.720990 2026] [security2:error] [pid 12194:tid 12194] [client 35.243.117.232:26156] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.southsideaccountingservices.com"] [uri "/@fs/root/.env"] [unique_id "aqBYb45inTOAFGtg52YYKAAAACo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 18:22:36
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.243.117.232 (232.117.243.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.243.117.232 (232.117.243.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 14:22:33.072032 2026] [security2:error] [pid 8992:tid 8992] [client 35.243.117.232:10200] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kenirving.com"] [uri "/@fs/.env"] [unique_id "aqBSaZWdhtnHpjHr5cCzKQAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇩
Burayot
2026-09-08 18:05:13
(1 day ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 35.243.117.232 (JP/Japan/232.117.24 ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 35.243.117.232 (JP/Japan/232.117.243.35.bc.googleusercontent.com): 1 in the last 3600 secs
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 17:44:57
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.243.117.232 (232.117.243.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.243.117.232 (232.117.243.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 13:44:50.096938 2026] [security2:error] [pid 1246:tid 1274] [client 35.243.117.232:4222] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.stateabbreviationlist.com"] [uri "/@fs/root/.env"] [unique_id "aqBJkgxm6dtPr82acgoIYwAAAFY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇿🇦
conure.sh
2026-09-08 17:30:06
(1 day ago)
csagent: score 20.0: secrets grab x2; 1 domain(s) in 9s
Web App Attack
🇨🇭
backslash
2026-09-08 17:27:01
(1 day ago)
block ruleset WAF detection and high score on abuseIPDB 149EB1B42C242111FADBBC2EF8F90219570691E1
Bad Web Bot
🇩🇪
palzer.IT
2026-09-08 17:13:47
(1 day ago)
Fail2ban automatic report for plesk-apache-badbot: 35.243.117.232 - - [08/Sep/2026:19:13:31 +0200] G ...
show more
Fail2ban automatic report for plesk-apache-badbot: 35.243.117.232 - - [08/Sep/2026:19:13:31 +0200] GET /@fs/..%252f..%252f..%252f..%252f..%252froot/.env?raw?? [DOMAIN_REMOVED] 403 6402 - Mozilla/5.0 (Linux; Android 14; Pixel 8) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.1397.8 Mobile Safari/537.36; compatible; GPTBot/1.2; +[DOMAIN_REMOVED]
show less
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-08 17:09:35
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.243.117.232 (232.117.243.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.243.117.232 (232.117.243.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 13:09:27.814214 2026] [security2:error] [pid 30996:tid 30996] [client 35.243.117.232:37588] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "publicdomaingraphicssharing.banis-associates.com"] [uri "/@fs/.env"] [unique_id "aqBBRzDs-2prg2Y3b9vEawAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-08 17:08:46
(1 day ago)
Multiple web server 400 error codes from same source ip
Web App Attack