๐ท๐บ
DZBOT
2026-08-01 17:32:05
(3 hours ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐จ๐ญ
4server
2026-08-01 16:58:50
(4 hours ago)
[SatAug0118:58:44.5667402026][security2:error][pid130093:tid130384][client35.243.71.122:0]ModSecurit ...
show more
[SatAug0118:58:44.5667402026][security2:error][pid130093:tid130384][client35.243.71.122:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".env\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"365\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"www.comarcosa.com.81-17-25-250.cpanel.site\"][uri\"/.env.prod\"][unique_id\"am4lxDmKoUgx-18DLCCEuwAAAQY\"]
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 16:04:03
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.243.71.122 (122.71.243.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.243.71.122 (122.71.243.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 12:03:57.896121 2026] [security2:error] [pid 2461640:tid 2461640] [client 35.243.71.122:56342] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.merlinaerospace.com"] [uri "/.env.prod"] [unique_id "am4Y7TV91_10DU3Ry3EK_wAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 15:46:45
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.243.71.122 (122.71.243.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.243.71.122 (122.71.243.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 11:46:37.697607 2026] [security2:error] [pid 2155507:tid 2155507] [client 35.243.71.122:52542] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "reciprodyne.com"] [uri "/.env.old"] [unique_id "am4U3TGKG5p231r-h-TiEgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-08-01 15:25:21
(5 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 12
Exploited Host
Web App Attack
๐ฉ๐ช
IVski
2026-08-01 15:17:59
(5 hours ago)
IVski WAF | Multiple 403 Forbidden responses detected from this IP. Likely automated scanning.
DDoS Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-08-01 15:01:17
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.243.71.122 (122.71.243.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.243.71.122 (122.71.243.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 11:01:13.558214 2026] [security2:error] [pid 926771:tid 926771] [client 35.243.71.122:45148] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.mkkfactory.com"] [uri "/.env.local"] [unique_id "am4KOQGRSdsM1IDh0uYFVgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 14:20:34
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.243.71.122 (122.71.243.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.243.71.122 (122.71.243.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 10:20:26.867534 2026] [security2:error] [pid 2190259:tid 2190259] [client 35.243.71.122:51496] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rfinderradios.suffolksystems.com"] [uri "/.env.save"] [unique_id "am4AqnVrqq38GmsV5yMDEwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-08-01 14:16:39
(6 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-01 13:41:43
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.243.71.122 (122.71.243.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.243.71.122 (122.71.243.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 09:41:39.143252 2026] [security2:error] [pid 602035:tid 602035] [client 35.243.71.122:50592] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gensou.net"] [uri "/.env.example"] [unique_id "am33k8-fqWasUvAusVbcFAAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-08-01 13:36:39
(7 hours ago)
Web attack/malicious scanning detected
Web App Attack
Anonymous
2026-08-01 13:36:04
(7 hours ago)
Bot / scanning and/or hacking attempts: GET /.env.prod HTTP/1.1, GET /.env.backup HTTP/1.1, GET /.en ...
show more
Bot / scanning and/or hacking attempts: GET /.env.prod HTTP/1.1, GET /.env.backup HTTP/1.1, GET /.env HTTP/1.1
show less
Hacking
Web App Attack
๐ซ๐ท
masterguru
2026-08-01 13:25:01
(7 hours ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 35.243.71.122 (JP/Japan/122.71.243.35 ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 35.243.71.122 (JP/Japan/122.71.243.35.bc.googleusercontent.com): 2 in the last 3600 secs (0-196)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-01 13:10:45
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.243.71.122 (122.71.243.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.243.71.122 (122.71.243.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 09:10:40.636390 2026] [security2:error] [pid 758753:tid 758753] [client 35.243.71.122:51988] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.anekawangi.kairoslogammakmur.com"] [uri "/.env.prod"] [unique_id "am3wUHrSqAgTexugYfeUAwAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-08-01 13:08:42
(8 hours ago)
Scanning/Probing (20)
Brute-Force
Web App Attack