🇳🇱
WeCloudit-Anti-Abuse
2026-09-04 13:23:04
(36 minutes ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇬🇧
Aetherweb Ark
2026-09-04 12:15:29
(1 hour ago)
(mod_security) mod_security (id:949110) triggered by 35.244.69.211 (AU/Australia/211.69.244.35.bc.go ...
show more
(mod_security) mod_security (id:949110) triggered by 35.244.69.211 (AU/Australia/211.69.244.35.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 10:51:10
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.244.69.211 (211.69.244.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.244.69.211 (211.69.244.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:51:04.651993 2026] [security2:error] [pid 4049:tid 4049] [client 35.244.69.211:39896] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "myduraluxepanel.ipostsocialmedia.com"] [uri "/.env.production"] [unique_id "apqimMLJOxNtNkGVoOv-9QAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 10:35:19
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.244.69.211 (211.69.244.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.244.69.211 (211.69.244.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:35:12.253201 2026] [security2:error] [pid 17674:tid 17674] [client 35.244.69.211:60430] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "amdavies15.com"] [uri "/.env"] [unique_id "apqe4DhSdX5q2Zfdyd5TNwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 09:58:55
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.244.69.211 (211.69.244.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.244.69.211 (211.69.244.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 05:58:47.836914 2026] [security2:error] [pid 2824998:tid 2825088] [client 35.244.69.211:56584] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "onenessrecords.com"] [uri "/.env.old"] [unique_id "apqWVw1OtXLqWHx1GpG3SQAAAIg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 07:47:42
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.244.69.211 (211.69.244.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.244.69.211 (211.69.244.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 03:47:32.911985 2026] [security2:error] [pid 12673:tid 12673] [client 35.244.69.211:51820] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "goldenstatealliance.com"] [uri "/.env.backup"] [unique_id "app3lKM-yuzj9IPC6Qg-AAAAADs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
webanyone
2026-09-04 07:47:25
(6 hours ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
🇬🇧
consul.to
2026-09-04 07:17:49
(6 hours ago)
Web attack/malicious scanning detected
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 07:01:08
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.244.69.211 (211.69.244.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.244.69.211 (211.69.244.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 03:01:01.527930 2026] [security2:error] [pid 29266:tid 29266] [client 35.244.69.211:39010] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.berkelmiami.com"] [uri "/.env.backup"] [unique_id "appsrRH3IT0odP4xLXLV1QAAAC4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-04 06:47:47
(7 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
🇫🇷
masterguru
2026-09-04 06:44:49
(7 hours ago)
URL file extension is restricted by policy. String match within ".ani/ .asa/ .asax/ .ascx/ .backup/ ...
show more
URL file extension is restricted by policy. String match within ".ani/ .asa/ .asax/ .ascx/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .compositefont/ .config/ .conf/ .crt/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dist/ .dll/ .dos/ .dpkg-dist/ .drv/ .gadget/ .hta/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .inf/ .ini/ .jse/ .key/ .licx/ .lnk/ .log/ .mdb/ .msc/ .ocx/ .old/ .pass/ .pdb/ .pfx/ .pif/ .pem/ .pol/ .prf/ .printer/ .pwd/ .rdb/ .rdp/ .reg/ .resources/ .resx/ .scr/ .sct/ .shs/ .sql/ .swp/ .sys/ .tlb/ .tmp/ .url/ .vb/ .vbe/ .vbs/ .vbproj/ .vsdisco/ .vxd/ .webinfo/ .ws/ .wsc/ .wsf/ .wsh/ .xsd/ .xsx/" at TX:extension. (920440-196)
show less
Hacking
🇮🇹
VHosting
2026-09-04 06:05:04
(7 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
Anonymous
2026-09-04 05:25:01
(8 hours ago)
suspicious request in access.log
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 05:23:59
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.244.69.211 (211.69.244.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.244.69.211 (211.69.244.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 01:23:55.353151 2026] [security2:error] [pid 18961:tid 18961] [client 35.244.69.211:51254] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "vmail.davisllp.com"] [uri "/.env.prod"] [unique_id "appV67MzfEIBmVYXnfBecgAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-04 05:20:37
(8 hours ago)
Automatically blocked after 8 security events. Observed sensitive configuration-file probes. Source: ...
show more
Automatically blocked after 8 security events. Observed sensitive configuration-file probes. Source: Cloudflare security controls.
show less
Hacking
Web App Attack