🇺🇸
TPI-Abuse
2026-09-04 15:21:00
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.244.70.239 (239.70.244.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.244.70.239 (239.70.244.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 11:20:55.355165 2026] [security2:error] [pid 3195628:tid 3195655] [client 35.244.70.239:47128] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.isoceansl.com"] [uri "/.env.local"] [unique_id "aprh1yB4yelftn8vSNpD5QAAAVg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 15:02:22
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.244.70.239 (239.70.244.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.244.70.239 (239.70.244.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 11:02:16.960247 2026] [security2:error] [pid 9447:tid 9447] [client 35.244.70.239:53356] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lahamcustomwoods.com"] [uri "/.env.local"] [unique_id "aprdeNORtM5AwyBujmY5nAAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
debestelapp
2026-09-04 14:55:11
(3 days ago)
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-04 14:11:25
(3 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-04 14:06:56
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.244.70.239 (239.70.244.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.244.70.239 (239.70.244.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 10:06:52.215556 2026] [security2:error] [pid 32596:tid 32596] [client 35.244.70.239:35124] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.medics-group.com"] [uri "/.env.old"] [unique_id "aprQfL9xjT9fyvOizq47KgAAAEY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-04 13:35:02
(3 days ago)
suspicious request in access.log
Web App Attack
🇩🇪
BiancaNL
2026-09-04 13:23:02
(3 days ago)
Fail2Ban: jail=code-runner-scanner-probe on <fqdn> (port=<port>)
Hacking
Web App Attack
🇺🇸
ISPLtd
2026-09-04 12:30:10
(3 days ago)
Sep 4 06:30:10 35.244.70.239 TCP SPT=45070 DPT=80 SYN
Sep 4 06:30:10 35.244.70.239 TCP SPT=45064 D ...
show more
Sep 4 06:30:10 35.244.70.239 TCP SPT=45070 DPT=80 SYN
Sep 4 06:30:10 35.244.70.239 TCP SPT=45064 DPT=80 SYN
Sep 4 06:30:10 35.244.70.239 TCP SPT=45032 DPT=80 SYN
...
show less
DDoS Attack
Anonymous
2026-09-04 12:16:19
(3 days ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
🇩🇪
kkw
2026-09-04 12:12:16
(3 days ago)
[REDACTED] 35.244.70.239 - - [04/Sep/2026:14:12:15 +0200] "GET /.env.bak HTTP/1.1" 404 5884 "-" "cru ...
show more
[REDACTED] 35.244.70.239 - - [04/Sep/2026:14:12:15 +0200] "GET /.env.bak HTTP/1.1" 404 5884 "-" "crusader-worker/1.0"
... (mode: searching http-sensitive-files)
show less
Bad Web Bot
Web App Attack
🇮🇹
VHosting
2026-09-04 11:45:03
(3 days ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇩🇪
webanyone
2026-09-04 11:17:28
(3 days ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 11:15:43
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.244.70.239 (239.70.244.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.244.70.239 (239.70.244.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 07:15:38.375596 2026] [security2:error] [pid 19771:tid 19771] [client 35.244.70.239:37656] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.corepest.com"] [uri "/.env.production"] [unique_id "apqoWm9A3aAlU0o5cApVdwAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
e.fierstra
2026-09-04 10:59:02
(3 days ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇫🇷
dynamix
2026-09-04 10:32:24
(3 days ago)
Multiple WAF Violations
Web App Attack