🇺🇸
TPI-Abuse
2026-09-04 10:55:06
(57 minutes ago)
(mod_security) mod_security (id:210492) triggered by 35.244.78.225 (225.78.244.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.244.78.225 (225.78.244.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:55:01.719423 2026] [security2:error] [pid 27284:tid 27284] [client 35.244.78.225:59016] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "blacktvnow.com"] [uri "/.env.old"] [unique_id "apqjherXtYxGUds_jyZacAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 10:04:03
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 35.244.78.225 (225.78.244.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.244.78.225 (225.78.244.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:03:58.765001 2026] [security2:error] [pid 1030:tid 1030] [client 35.244.78.225:45906] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "backtosleep.com"] [uri "/.env"] [unique_id "apqXjtwVvwxQSYLssFvtlAAAAC0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-04 10:01:53
(1 hour ago)
Auto-reported by Fail2Ban (NPM-Auth)
Web App Attack
🇭🇺
DumaNet
2026-09-04 10:01:00
(1 hour ago)
Web app attack attempts, scanning for vulnerability.
Date: 2026 Sep 04. 10:28:09
Source IP: 35.244 ...
show more
Web app attack attempts, scanning for vulnerability.
Date: 2026 Sep 04. 10:28:09
Source IP: 35.244.78.225
Portion of the log(s):
35.244.78.225 - [04/Sep/2026:10:28:09 +0200] "GET /.env.example HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
35.244.78.225 - [04/Sep/2026:10:28:09 +0200] "GET /storage/logs/laravel.log HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
35.244.78.225 - [04/Sep/2026:10:28:09 +0200] "GET /wp-config.php~ HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
35.244.78.225 - [04/Sep/2026:10:28:09 +0200] "GET /_ignition/health-check HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
35.244.78.225 - [04/Sep/2026:10:28:09 +0200] "GET /.env.save HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
35.244.78.225 - [04/Sep/2026:10:28:09 +0200] "GET /.env.backup HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
35.244.78.225 - [04/Sep/2026:10:28:09 +0200] "GET /.env.old HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
35.244.78.225 - [04/Sep/2026:10:28:09 +0200] "GET /env HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
show less
Web App Attack
🇫🇷
masterguru
2026-09-04 10:00:58
(1 hour ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-195)
Hacking
Web App Attack
🇩🇪
Marc
2026-09-04 09:16:15
(2 hours ago)
35.244.78.225 - - [04/Sep/2026:11:16:14 +0200] "GET /_ignition/health-check HTTP/1.1" 404 4617 "-" " ...
show more
35.244.78.225 - - [04/Sep/2026:11:16:14 +0200] "GET /_ignition/health-check HTTP/1.1" 404 4617 "-" "crusader-worker/1.0" 35.244.78.225 - - [04/Sep/2026:11:16:14 +0200] "GET /.env.dev HTTP/1.1" 404 4617 "-" "crusader-worker/1.0" 35.244.78.225 - - [04/Sep/2026:11:16:14 +0200] "GET /actuator/env HTTP/1.1" 404 4617 "-" "crusader-worker/1.0"
show less
Brute-Force
🇺🇸
TPI-Abuse
2026-09-04 08:27:26
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.244.78.225 (225.78.244.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.244.78.225 (225.78.244.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 04:27:20.729098 2026] [security2:error] [pid 27463:tid 27463] [client 35.244.78.225:49364] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.cfabeachblvd.com"] [uri "/.env.bak"] [unique_id "apqA6J7Bh12WNSTsZiPppgAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
e.fierstra
2026-09-04 08:21:03
(3 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇩🇪
raph
2026-09-04 08:14:56
(3 hours ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack
🇺🇸
daveoctober
2026-09-04 07:57:09
(3 hours ago)
October Sentinel: honeypot triggered
Bad Web Bot
Web App Attack
🇩🇪
Phenix Info
2026-09-04 07:56:20
(3 hours ago)
SmallGuard.fr/Prestashop Forbidden Ext.
Web App Attack
🇩🇪
Petros Stefanakis
2026-09-04 07:23:54
(4 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 35.244.78.225 (AU/Australia/225.78.244. ...
show more
(mod_security) mod_security triggered on hostname [redacted] 35.244.78.225 (AU/Australia/225.78.244.35.bc.googleusercontent.com)
show less
SQL Injection
🇸🇪
vaia.cloud
2026-09-04 06:40:04
(5 hours ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
🇧🇷
Halux
2026-09-04 06:38:13
(5 hours ago)
35.244.78.225 Web Application Firewall multiple violations
Hacking
Web App Attack
🇬🇧
WebNiraj
2026-09-04 06:33:51
(5 hours ago)
(mod_security) mod_security (id:949110) triggered by 35.244.78.225 (AU/Australia/225.78.244.35.bc.go ...
show more
(mod_security) mod_security (id:949110) triggered by 35.244.78.225 (AU/Australia/225.78.244.35.bc.googleusercontent.com): 5 in the last 3600 secs [SIGMA]
show less
Brute-Force