Anonymous
2026-08-28 19:30:24
(29 minutes ago)
Too many successive quick attempts with error status 301, 404, 405, 444, 403 or 400
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-08-28 19:28:20
(31 minutes ago)
(mod_security) mod_security (id:210492) triggered by 35.245.163.121 (121.163.245.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.245.163.121 (121.163.245.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 15:28:17.428729 2026] [security2:error] [pid 21193:tid 21193] [client 35.245.163.121:35410] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.cameronwv.mmldesign.com"] [uri "/.env.production"] [unique_id "apHhUdrMv9kpMCFJBrpC6QAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
todix
2026-08-28 19:07:44
(52 minutes ago)
Web App Attack Exploid from 35.245.163.121
Web App Attack
๐บ๐ธ
NXTwoThou
2026-08-28 18:56:47
(1 hour ago)
/.env.prod
Web App Attack
Anonymous
2026-08-28 18:47:42
(1 hour ago)
[Fri Aug 28 20:47:42.326912 2026] [access_compat:error] [pid 1620413:tid 1620413] [client 35.245.163 ...
show more
[Fri Aug 28 20:47:42.326912 2026] [access_compat:error] [pid 1620413:tid 1620413] [client 35.245.163.121:54142] AH01797: client denied by server configuration: /var/www/html/wp-config.php.bak
[Fri Aug 28 20:47:42.326956 2026] [access_compat:error] [pid 1634855:tid 1634855] [client 35.245.163.121:54088] AH01797: client denied by server configuration: /var/www/html/actuator
...
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-08-28 18:35:18
(1 hour ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐ฉ๐ช
gadix
2026-08-28 17:55:02
(2 hours ago)
[28/Aug/2026:19:55:01.806351 +0200] apHLdflJeVnsPs0TY0xo3wAAAFM 35.245.163.121 49312 127.0.0.1 7081
...
show more
[28/Aug/2026:19:55:01.806351 +0200] apHLdflJeVnsPs0TY0xo3wAAAFM 35.245.163.121 49312 127.0.0.1 7081
[28/Aug/2026:19:55:01.814501 +0200] apHLdSYUBxCubAmmO4Rp4gAAABQ 35.245.163.121 49332 127.0.0.1 7081
[28/Aug/2026:19:55:01.817809 +0200] apHLdflJeVnsPs0TY0xo4wAAAFY 35.245.163.121 49340 127.0.0.1 7081
...
show less
Web App Attack
Anonymous
2026-08-28 17:27:20
(2 hours ago)
35.245.163.121 - [28/Aug/2026:10:27:19 -0700] audiobookshelf.koselig.dynu.net "GET /wp-config.php.sw ...
show more
35.245.163.121 - [28/Aug/2026:10:27:19 -0700] audiobookshelf.koselig.dynu.net "GET /wp-config.php.swp HTTP/1.1" 404 4540
35.245.163.121 - [28/Aug/2026:10:27:19 -0700] audiobookshelf.koselig.dynu.net "GET /actuator/configprops HTTP/1.1" 404 4544
35.245.163.121 - [28/Aug/2026:10:27:19 -0700] audiobookshelf.koselig.dynu.net "GET /actuator/env HTTP/1.1" 404 4534
35.245.163.121 - [28/Aug/2026:10:27:19 -0700] audiobookshelf.koselig.dynu.net "GET /.env.example HTTP/1.1" 404 4534
35.245.163.121 - [28/Aug/2026:10:27:19 -0700] audiobookshelf.koselig.dynu.net "GET /.env HTTP/1.1" 404 4527
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 17:25:55
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.245.163.121 (121.163.245.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.245.163.121 (121.163.245.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 13:25:47.767375 2026] [security2:error] [pid 23703:tid 23703] [client 35.245.163.121:49988] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.fourmarket.com.joqlawncare.com"] [uri "/.env.save"] [unique_id "apHEmzX5ruicSsvQOdxrGgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ท๐ด
iulianh
2026-08-28 17:04:43
(2 hours ago)
80,443
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-08-28 17:02:55
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.245.163.121 (121.163.245.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.245.163.121 (121.163.245.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 13:02:48.617479 2026] [security2:error] [pid 4307:tid 4307] [client 35.245.163.121:59550] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.proof.bonefrog.com"] [uri "/wp-config.php.bak"] [unique_id "apG_OKRM2c8rTTslAGBonwAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
mediarama.com
2026-08-28 16:58:18
(3 hours ago)
Banned by Fail2Ban
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 16:29:43
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.245.163.121 (121.163.245.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.245.163.121 (121.163.245.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 12:29:39.671949 2026] [security2:error] [pid 30985:tid 30994] [client 35.245.163.121:45356] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tapdd.com"] [uri "/.env"] [unique_id "apG3c7PO-s49xaS9dpxBVgAAAIQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-28 16:28:05
(3 hours ago)
Bot / scanning and/or hacking attempts: GET /.env.old HTTP/1.1
Hacking
Web App Attack
๐ต๐ฑ
itsvic.dev
2026-08-28 15:55:41
(4 hours ago)
35.245.163.121 - - [28/Aug/2026:15:55:41 +0000] "media.itsvic.dev" "GET /.env.prod HTTP/1.1" 404 0 " ...
show more
35.245.163.121 - - [28/Aug/2026:15:55:41 +0000] "media.itsvic.dev" "GET /.env.prod HTTP/1.1" 404 0 "-" "crusader-worker/1.0"
35.245.163.121 - - [28/Aug/2026:15:55:41 +0000] "media.itsvic.dev" "GET /.env.bak HTTP/1.1" 404 0 "-" "crusader-worker/1.0"
35.245.163.121 - - [28/Aug/2026:15:55:41 +0000] "media.itsvic.dev" "GET /.env.old HTTP/1.1" 404 0 "-" "crusader-worker/1.0"
...
show less
Brute-Force
Web App Attack