๐บ๐ธ
TPI-Abuse
2026-08-29 01:40:12
(37 seconds ago)
(mod_security) mod_security (id:210492) triggered by 35.245.197.72 (72.197.245.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.245.197.72 (72.197.245.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 21:40:05.067935 2026] [security2:error] [pid 19503:tid 19503] [client 35.245.197.72:29994] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.sierrablue.ecuablue.farm"] [uri "/@fs/.env"] [unique_id "apI4dVpJR_XsggsllEbPOQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Aetherweb Ark
2026-08-29 01:25:08
(15 minutes ago)
(mod_security) mod_security (id:949110) triggered by 35.245.197.72 (US/United States/72.197.245.35.b ...
show more
(mod_security) mod_security (id:949110) triggered by 35.245.197.72 (US/United States/72.197.245.35.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
Anonymous
2026-08-29 01:00:02
(40 minutes ago)
suspicious request in access.log
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 00:22:05
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 35.245.197.72 (72.197.245.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.245.197.72 (72.197.245.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 20:21:56.385935 2026] [security2:error] [pid 14057:tid 14057] [client 35.245.197.72:64986] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.tempsetters.com"] [uri "/@fs/root/.env"] [unique_id "apImJOHZS5K2mDdQpmEYAgAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-08-29 00:12:26
(1 hour ago)
Scanning/Probing (26)
Brute-Force
Web App Attack
๐ณ๐ฑ
Alboweb B.V.
2026-08-29 00:11:05
(1 hour ago)
Bad web bot activity detected by Fail2Ban in plesk-apache-badbot jail
Bad Web Bot
๐ช๐ธ
pipeline.es
2026-08-28 23:58:59
(1 hour ago)
Web scanning / probing for vulnerable paths | URL: /@fs/src/.env?raw?? | Evidence: travelplanet.pt 3 ...
show more
Web scanning / probing for vulnerable paths | URL: /@fs/src/.env?raw?? | Evidence: travelplanet.pt 35.245.197.72 - - [29/Aug/2026:01:58:48 +0200] \"GET /@fs/src/.env?raw?? HTTP/1.1\" 404 20652 \"-\" \"Mozilla/5.0 (Linux; Android 14; Pixel 8) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.7681.74 Mobile Safari/537.36; compatible; WhatsApp/[internal_ip]\" GEOIP_COUNTRY_CODE=US | ASN: GOOGLE-CLOUD-PLATFORM | Country: US
show less
Port Scan
Web App Attack
๐ฉ๐ช
netclix.gr
2026-08-28 23:54:55
(1 hour ago)
(security_scan) Sensitive File Scan Blocked 35.245.197.72 (US/United States/72.197.245.35.bc.googleu ...
show more
(security_scan) Sensitive File Scan Blocked 35.245.197.72 (US/United States/72.197.245.35.bc.googleusercontent.com): 1 in the last 4600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 35.245.197.72 - - [29/Aug/2026:02:54:54 +0300] "GET /@fs/../../.env?raw?? HTTP/1.1" 400 150 "-" "-"
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-08-28 23:40:00
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.245.197.72 (72.197.245.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.245.197.72 (72.197.245.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 19:39:54.184146 2026] [security2:error] [pid 27559:tid 27559] [client 35.245.197.72:51702] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "teamrealduck.com"] [uri "/@fs/root/.env"] [unique_id "apIcSi6hDPw3A5H52TrKFAAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Octopuce
2026-08-28 23:35:52
(2 hours ago)
Aggressive web search of vulnerable pages: /v2/.env /images../.env /.docker/.env /v1/.env /api/.env ...
show more
Aggressive web search of vulnerable pages: /v2/.env /images../.env /.docker/.env /v1/.env /api/.env ...
show less
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-08-28 22:57:53
(2 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-08-28 22:57:40
(2 hours ago)
Multiple WAF Violations
Web App Attack
๐ฎ๐น
VHosting
2026-08-28 22:45:04
(2 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-08-28 22:38:02
(3 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-path-traversal-probing
Web App Attack
Hacking