🇳🇱
debestelapp
2026-09-04 12:05:10
(1 minute ago)
Web App Attack
🇩🇪
Petros Stefanakis
2026-09-04 11:06:48
(1 hour ago)
(mod_security) mod_security triggered on hostname [redacted] 35.246.127.38 (GB/United Kingdom/38.127 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 35.246.127.38 (GB/United Kingdom/38.127.246.35.bc.googleusercontent.com)
show less
SQL Injection
🇺🇸
TPI-Abuse
2026-09-04 10:01:31
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.246.127.38 (38.127.246.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.246.127.38 (38.127.246.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:01:25.281809 2026] [security2:error] [pid 27836:tid 27836] [client 35.246.127.38:40784] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.bmbb1.com"] [uri "/.env.example"] [unique_id "apqW9Y9Tv-a1UPowFPkJJAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-04 09:38:00
(2 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-04 09:09:06
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.246.127.38 (38.127.246.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.246.127.38 (38.127.246.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 05:08:58.241285 2026] [security2:error] [pid 7582:tid 7582] [client 35.246.127.38:41240] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kurikka.net"] [uri "/.env.bak"] [unique_id "apqKqkq2EboeAQk8cajydQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 08:25:51
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.246.127.38 (38.127.246.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.246.127.38 (38.127.246.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 04:25:47.225854 2026] [security2:error] [pid 32343:tid 32343] [client 35.246.127.38:57742] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.digitalcarbonbank.com"] [uri "/.env"] [unique_id "apqAi54rgWNSG7uZF2Df7QAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
Aetherweb Ark
2026-09-04 08:19:28
(3 hours ago)
(mod_security) mod_security (id:949110) triggered by 35.246.127.38 (GB/United Kingdom/38.127.246.35. ...
show more
(mod_security) mod_security (id:949110) triggered by 35.246.127.38 (GB/United Kingdom/38.127.246.35.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 08:08:28
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.246.127.38 (38.127.246.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.246.127.38 (38.127.246.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 04:08:23.221799 2026] [security2:error] [pid 30779:tid 30779] [client 35.246.127.38:34428] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "directnic-support.rocks"] [uri "/.env.dev"] [unique_id "app8d73djb9OqORfqYHWmAAAAC0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-04 07:48:01
(4 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-04 06:07:24
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.246.127.38 (38.127.246.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.246.127.38 (38.127.246.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 02:07:20.688208 2026] [security2:error] [pid 19571:tid 19628] [client 35.246.127.38:40564] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rcorbet.net"] [uri "/.env.production"] [unique_id "appgGOzmEVCygGThsAdukwAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇦
URAN Publishing Service
2026-09-04 05:46:57
(6 hours ago)
[04/Sep/2026:08:46:57 +0300] -- 35.246.127.38 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.env ...
show more
[04/Sep/2026:08:46:57 +0300] -- 35.246.127.38 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.env.example HTTP/1.1
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 05:42:44
(6 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.246.127.38 (38.127.246.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.246.127.38 (38.127.246.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 01:42:37.549244 2026] [security2:error] [pid 25391:tid 25391] [client 35.246.127.38:36208] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||investorsgeorgia.usaangelinvestors.com|F|2"] [data ".env.backup"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "investorsgeorgia.usaangelinvestors.com"] [uri "/.env.backup"] [unique_id "appaTR-9Gqzw8cc66mObwwAAAC0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-09-04 04:50:09
(7 hours ago)
Web attack/malicious scanning detected
Web App Attack
🇫🇷
dynamix
2026-09-04 04:23:21
(7 hours ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 04:16:51
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.246.127.38 (38.127.246.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.246.127.38 (38.127.246.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 00:16:46.510557 2026] [security2:error] [pid 32556:tid 32556] [client 35.246.127.38:52720] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.aluminatrailers.com"] [uri "/.env.production"] [unique_id "appGLqF0CQ7IployZsm6dgAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack