๐บ๐ธ
TPI-Abuse
2026-09-01 03:30:42
(12 minutes ago)
(mod_security) mod_security (id:210492) triggered by 35.246.164.6 (6.164.246.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.246.164.6 (6.164.246.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 23:30:36.425012 2026] [security2:error] [pid 32208:tid 32208] [client 35.246.164.6:54332] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ic1.ic1.biz"] [uri "/.env.save"] [unique_id "apZG3J7slMKJBStxoE5k4gAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
loadsoporte
2026-09-01 03:30:33
(12 minutes ago)
RdpGuard detected brute-force attempt on HTTP
Brute-Force
๐ฉ๐ช
SiyCah
2026-09-01 03:00:02
(42 minutes ago)
IP banned by fail2ban; banned in jail apache-modsecurity. Report generated by fail2abuseipdb.
Hacking
Brute-Force
Web App Attack
๐ณ๐ฑ
thedreamer.nl
2026-09-01 01:40:58
(2 hours ago)
35.246.164.6 - - [01/Sep/2026:03:39:27 +0200] "GET /.env.prod HTTP/1.1" 404 14 "-" "crusader-worker/ ...
show more
35.246.164.6 - - [01/Sep/2026:03:39:27 +0200] "GET /.env.prod HTTP/1.1" 404 14 "-" "crusader-worker/1.0" "DE" "Frankfurt am Main" "50.11690" "8.68370"
35.246.164.6 - - [01/Sep/2026:03:39:27 +0200] "GET /.env.production HTTP/1.1" 404 14 "-" "crusader-worker/1.0" "DE" "Frankfurt am Main" "50.11690" "8.68370"
35.246.164.6 - - [01/Sep/2026:03:39:27 +0200] "GET /.env HTTP/1.1" 404 14 "-" "crusader-worker/1.0" "DE" "Frankfurt am Main" "50.11690" "8.68370"
35.246.164.6 - - [01/Sep/2026:03:39:27 +0200] "GET /.env.old HTTP/1.1" 404 14 "-" "crusader-worker/1.0" "DE" "Frankfurt am Main" "50.11690" "8.68370"
...
show less
Hacking
Brute-Force
Bad Web Bot
Web App Attack
๐ฒ๐พ
Rizzy
2026-09-01 01:37:29
(2 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack
Anonymous
2026-09-01 01:15:55
(2 hours ago)
Banned by Fail2Ban on server
Web App Attack
๐ธ๐ช
vaia.cloud
2026-09-01 01:05:03
(2 hours ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 00:53:23
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.246.164.6 (6.164.246.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.246.164.6 (6.164.246.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 20:53:19.979368 2026] [security2:error] [pid 23831:tid 23831] [client 35.246.164.6:39784] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dceabronwilliams.com"] [uri "/.env.bak"] [unique_id "apYh_8stCqg2tzgz_PUVuwAAAFo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-09-01 00:39:05
(3 hours ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.env.local (+12 more) | 2026-09-01 00:39 UTC
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 00:35:57
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.246.164.6 (6.164.246.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.246.164.6 (6.164.246.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 20:35:52.975757 2026] [security2:error] [pid 31294:tid 31294] [client 35.246.164.6:55212] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ctrussell.grabnerconsulting.com"] [uri "/.env"] [unique_id "apYd6AT_nES8VYLxqznIqwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 00:16:05
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.246.164.6 (6.164.246.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.246.164.6 (6.164.246.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 20:15:59.128268 2026] [security2:error] [pid 2133:tid 2133] [client 35.246.164.6:57524] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.itaxcenter.com"] [uri "/.env.backup"] [unique_id "apYZPx3gKQWxly1fnZ9NsAAAACQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
Saec
2026-08-31 23:48:01
(3 hours ago)
Jarvis auto-ban: CF top attacker on saec.me (26 hits, DE)
Port Scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-31 22:20:49
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.246.164.6 (6.164.246.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.246.164.6 (6.164.246.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 18:20:04.065254 2026] [security2:error] [pid 29651:tid 29651] [client 35.246.164.6:58548] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.madisonworkshopwest.com"] [uri "/.env.prod"] [unique_id "apX-FKPKkHs13td1C2-CxgAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-08-31 22:20:19
(5 hours ago)
Multiple WAF Violations
Web App Attack
๐ฌ๐ง
Aetherweb Ark
2026-08-31 22:19:29
(5 hours ago)
(mod_security) mod_security (id:949110) triggered by 35.246.164.6 (DE/Germany/6.164.246.35.bc.google ...
show more
(mod_security) mod_security (id:949110) triggered by 35.246.164.6 (DE/Germany/6.164.246.35.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack