🇺🇸
TPI-Abuse
2026-09-06 03:50:08
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.247.253.140 (140.253.247.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.247.253.140 (140.253.247.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:49:59.427150 2026] [security2:error] [pid 16512:tid 16512] [client 35.247.253.140:37204] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.montymilburn.com"] [uri "/.env.local"] [unique_id "apzi51joYz6FrJFXpIE9fAAAAIs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 02:58:07
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.247.253.140 (140.253.247.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.247.253.140 (140.253.247.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:58:03.402703 2026] [security2:error] [pid 15234:tid 15234] [client 35.247.253.140:56684] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.naturalhomebuilders.com"] [uri "/.env.local"] [unique_id "apzWu_epMKcyNtuuBEkW2AAAAEU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
FeG Deutschland
2026-09-06 02:34:51
(14 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 01:46:46
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.247.253.140 (140.253.247.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.247.253.140 (140.253.247.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 21:46:41.976380 2026] [security2:error] [pid 19086:tid 19086] [client 35.247.253.140:44472] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ftp.newerc.com"] [uri "/wp-config.php.swp"] [unique_id "apzGAcmZEskFZh2ykklcrQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
dynamix
2026-09-06 01:34:10
(15 hours ago)
Multiple WAF Violations
Web App Attack
Anonymous
2026-09-06 01:11:46
(16 hours ago)
Blocked by ModSec and CSF
Port Scan
🇺🇸
TPI-Abuse
2026-09-06 01:08:23
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.247.253.140 (140.253.247.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.247.253.140 (140.253.247.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 21:08:16.474682 2026] [security2:error] [pid 14694:tid 14694] [client 35.247.253.140:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.kidswithcamerasmovie.com"] [uri "/.env.bak"] [unique_id "apy9AGm5GeD2MlTDvYxu1AAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
raph
2026-09-06 00:40:27
(16 hours ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 00:26:38
(17 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.247.253.140 (140.253.247.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.247.253.140 (140.253.247.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 20:26:34.218641 2026] [security2:error] [pid 8862:tid 8862] [client 35.247.253.140:43078] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||hr-base-camp.com.smartstylehair.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "hr-base-camp.com.smartstylehair.com"] [uri "/db.sql"] [unique_id "apyzOvb-jFjmuBVkWyh_-QAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
e.fierstra
2026-09-06 00:20:15
(17 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 23:53:17
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.247.253.140 (140.253.247.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.247.253.140 (140.253.247.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 19:53:11.223382 2026] [security2:error] [pid 32340:tid 32340] [client 35.247.253.140:47512] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.musicpolitan.com"] [uri "/wp-config.php~"] [unique_id "apyrZ7sfOtJKQRPmJ7-RCwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
IndigoRidge
2026-09-05 23:47:08
(17 hours ago)
[05/Sep/2026:19:47:07.480932 --0400] apyp@xI1y-@L08EdMytDdAAAAdA 35.247.253.140 34708 205.233.18.17 ...
show more
[05/Sep/2026:19:47:07.480932 --0400] apyp@xI1y-@L08EdMytDdAAAAdA 35.247.253.140 34708 205.233.18.17 7081
[05/Sep/2026:19:47:07.481260 --0400] apyp@9RRrRTGKYKM62t5EwAAAtI 35.247.253.140 34718 205.233.18.17 7081
[05/Sep/2026:19:47:07.492182 --0400] apyp@2jXsgLkEg79yVVYUgAAAA0 35.247.253.140 34836 205.233.18.17 7081
[05/Sep/2026:19:47:07.492795 --0400] apyp@@nkF3EQX2VX6Uln3QAAAJI 35.247.253.140 34852 205.233.18.17 7081
[05/Sep/2026:19:47:07.494383 --0400] apyp@ypoDWFq8ni5eHp6gQAAAMY 35.247.253.140 34822 205.233.18.17 7081
...
show less
Hacking
🇺🇸
TPI-Abuse
2026-09-05 23:30:45
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.247.253.140 (140.253.247.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.247.253.140 (140.253.247.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 19:30:41.131839 2026] [security2:error] [pid 26234:tid 26234] [client 35.247.253.140:48530] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.jpkaz.com"] [uri "/.env"] [unique_id "apymIQTzN2HtihWdXJfAEwAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇩
rvsdi
2026-09-05 23:21:15
(18 hours ago)
[OGWAF] bad_reputation attack blocked | severity: high | GET /env | UA: crusader-worker/1.0
Web App Attack
🇮🇩
rvsdi
2026-09-05 23:21:14
(18 hours ago)
[OGWAF] path_traversal attack blocked | severity: high | GET /.env.save | UA: crusader-worker/1.0
Hacking
Web App Attack