🇺🇸
TPI-Abuse
2026-09-07 20:50:27
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.253.38.154 (154.38.253.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.253.38.154 (154.38.253.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 16:50:24.297579 2026] [security2:error] [pid 11174:tid 11174] [client 35.253.38.154:3084] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.thepianosmith.com"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252froot/.env"] [unique_id "ap8jkH2NYCIPWCZiSulRxAAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-09-07 20:45:06
(17 hours ago)
Web attack/malicious scanning detected
Web App Attack
🇩🇪
maxpower
2026-09-07 20:44:26
(17 hours ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 35.253.38.154 (US/United States/154.38.2 ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 35.253.38.154 (US/United States/154.38.253.35.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 35.253.38.154 - - [07/Sep/2026:22:44:22 +0200] "GET /@fs/root/.aws/credentials.backup?raw?? HTTP/2.0" 200 4748 "-" "Mozilla/5.0 (compatible; GrokBot/1.0; +https://x.ai/grokbot)" "35.253.38.154" host=essenzaestetica.eu
show less
Port Scan
🇺🇸
mnsf
2026-09-07 20:05:22
(18 hours ago)
Scanning/Probing (11)
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 18:57:20
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.253.38.154 (154.38.253.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.253.38.154 (154.38.253.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 14:57:14.160954 2026] [security2:error] [pid 5605:tid 5716] [client 35.253.38.154:54532] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "geegeefive.com"] [uri "/@fs/../.env"] [unique_id "ap8JCj2YA4KZBVkn7lNlQAAAAE4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
grassau.com
2026-09-07 18:55:45
(19 hours ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 35.253.38.154 (US/Un ...
show more
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 35.253.38.154 (US/United States/Iowa/Council Bluffs/154.38.253.35.bc.googleusercontent.com)
show less
Bad Web Bot
🇸🇪
vaia.cloud
2026-09-07 18:50:03
(19 hours ago)
crowdsecurity/http-probing
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 18:37:13
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.253.38.154 (154.38.253.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.253.38.154 (154.38.253.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 14:37:07.709697 2026] [security2:error] [pid 21775:tid 21775] [client 35.253.38.154:9680] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.pharmahc.com"] [uri "/@fs/.env.production"] [unique_id "ap8EU4A9LrEG693TMkJmbgAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
ConsulHosting
2026-09-07 18:29:09
(20 hours ago)
Automatically blocked due to distributed attack
Hacking
🇳🇱
middelkoopcc
2026-09-07 18:17:01
(20 hours ago)
2026-09-07 20:14:48 GET /@fs/.env?raw?? [301] && 2026-09-07 20:14:49 GET /@fs/..%252f..%252f..%252f. ...
show more
2026-09-07 20:14:48 GET /@fs/.env?raw?? [301] && 2026-09-07 20:14:49 GET /@fs/..%252f..%252f..%252f..%252f..%252froot/.env?raw?? [301] && 2026-09-07 20:14:49 GET /@fs/src/.env?raw?? [301] && 153 more within 20 minutes
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 18:11:48
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.253.38.154 (154.38.253.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.253.38.154 (154.38.253.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 14:11:40.904441 2026] [security2:error] [pid 8068:tid 8068] [client 35.253.38.154:50304] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.jenricker.com"] [uri "/@fs/src/.env"] [unique_id "ap7-XDtzF6Eacy2M_10tJgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
Rocky Mountain Bioengineering Symposium
2026-09-07 17:29:01
(21 hours ago)
[Mon Sep 07 11:29:01.581907 2026] [authz_core:error] [pid 89514:tid 139763814204992] [client 35.253. ...
show more
[Mon Sep 07 11:29:01.581907 2026] [authz_core:error] [pid 89514:tid 139763814204992] [client 35.253.38.154:17066] AH01630: client denied by server configuration: /var/www/horde/@fs
[Mon Sep 07 11:29:01.632357 2026] [authz_core:error] [pid 89515:tid 139765282240064] [client 35.253.38.154:17108] AH01630: client denied by server configuration: /var/www/horde/@fs
[Mon Sep 07 11:29:01.643042 2026] [authz_core:error] [pid 89515:tid 139766246909504] [client 35.253.38.154:17090] AH01630: client denied by server configuration: /var/www/horde/@fs
...
show less
Bad Web Bot
Anonymous
2026-09-07 17:02:28
(21 hours ago)
Multiple web server 400 error codes from same source ip
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 17:00:17
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.253.38.154 (154.38.253.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.253.38.154 (154.38.253.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 13:00:09.403744 2026] [security2:error] [pid 21885:tid 21885] [client 35.253.38.154:44340] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.johnlittlehorn.littlehorndesign.com"] [uri "/@fs/.env"] [unique_id "ap7tmYvWIOXjpTGNJZlMLwAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇪🇸
beats
2026-09-07 16:59:05
(21 hours ago)
Reported by CrowdSec
Brute-Force
Bad Web Bot
Web App Attack