🇫🇷
SpaceHost-Server
2026-09-06 22:20:58
(1 day ago)
Brute-Force
Web App Attack
🇮🇩
Burayot
2026-09-06 14:21:21
(2 days ago)
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 35.254.244.111 (US/United States/111 ...
show more
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 35.254.244.111 (US/United States/111.244.254.35.bc.googleusercontent.com): 1 in the last 3600 secs
show less
Web App Attack
🇨🇦
cubie
2026-09-06 13:52:18
(2 days ago)
Port Scan: Admin Enumeration - Reported by CubieCloud Firewall [CFW_H326-009]
Port Scan
🇺🇸
TPI-Abuse
2026-09-06 12:45:17
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 35.254.244.111 (111.244.254.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.254.244.111 (111.244.254.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 08:45:10.978605 2026] [security2:error] [pid 13289:tid 13289] [client 35.254.244.111:56866] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.caalmconsulting.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.caalmconsulting.com"] [uri "/rclone.conf"] [unique_id "ap1gVh9GKsK8yUQbACUVYAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
macrob
2026-09-06 12:06:33
(2 days ago)
2026/09/06 12:06:32 [error] 2274822#2274822: *562866700 access forbidden by rule, client: 35.254.244 ...
show more
2026/09/06 12:06:32 [error] 2274822#2274822: *562866700 access forbidden by rule, client: 35.254.244.111, server: ca5h.win, request: "GET /_nuxt/../.env HTTP/1.1", host: "ca5h.win"
2026/09/06 12:06:32 [error] 2274822#2274822: *562866701 access forbidden by rule, client: 35.254.244.111, server: ca5h.win, request: "GET /static../.env HTTP/1.1", host: "ca5h.win"
2026/09/06 12:06:32 [error] 2274822#2274822: *562866702 access forbidden by rule, client: 35.254.244.111, server: ca5h.win, request: "GET /.pypirc HTTP/1.1", host: "ca5h.win"
...
show less
Web App Attack
Anonymous
2026-09-06 11:47:47
(2 days ago)
Web Attack Next.js Authorization Bypass Vulnerability
Web App Attack
🇧🇾
lns.bz
2026-09-06 08:59:51
(2 days ago)
.env scanning [BY]
Web App Attack
🇩🇪
macrob
2026-09-06 08:57:04
(2 days ago)
2026/09/06 08:57:02 [error] 2142590#2142590: *562357758 access forbidden by rule, client: 35.254.244 ...
show more
2026/09/06 08:57:02 [error] 2142590#2142590: *562357758 access forbidden by rule, client: 35.254.244.111, server: ca5h.win, request: "GET /.dockerenv HTTP/1.1", host: "ca5h.win"
2026/09/06 08:57:03 [error] 2142588#2142588: *562357753 access forbidden by rule, client: 35.254.244.111, server: ca5h.win, request: "GET /.env?raw HTTP/1.1", host: "ca5h.win"
2026/09/06 08:57:03 [error] 2142590#2142590: *562357776 access forbidden by rule, client: 35.254.244.111, server: ca5h.win, request: "GET /.env.local?raw HTTP/1.1", host: "ca5h.win"
...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 08:06:03
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.254.244.111 (111.244.254.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.254.244.111 (111.244.254.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 04:05:57.725868 2026] [security2:error] [pid 7541:tid 7541] [client 35.254.244.111:42554] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cabanaconstructionandpaving.com"] [uri "/@fs/.env"] [unique_id "ap0e5TAC1EAXe94yfTzbcAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
VHosting
2026-09-06 08:05:03
(2 days ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇫🇷
Octopuce
2026-09-06 06:50:08
(2 days ago)
Aggressive web search of vulnerable pages: /.env /.env.local /api/.env /backend/.env /admin/.env .. ...
show more
Aggressive web search of vulnerable pages: /.env /.env.local /api/.env /backend/.env /admin/.env ...
show less
Web App Attack
🇳🇱
debestelapp
2026-09-06 06:45:11
(2 days ago)
Web App Attack
Anonymous
2026-09-06 06:42:32
(2 days ago)
IP matched detection query more than 2 hosts and only bad rq long ban.
Brute-Force
Web App Attack
Hacking
Anonymous
2026-09-06 06:06:53
(2 days ago)
35.254.244.111 - - [06/Sep/2026:01:00:53 -0500] "GET /.env HTTP/1.1" 403 199 "-" "Mozilla/5.0 (Windo ...
show more
35.254.244.111 - - [06/Sep/2026:01:00:53 -0500] "GET /.env HTTP/1.1" 403 199 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/148.0.0.0 Safari/537.36 Edg/148.0.0.0" 35.254.244.111
35.254.244.111 - - [06/Sep/2026:01:00:53 -0500] "GET /.env.production HTTP/1.1" 403 199 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/148.0.0.0 Safari/537.36 Edg/148.0.0.0" 35.254.244.111
35.254.244.111 - - [06/Sep/2026:01:00:53 -0500] "GET /.env.example HTTP/1.1" 403 199 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/148.0.0.0 Safari/537.36 Edg/148.0.0.0" 35.254.244.111
35.254.244.111 - - [06/Sep/2026:01:00:53 -0500] "GET /.env.backup HTTP/1.1" 403 199 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/148.0.0.0 Safari/537.36 Edg/148.0.0.0" 35.254.244.111
35.254.244.111 - - [06/Sep/2026:01:00:53 -0500] "GET /.env.bak HTTP/1.1" 403 1
...
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-06 06:00:21
(2 days ago)
| Multiple common web attacks from same source ip. (multiple servers)
Web App Attack
Hacking
SQL Injection