πΊπΈ
TPI-Abuse
2026-08-29 01:12:52
(12 minutes ago)
(mod_security) mod_security (id:210492) triggered by 35.254.53.209 (209.53.254.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.254.53.209 (209.53.254.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 21:12:45.009950 2026] [security2:error] [pid 9738:tid 9738] [client 35.254.53.209:45290] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.talentstar.com"] [uri "/.env.example"] [unique_id "apIyDSz7d2YktaQfMrH8WAAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
mnsf
2026-08-29 00:09:05
(1 hour ago)
Abuse Detected (13)
Brute-Force
Web App Attack
π©πͺ
Marc
2026-08-28 23:28:53
(1 hour ago)
35.254.53.209 - - [29/Aug/2026:01:28:52 +0200] "GET /.env.dev HTTP/1.1" 404 4616 "-" "crusader-worke ...
show more
35.254.53.209 - - [29/Aug/2026:01:28:52 +0200] "GET /.env.dev HTTP/1.1" 404 4616 "-" "crusader-worker/1.0" 35.254.53.209 - - [29/Aug/2026:01:28:52 +0200] "GET /env HTTP/1.1" 404 4616 "-" "crusader-worker/1.0" 35.254.53.209 - - [29/Aug/2026:01:28:52 +0200] "GET /.env.backup HTTP/1.1" 404 4618 "-" "crusader-worker/1.0"
show less
Brute-Force
πΊπΈ
TPI-Abuse
2026-08-28 22:43:57
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.254.53.209 (209.53.254.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.254.53.209 (209.53.254.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 18:43:49.152733 2026] [security2:error] [pid 17395:tid 17395] [client 35.254.53.209:60970] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "abundancecompany.com"] [uri "/wp-config.php~"] [unique_id "apIPJcXlbUfhbJsF49sTVAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
homeshowdomain.nl
2026-08-28 21:59:45
(3 hours ago)
Auto-ban: >3000 req/min op 2026-08-28
Web App Attack
SSH
Hacking
π±πΊ
SiteXL
2026-08-28 21:20:17
(4 hours ago)
Automated Fail2Ban detection: malicious activity observed; source IP was banned.
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-28 20:52:49
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.254.53.209 (209.53.254.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.254.53.209 (209.53.254.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 16:52:41.488483 2026] [security2:error] [pid 27909:tid 27909] [client 35.254.53.209:57422] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "templeantiques.org"] [uri "/wp-config.php.swp"] [unique_id "apH1GWo9b7tc0n5ReUTeOwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-28 19:56:13
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.254.53.209 (209.53.254.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.254.53.209 (209.53.254.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 15:56:07.925352 2026] [security2:error] [pid 24339:tid 24339] [client 35.254.53.209:59474] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.cassies.jbaydeliveries.com"] [uri "/.env.old"] [unique_id "apHn18SamfrSF47UKbH0qgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
Dominik Lysiak
2026-08-28 17:51:46
(7 hours ago)
35.254.53.209 - - [28/Aug/2026:19:51:45 +0200] "GET /.env HTTP/1.1" 302 0 "-" "crusader-worker/1.0"
...
show more
35.254.53.209 - - [28/Aug/2026:19:51:45 +0200] "GET /.env HTTP/1.1" 302 0 "-" "crusader-worker/1.0"
35.254.53.209 - - [28/Aug/2026:19:51:45 +0200] "GET /.env.local HTTP/1.1" 302 0 "-" "crusader-worker/1.0"
35.254.53.209 - - [28/Aug/2026:19:51:45 +0200] "GET /.env.production HTTP/1.1" 302 0 "-" "crusader-worker/1.0"
...
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-28 16:42:00
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.254.53.209 (209.53.254.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.254.53.209 (209.53.254.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 12:41:52.535470 2026] [security2:error] [pid 20115:tid 20115] [client 35.254.53.209:50750] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ppcspetsitting.com"] [uri "/.env.local"] [unique_id "apG6UD7KkKXMsOVeKoyinQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-28 16:26:32
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.254.53.209 (209.53.254.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.254.53.209 (209.53.254.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 12:26:28.489950 2026] [security2:error] [pid 26311:tid 26311] [client 35.254.53.209:34544] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tobyscott.com"] [uri "/.env"] [unique_id "apG2tHhja5RN5jhJb56UHAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
Hazzard
2026-08-28 16:01:45
(9 hours ago)
(mod_security) mod_security triggered on hostname [redacted]): (CF_ENABLE)
SQL Injection
π©πͺ
FeG Deutschland
2026-08-28 15:59:23
(9 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
π©πͺ
ger-stg-sifi1
2026-08-28 15:45:35
(9 hours ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-28 15:37:44
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.254.53.209 (209.53.254.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.254.53.209 (209.53.254.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 11:37:37.755947 2026] [security2:error] [pid 2754587:tid 2754652] [client 35.254.53.209:47138] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ward-bergerhouse.org"] [uri "/.env.old"] [unique_id "apGrQZVJy0gU-giJKURknwAAAU0"]
show less
Brute-Force
Bad Web Bot
Web App Attack