🇺🇸
TPI-Abuse
2026-09-07 20:21:48
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.255.144.202 (202.144.255.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.255.144.202 (202.144.255.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 16:21:40.207676 2026] [security2:error] [pid 6479:tid 6479] [client 35.255.144.202:3840] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.kaldaragroup.com"] [uri "/@fs/app/.env"] [unique_id "ap8c1G3ny9ET4jkTRMIyIgAAACQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Hazzard
2026-09-07 20:14:32
(9 hours ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted]): (CF_ENABLE)
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-07 20:00:57
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.255.144.202 (202.144.255.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.255.144.202 (202.144.255.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 16:00:50.687524 2026] [security2:error] [pid 26588:tid 26588] [client 35.255.144.202:11610] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.sunsettrailsardmore.com"] [uri "/@fs/.env"] [unique_id "ap8X8npDwqJrDOFZV8zK8AAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇰
HostingGroup
2026-09-07 19:51:53
(9 hours ago)
Automated malicious activity (Honeypot Trap) detected and blocked at the CDN edge by NordicCDN Shiel ...
show more
Automated malicious activity (Honeypot Trap) detected and blocked at the CDN edge by NordicCDN Shield. Offenses: 7. First blocked: 2026-09-07.
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 19:13:14
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.255.144.202 (202.144.255.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.255.144.202 (202.144.255.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 15:13:09.640854 2026] [security2:error] [pid 9791:tid 9791] [client 35.255.144.202:60252] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ftp.jeffstamper.com"] [uri "/@fs/.env.development"] [unique_id "ap8MxZ3r_1bDadH-YUe79gAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 18:52:17
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.255.144.202 (202.144.255.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.255.144.202 (202.144.255.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 14:52:11.171132 2026] [security2:error] [pid 24294:tid 24294] [client 35.255.144.202:12830] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "styxfreeworld.grayhost.net"] [uri "/@fs/root/.env"] [unique_id "ap8H2_Fgw_OOSxTVKvA3mgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 18:15:50
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.255.144.202 (202.144.255.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.255.144.202 (202.144.255.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 14:15:45.038767 2026] [security2:error] [pid 28802:tid 28802] [client 35.255.144.202:64016] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.timjbutler.com"] [uri "/@fs/root/.env"] [unique_id "ap7_UfDzE_irvugXt3vLOwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇷🇴
iulianh
2026-09-07 18:04:23
(11 hours ago)
80,443
Brute-Force
SSH
🇧🇪
cmbplf
2026-09-07 17:47:55
(11 hours ago)
300 requests with url.path *config.json
Brute-Force
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-07 17:47:17
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.255.144.202 (202.144.255.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.255.144.202 (202.144.255.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 13:47:14.386162 2026] [security2:error] [pid 9246:tid 9246] [client 35.255.144.202:58402] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.terrysavastano.com"] [uri "/@fs/.env.local"] [unique_id "ap74ooeRNu_pDJm6bFOHugAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇲🇾
Rizzy
2026-09-07 17:27:45
(12 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack
🇫🇷
Octopuce
2026-09-07 17:25:10
(12 hours ago)
Aggressive web search of vulnerable pages: /img../.env /.docker/.env /.env.local /v2/.env /assets../ ...
show more
Aggressive web search of vulnerable pages: /img../.env /.docker/.env /.env.local /v2/.env /assets../.env ...
show less
Web App Attack
🇳🇱
Savvii
2026-09-07 17:23:35
(12 hours ago)
20 attempts against mh-misbehave-ban on comet
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 16:50:16
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.255.144.202 (202.144.255.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.255.144.202 (202.144.255.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 12:50:08.578598 2026] [security2:error] [pid 28795:tid 28795] [client 35.255.144.202:38886] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.extreme-atv.com"] [uri "/@fs/../.env"] [unique_id "ap7rQGkc3-xy2SLyzhuFVQAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
VHosting
2026-09-07 16:25:03
(13 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack