🇺🇸
TPI-Abuse
2026-08-28 20:53:21
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 35.255.88.246 (246.88.255.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.255.88.246 (246.88.255.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 16:53:15.632172 2026] [security2:error] [pid 9368:tid 9368] [client 35.255.88.246:40552] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "test.boardingatthewedge.com"] [uri "/.env"] [unique_id "apH1OwsuQAgBs_qVV4VaRgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-28 20:34:24
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 35.255.88.246 (246.88.255.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.255.88.246 (246.88.255.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 16:34:20.026309 2026] [security2:error] [pid 24282:tid 24282] [client 35.255.88.246:38176] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.buygoldandsilveratspot.mroxygen.org"] [uri "/.env.production"] [unique_id "apHwzJgTuyhCqq4_wXnLxgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
0x44
2026-08-28 19:52:22
(3 weeks ago)
TCP SYN Discovery - Flooding
DDoS Attack
🇺🇸
TPI-Abuse
2026-08-28 19:44:34
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 35.255.88.246 (246.88.255.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.255.88.246 (246.88.255.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 15:44:30.778183 2026] [security2:error] [pid 21208:tid 21208] [client 35.255.88.246:56572] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sekelconsulting.com"] [uri "/.env.prod"] [unique_id "apHlHoGo3rHu-77XvnYMGAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Lino Project
2026-08-28 19:10:24
(3 weeks ago)
CrowdSec abuse IP report (host SRV-2) Scenario: crowdsecurity/http-sensitive-files
Hacking
🇩🇪
sigurg
2026-08-28 19:06:07
(3 weeks ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇬🇧
WebNiraj
2026-08-28 19:05:30
(3 weeks ago)
(mod_security) mod_security (id:949110) triggered by 35.255.88.246 (US/United States/246.88.255.35.b ...
show more
(mod_security) mod_security (id:949110) triggered by 35.255.88.246 (US/United States/246.88.255.35.bc.googleusercontent.com): 5 in the last 3600 secs [SIGMA]
show less
Brute-Force
🇩🇪
on-com
2026-08-28 18:11:11
(3 weeks ago)
URL scan
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-08-28 17:57:39
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 35.255.88.246 (246.88.255.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.255.88.246 (246.88.255.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 13:57:31.406676 2026] [security2:error] [pid 10726:tid 10726] [client 35.255.88.246:36582] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "economy-cleaners.com"] [uri "/.env.dev"] [unique_id "apHMC9yJEhMFPVoHjVLwIgAAACc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
4server
2026-08-28 16:54:22
(3 weeks ago)
[FriAug2818:54:15.7893042026][security2:error][pid2925270:tid2925367][client35.255.88.246:0]ModSecur ...
show more
[FriAug2818:54:15.7893042026][security2:error][pid2925270:tid2925367][client35.255.88.246:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(\?:/\(\?:\^\|/\)\\\\\\\\.\(env\|git\|svn\|hg\|DS_Store\)\|/\(\?:wp-config\|\\\\\\\\.htaccess\|\\\\\\\\.htpasswd\)\|\\\\\\\\.\(\?:sql\|bak\|old\|log\)\$\)\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"156\"][id\"960720\"][msg\"Forbiddenfileaccessattempt\"][severity\"CRITICAL\"][hostname\"simireinigung.ch\"][uri\"/storage/logs/laravel.log\"][unique_id\"apG9N2pTE0a6uUIB3DfUAQAAAQI\"]
show less
Port Scan
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-08-28 16:33:51
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 35.255.88.246 (246.88.255.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.255.88.246 (246.88.255.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 12:33:45.624412 2026] [security2:error] [pid 28629:tid 28629] [client 35.255.88.246:49828] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "claireashton.com"] [uri "/.env.production"] [unique_id "apG4aYxktoxPcZUl0GmJpwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-28 15:57:18
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 35.255.88.246 (246.88.255.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.255.88.246 (246.88.255.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 11:57:13.495950 2026] [security2:error] [pid 14014:tid 14014] [client 35.255.88.246:58180] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tacanicsa.com"] [uri "/.env.local"] [unique_id "apGv2Vs0KpO6FxE2CFadzQAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-28 15:10:38
(3 weeks ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
🇺🇸
TPI-Abuse
2026-08-28 15:09:04
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 35.255.88.246 (246.88.255.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.255.88.246 (246.88.255.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 11:08:56.394555 2026] [security2:error] [pid 12357:tid 12357] [client 35.255.88.246:43996] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gkerby.com"] [uri "/.env.dev"] [unique_id "apGkiPzuR2vq5T-LwHaxWgAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇷
Halux
2026-08-28 14:56:15
(3 weeks ago)
35.255.88.246 Web Application Firewall multiple violations
Hacking
Web App Attack