🇺🇸
TPI-Abuse
2026-09-08 10:59:41
(58 minutes ago)
(mod_security) mod_security (id:210492) triggered by 104.199.138.0 (0.138.199.104.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 104.199.138.0 (0.138.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 06:59:37.340273 2026] [security2:error] [pid 27570:tid 27570] [client 104.199.138.0:55160] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dildog.ingberinteriors.com"] [uri "/@fs/root/.env"] [unique_id "ap_qmU4SVR0OAogwbERfKQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 10:40:11
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 104.199.138.0 (0.138.199.104.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 104.199.138.0 (0.138.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 06:40:04.132375 2026] [security2:error] [pid 12627:tid 12717] [client 104.199.138.0:43278] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "accutar.com"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252froot/.env"] [unique_id "ap_mBPq0A1oQIqsBqjOQ1gAAAgA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
e.fierstra
2026-09-08 10:30:44
(1 hour ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇳🇱
cybertailor
2026-09-08 10:02:07
(1 hour ago)
104.199.138.0 - - [08/Sep/2026:15:02:03 +0500] "GET /@fs/.env?raw?? HTTP/1.1" 404 178 "-" "Mozilla/5 ...
show more
104.199.138.0 - - [08/Sep/2026:15:02:03 +0500] "GET /@fs/.env?raw?? HTTP/1.1" 404 178 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.1088.204 Safari/537.36 Edg/124.0.1088.204; compatible; WhatsApp/10.0.2.1"
104.199.138.0 - - [08/Sep/2026:15:02:03 +0500] "GET /@fs/root/.env?raw?? HTTP/1.1" 404 178 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.4193.93 Safari/537.36; compatible; ClaudeBot/1.0; [email protected] "
104.199.138.0 - - [08/Sep/2026:15:02:03 +0500] "GET /@fs/..%252f..%252f..%252f..%252f..%252froot/.env?raw?? HTTP/1.1" 404 146 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; TelegramBot/1.0)"
104.199.138.0 - - [08/Sep/2026:15:02:03 +0500] "GET /@fs/.env.local?raw?? HTTP/1.1" 404 146 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; Claude-User/1.0; +https://www.anthropic.com/claude-user"
104.199.138.0 - - [08/Sep/2026:15:02:03 +0500] "G
...
show less
Web App Attack
🇦🇺
aranguren.org
2026-09-08 09:59:33
(1 hour ago)
104.199.138.0 - - [08/Sep/2026:19:59:31 +1000] "GET /@fs/root/.env?raw?? HTTP/1.1" 404 994 "-" "Mozi ...
show more
104.199.138.0 - - [08/Sep/2026:19:59:31 +1000] "GET /@fs/root/.env?raw?? HTTP/1.1" 404 994 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; [email protected] )"
104.199.138.0 - - [08/Sep/2026:19:59:31 +1000] "GET /@fs/.env?raw?? HTTP/1.1" 404 994 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; TelegramBot/1.0"
104.199.138.0 - - [08/Sep/2026:19:59:31 +1000] "GET /@fs/..%252f..%252f..%252f..%252f..%252fproc/self/environ?raw?? HTTP/1.1" 404 994 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-SearchBot/1.0; +https://www.anthropic.com/claude-searchbot)"
104.199.138.0 - - [08/Sep/2026:19:59:31 +1000] "GET /@fs/..%252f..%252f..%252f..%252f..%252fapp/.env?raw?? HTTP/1.1" 404 994 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot)"
104.199.138.0 - - [08/Sep/2026:19:59:31 +1000] "GET /@fs/app/.env?raw?? HTTP/1.1" 404 994 "-" "
...
show less
Bad Web Bot
🇫🇷
Catalin Negru
2026-09-08 09:14:31
(2 hours ago)
Recidive ban by fail2ban on server.blackbit.ro
Brute-Force
🇺🇸
revslowmo
2026-09-08 08:56:39
(3 hours ago)
Bot attempt ssh bruteforce
Brute-Force
SSH
🇨🇭
4server
2026-09-08 08:11:49
(3 hours ago)
[TueSep0810:11:42.9737392026][security2:error][pid758612:tid758965][client104.199.138.0:0]ModSecurit ...
show more
[TueSep0810:11:42.9737392026][security2:error][pid758612:tid758965][client104.199.138.0:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".env\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"610\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"foodelivery.benvenutialfood.ch\"][uri\"/@fs/.env.staging\"][unique_id\"ap_DPhpvJkMuUuz2tY32qgAAAFI\"]
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 07:50:03
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.199.138.0 (0.138.199.104.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 104.199.138.0 (0.138.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 03:49:58.095118 2026] [security2:error] [pid 1957:tid 1957] [client 104.199.138.0:30160] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.adj-tech.net"] [uri "/@fs/.env"] [unique_id "ap--Jg3slNryJQuiUp2pdgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇪
cmbplf
2026-09-08 07:46:25
(4 hours ago)
107 requests with url.path *config.php
Brute-Force
Bad Web Bot
🇳🇱
i-turnradio.nl
2026-09-08 07:20:59
(4 hours ago)
2026-09-08 @ 09:20:56 (CET) ~ Blocked for trying to access: /@fs/src/.env?raw??
Web App Attack
🇩🇪
FeG Deutschland
2026-09-08 07:18:18
(4 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 1247
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 07:01:58
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.199.138.0 (0.138.199.104.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 104.199.138.0 (0.138.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 03:01:53.630075 2026] [security2:error] [pid 30483:tid 30483] [client 104.199.138.0:54756] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.daveroozendaal.com"] [uri "/@fs/../../.env"] [unique_id "ap-y4W47jHbVnLFg8JgN-gAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
maxpower
2026-09-08 06:30:13
(5 hours ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 104.199.138.0 (TW/Taiwan/0.138.199.104.b ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 104.199.138.0 (TW/Taiwan/0.138.199.104.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 104.199.138.0 - - [08/Sep/2026:08:30:09 +0200] "GET /@fs/home/ubuntu/.aws/credentials?raw?? HTTP/2.0" 429 41 "-" "Mozilla/5.0 (compatible; TelegramBot/1.0)" "104.199.138.0" host=www.direnzoassicurazioni.it
show less
Port Scan
Anonymous
2026-09-08 05:50:58
(6 hours ago)
CrowdSec: crowdsecurity/vpatch-env-access
Hacking
Web App Attack