🇧🇪
cmbplf
2026-09-11 21:43:12
(10 hours ago)
419 requests with url.path */@fs/*
188 requests with url.path *.ssh/*
107 requests with url.path ...
show more
419 requests with url.path */@fs/*
188 requests with url.path *.ssh/*
107 requests with url.path *.aws/*
show less
Brute-Force
Bad Web Bot
🇫🇷
Stara
2026-09-11 20:07:28
(11 hours ago)
ModSecurity detected web attack - .env/config probing or SQLi/Code injection (Rule 949110)
Brute-Force
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 18:59:17
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.10.93.196 (196.93.10.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.10.93.196 (196.93.10.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 14:59:12.645854 2026] [security2:error] [pid 1818784:tid 1819530] [client 34.10.93.196:51000] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "besfixedwireless.com"] [uri "/.env.backup"] [unique_id "aqRPgGLPhJgtVadW5skMZAAAAMI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-11 18:45:02
(13 hours ago)
suspicious request in access.log
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 18:38:14
(13 hours ago)
(mod_security) mod_security (id:210580) triggered by 34.10.93.196 (196.93.10.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210580) triggered by 34.10.93.196 (196.93.10.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 14:38:06.712901 2026] [security2:error] [pid 23686:tid 23686] [client 34.10.93.196:55920] ModSecurity: Access denied with code 403 (phase 2). Matched phrase ".ssh/id_rsa" at ARGS:filename. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/08_Global_Other.conf"] [line "57"] [id "210580"] [rev "2"] [msg "COMODO WAF: OS File Access Attempt||bernsteinip.com|F|2"] [data "Matched Data: .ssh/id_rsa found within ARGS:filename: file:/root/.ssh/id_rsa"] [severity "CRITICAL"] [tag "CWAF"] [tag "Other"] [hostname "bernsteinip.com"] [uri "/__vite_rsc_findSourceMapURL"] [unique_id "aqRKjrIHBE1M_diKdK7ovwAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 18:19:36
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.10.93.196 (196.93.10.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.10.93.196 (196.93.10.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 14:19:29.548848 2026] [security2:error] [pid 4080:tid 4080] [client 34.10.93.196:42354] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "berlatinc.com"] [uri "/.env.example"] [unique_id "aqRGMTEv9rvOMA9b_yshIwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇸🇪
vaia.cloud
2026-09-11 18:10:01
(13 hours ago)
crowdsecurity/http-cve-2021-41773
Brute-Force
Web App Attack
🇺🇸
mnsf
2026-09-11 18:05:36
(13 hours ago)
Scanning/Probing (25)
Brute-Force
Web App Attack
🇳🇱
Savvii
2026-09-11 18:04:08
(13 hours ago)
20 attempts against mh-misbehave-ban on redirect
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-11 17:40:03
(14 hours ago)
Bot / scanning and/or hacking attempts: GET /src/amplifyconfiguration.json HTTP/2.0, GET /storage/.e ...
show more
Bot / scanning and/or hacking attempts: GET /src/amplifyconfiguration.json HTTP/2.0, GET /storage/.env HTTP/2.0, GET /userfiles?path=../../../../.env HTTP/2.0, GET /aws-exports.js HTTP/2.0, GET /@fs/app/.env.local?import&raw?? HTTP/2.0, GET /.env.swp HTTP/2.0, GET /values.yaml HTTP/2.0, GET /userfiles?path=../../.env HTTP/2.0, GET /amplify_outputs.json HTTP/2.0, GET /config/runtime.exs HTTP/2.0, GET /.env?.svg?.wasm?init HTTP/2.0, GET /awsConfig.js HTTP/2.0, GET /.env.production?import&raw HTTP/2.0
show less
Hacking
Web App Attack
🇬🇧
bensmithurst
2026-09-11 17:24:42
(14 hours ago)
34.10.93.196 - - [11/Sep/2026:17:24:40 +0000] "GET /..%2f.env HTTP/1.1" 400 150 "-" "-"
34.10.93.196 ...
show more
34.10.93.196 - - [11/Sep/2026:17:24:40 +0000] "GET /..%2f.env HTTP/1.1" 400 150 "-" "-"
34.10.93.196 - - [11/Sep/2026:17:24:41 +0000] "GET /@fs/..%2f..%2f..%2f..%2f..%2fproc/self/environ HTTP/1.1" 400 150 "-" "-"
34.10.93.196 - - [11/Sep/2026:17:24:41 +0000] "GET /public/plugins/grafana-clock-panel/../../../../../../../../proc/self/environ HTTP/1.1" 400 150 "-" "-"
34.10.93.196 - - [11/Sep/2026:17:24:41 +0000] "GET /%2e%2e/.env HTTP/1.1" 400 150 "-" "-"
34.10.93.196 - - [11/Sep/2026:17:24:41 +0000] "GET /public/plugins/text/../../../../../../../../proc/self/environ HTTP/1.1" 400 150 "-" "-"
... [host=LAN***]
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 17:11:53
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.10.93.196 (196.93.10.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.10.93.196 (196.93.10.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 13:11:45.592561 2026] [security2:error] [pid 30245:tid 30245] [client 34.10.93.196:59768] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bennoyes.com"] [uri "/.env.js"] [unique_id "aqQ2UXc4rGmTPi4QqS5l-wAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 16:55:09
(14 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.10.93.196 (196.93.10.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.10.93.196 (196.93.10.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 12:55:02.991631 2026] [security2:error] [pid 11815:tid 11815] [client 34.10.93.196:34392] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||benjaminshaw.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "benjaminshaw.com"] [uri "/z9x8c7v6b5-debug-trigger-benjaminshaw.com"] [unique_id "aqQyZsUCWfqjwGuTvG32bgAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇮
NoaQT
2026-09-11 16:45:23
(14 hours ago)
2026-09-11T16:45:22.112336+00:00 ingress-1 haproxy[16887]: 34.10.93.196:60518 [11/Sep/2026:16:45:22. ...
show more
2026-09-11T16:45:22.112336+00:00 ingress-1 haproxy[16887]: 34.10.93.196:60518 [11/Sep/2026:16:45:22.112] https_in~ https_in/<NOSRV> 0/-1/-1/-1/0 429 225 - - PR-- 65/65/0/0/0 0/0 "GET https://benigarautomocion.com/@fs/app/.env.production?import&raw?? HTTP/2.0"
2026-09-11T16:45:22.196847+00:00 ingress-1 haproxy[16887]: 34.10.93.196:60518 [11/Sep/2026:16:45:22.196] https_in~ https_in/<NOSRV> 0/-1/-1/-1/0 429 225 - - PR-- 65/65/0/0/0 0/0 "POST https://benigarautomocion.com/v1/graphql HTTP/2.0"
2026-09-11T16:45:22.218071+00:00 ingress-1 haproxy[16887]: 34.10.93.196:60518 [11/Sep/2026:16:45:22.217] https_in~ https_in/<NOSRV> 0/-1/-1/-1/0 429 225 - - PR-- 65/65/0/0/0 0/0 "GET https://benigarautomocion.com/.env?.svg?.wasm?init HTTP/2.0"
2026-09-11T16:45:22.218553+00:00 ingress-1 haproxy[16887]: 34.10.93.196:60518 [11/Sep/2026:16:45:22.217] https_in~ https_in/<NOSRV> 0/-1/-1/-1/0 429 225 - - PR-- 65/65/0/0/0 0/0 "GET https://benigarautomocion.com/@fs/../.env?import&raw?? HTTP/2.0"
2026-09-11T16
...
show less
DDoS Attack
🇮🇹
VHosting
2026-09-11 16:35:03
(15 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack