Anonymous
2026-09-16 08:56:36
(4 days ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
๐บ๐ธ
ruusvuu
2026-09-16 08:21:06
(4 days ago)
Automated abuse report: 15 attack/probe requests from Google LLC / JP.
Targeted paths: /.env, //vend ...
show more
Automated abuse report: 15 attack/probe requests from Google LLC / JP.
Targeted paths: /.env, //vendor/.env, //lib/.env, //lab/.env, //cronlab/.env.
Sample log lines:
[mir-com] [9/16/2026, 1:21:05 AM] GET .mirregistry.com//app/.env 404 34.104.248.14 https://www.google.com/ 4.221 ms
[mir-com] [9/16/2026, 1:21:06 AM] GET .mirregistry.com//apps/.env 404 34.104.248.14 https://www.google.com/ 4.279 ms
[mir-com] [9/16/2026, 1:21:06 AM] GET .mirregistry.com//uploads/.env 404 34.104.248.14 https://www.google.com/ 4.132 ms
Detected by an automated web-server log monitor.
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 00:08:29
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.104.248.14 (14.248.104.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.104.248.14 (14.248.104.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 20:08:22.449210 2026] [security2:error] [pid 1964:tid 1964] [client 34.104.248.14:43362] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lynnejewson.com"] [uri "/.env"] [unique_id "aqnd9thET-u-igCdIP5VLwAAAAM"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 19:43:12
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.104.248.14 (14.248.104.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.104.248.14 (14.248.104.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 15:43:08.517535 2026] [security2:error] [pid 11991:tid 11991] [client 34.104.248.14:60998] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fundingangelinvestors.com"] [uri "/.env"] [unique_id "aqmfzIa_NtGd6Xz-ju6CAwAAAAk"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 17:42:12
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.104.248.14 (14.248.104.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.104.248.14 (14.248.104.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 13:42:04.876587 2026] [security2:error] [pid 24814:tid 24814] [client 34.104.248.14:51420] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "efsews.com"] [uri "/.env"] [unique_id "aqmDbGMw8LP6RWZ7QDjMfgAAAAo"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 10:59:06
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 34.104.248.14 (14.248.104.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.104.248.14 (14.248.104.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 06:59:00.465159 2026] [security2:error] [pid 816954:tid 816954] [client 34.104.248.14:33550] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "arogun.org"] [uri "/.env"] [unique_id "aqkk9ERdkvqRxUx3gNGi1gAAAAk"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
XICTRON
2026-09-15 06:30:07
(5 days ago)
ModSecurity rule violation detected by Fail2Ban
Web App Attack