🇺🇸
TPI-Abuse
2026-09-06 20:21:41
(57 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.11.178.163 (163.178.11.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.11.178.163 (163.178.11.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 16:21:35.980740 2026] [security2:error] [pid 17894:tid 17894] [client 34.11.178.163:58052] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.newmooncafe.com"] [uri "/%2e%2e/.env"] [unique_id "ap3LT2Z3e1ax3GsIhvzjQAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
D3monite
2026-09-06 19:43:02
(1 hour ago)
Attempted Brute Force (APIService)
Brute-Force
🇺🇸
TPI-Abuse
2026-09-06 19:25:42
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.11.178.163 (163.178.11.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.11.178.163 (163.178.11.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 15:25:34.657522 2026] [security2:error] [pid 20714:tid 20714] [client 34.11.178.163:46226] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ingberinteriors.com"] [uri "/.git/HEAD"] [unique_id "ap2-LvVZTl_LnAAT0XRxMAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 18:18:58
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.11.178.163 (163.178.11.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.11.178.163 (163.178.11.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 14:18:53.118313 2026] [security2:error] [pid 23397:tid 23448] [client 34.11.178.163:45716] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.streamriders.com.hdtv55.com"] [uri "/assets../.env"] [unique_id "ap2ujYjpuV7PPZkyXWNjOQAAANQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Site.eu
2026-09-06 17:48:45
(3 hours ago)
Excessive multi-domain requests
Brute-Force
🇺🇸
CDO
2026-09-06 17:45:56
(3 hours ago)
URL Injection attempt detected. Automated web attack.
Hacking
Bad Web Bot
Web App Attack
🇺🇸
mnsf
2026-09-06 17:05:26
(4 hours ago)
Too many Status 40X (15)
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 15:55:09
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.11.178.163 (163.178.11.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.11.178.163 (163.178.11.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 11:55:02.577740 2026] [security2:error] [pid 9871:tid 9871] [client 34.11.178.163:57968] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.styxtake2.grayhost.net"] [uri "/api/fs/read"] [unique_id "ap2M1pK6Sfxpd780xrL-9gAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇪
cmbplf
2026-09-06 15:38:01
(5 hours ago)
813 requests with url.path */@fs/*
321 requests with url.path */proc/*
276 requests with url.path ...
show more
813 requests with url.path */@fs/*
321 requests with url.path */proc/*
276 requests with url.path *.oci/*
240 requests with url.path *.ssh/*
191 requests with url.path *config.json
171 requests with url.path *.aws/*
show less
Brute-Force
Bad Web Bot
🇩🇪
pltcldvlpr
2026-09-06 15:18:31
(6 hours ago)
CMS/framework probe: 34.11.178.163 - - [06/Sep/2026:17:18:30 +0200] "GET /api/fs/read?path=/app/.env ...
show more
CMS/framework probe: 34.11.178.163 - - [06/Sep/2026:17:18:30 +0200] "GET /api/fs/read?path=/app/.env&allowOutsideWorkspace=true HTTP/2.0" 404 162 "-" "Mozilla/5.0 (compatible; Bravebot/1.0; +https://brave.com/search/)" asn=396982 org="Google LLC" country=US
...
show less
Web App Attack
🇨🇭
zynex
2026-09-06 14:32:49
(6 hours ago)
URL Probing: /@fs/var/task/.env
Web App Attack
🇫🇷
dynamix
2026-09-06 13:23:24
(7 hours ago)
Multiple WAF Violations
Web App Attack
Anonymous
2026-09-06 10:56:24
(10 hours ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
🇺🇸
dot.mg
2026-09-06 09:23:02
(11 hours ago)
Bad behaviour
Web Spam
🇮🇹
VHosting
2026-09-06 09:15:09
(12 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack