🇺🇸
TPI-Abuse
2026-09-09 11:16:33
(36 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.11.243.250 (250.243.11.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.11.243.250 (250.243.11.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 07:16:26.539349 2026] [security2:error] [pid 11418:tid 11418] [client 34.11.243.250:10342] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.computersraleigh.com"] [uri "/@fs/src/.env"] [unique_id "aqFAChn9loyQH72GtE_sMwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 10:24:39
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.11.243.250 (250.243.11.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.11.243.250 (250.243.11.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 06:24:36.094203 2026] [security2:error] [pid 26726:tid 26726] [client 34.11.243.250:23582] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bcerg.org"] [uri "/@fs/src/.env"] [unique_id "aqEz5KlH56pfJx_3ao_8CgAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
updown.io
2026-09-09 10:17:59
(1 hour ago)
{"level":"info","ts":1788949029.164957,"logger":"http.log.access.log1","msg":"handled request","requ ...
show more
{"level":"info","ts":1788949029.164957,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"34.11.243.250","remote_port":"29578","client_ip":"34.11.243.250","proto":"HTTP/1.1","method":"GET","host":"wcocstatus.pro-epic.info","uri":"/","headers":{"User-Agent":["Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36 Edg/126.0.0.0"],"Accept":["*/*"],"Accept-Encoding":["gzip"]}},"bytes_read":0,"user_id":"","duration":0.000071797,"size":0,"status":308,"resp_headers":{"Connection":["close"],"Location":["https://wcocstatus.pro-epic.info/"],"Content-Type":[],"Server":["Caddy"]}}
{"level":"info","ts":1788949032.5267596,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"34.11.243.250","remote_port":"31358","client_ip":"34.11.243.250","proto":"HTTP/1.1","method":"GET","host":"wcocstatus.pro-epic.info","uri":"/@fs/..%252f..%252f..%252f..%252f..%252froot/.env?raw??","headers":{"Accept":[
...
show less
DDoS Attack
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 09:56:41
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.11.243.250 (250.243.11.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.11.243.250 (250.243.11.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 05:56:36.013903 2026] [security2:error] [pid 16653:tid 16697] [client 34.11.243.250:51514] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "booking.heworeblack.com"] [uri "/@fs/root/.env"] [unique_id "aqEtVG206c_MfMEAHdLhmAAAAMI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-09-09 09:01:32
(2 hours ago)
Web attack/malicious scanning detected
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 07:51:47
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.11.243.250 (250.243.11.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.11.243.250 (250.243.11.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 03:51:40.906468 2026] [security2:error] [pid 32160:tid 32177] [client 34.11.243.250:61896] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.therosicrucianorder.com.aafm.us"] [uri "/@fs/root/.env"] [unique_id "aqEQDLsju2l5je7Mr8ESwAAAAE4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Site.eu
2026-09-09 06:52:00
(5 hours ago)
Excessive multi-domain requests
Brute-Force
Anonymous
2026-09-09 06:41:12
(5 hours ago)
Bot / seems abusive / Apache connections: 47
DDoS Attack
Web Spam
Bad Web Bot
Web App Attack
🇩🇪
netclix.gr
2026-09-09 06:31:49
(5 hours ago)
(security_scan) Sensitive File Scan Blocked 34.11.243.250 (US/United States/250.243.11.34.bc.googleu ...
show more
(security_scan) Sensitive File Scan Blocked 34.11.243.250 (US/United States/250.243.11.34.bc.googleusercontent.com): 1 in the last 4600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 34.11.243.250 - - [09/Sep/2026:09:29:23 +0300] "GET /@fs/../../.env?raw?? HTTP/1.1" 400 150 "-" "-"
show less
Port Scan
🇺🇸
TPI-Abuse
2026-09-09 05:48:04
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.11.243.250 (250.243.11.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.11.243.250 (250.243.11.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 01:48:00.593234 2026] [security2:error] [pid 536299:tid 536413] [client 34.11.243.250:29310] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.lynchburg.windowtailors.com"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252fapp/.env"] [unique_id "aqDzELdqgKcUbA4wGrJeZwAAAVA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 05:16:20
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.11.243.250 (250.243.11.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.11.243.250 (250.243.11.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 01:16:16.337211 2026] [security2:error] [pid 12817:tid 12817] [client 34.11.243.250:37566] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.noshsf.com"] [uri "/@fs/root/.env"] [unique_id "aqDroCcRqMbxQZHX8EAJRwAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇪
voormedia
2026-09-09 05:03:53
(6 hours ago)
Accessed trap at '/.env'
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 04:46:56
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.11.243.250 (250.243.11.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.11.243.250 (250.243.11.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 00:46:51.342594 2026] [security2:error] [pid 6685:tid 6685] [client 34.11.243.250:39526] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.amybeam.com"] [uri "/@fs/.env"] [unique_id "aqDkuzMJYTCvagrBDu4VyAAAADE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇵🇱
mscode.pl
2026-09-09 04:45:16
(7 hours ago)
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Pro ...
show more
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Protocol: HTTP/1.1 (GET method)
Zone: www.as201132.net
Endpoint: /serviceAccount.json
UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 14_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/130.0.4291.157 Safari/537.36 Edg/130.0.4291.157; compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexity-user
show less
Bad Web Bot
🇫🇷
masterguru
2026-09-09 04:31:48
(7 hours ago)
Restricted File Access Attempt. Matched phrase "/@fs/" at REQUEST_FILENAME. (930130-193)
Hacking
Web App Attack