🇳🇱
e.fierstra
2026-09-07 10:28:16
(2 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇫🇷
masterguru
2026-09-07 10:18:29
(2 hours ago)
Restricted File Access Attempt. Matched phrase "/@fs/" at REQUEST_FILENAME. (930130-197)
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 10:07:40
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.123.139.218 (218.139.123.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.123.139.218 (218.139.123.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 06:07:32.760050 2026] [security2:error] [pid 29945:tid 29945] [client 34.123.139.218:65192] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.healthyforyoullc.com"] [uri "/@fs/root/.env"] [unique_id "ap6M5NB0YW7Ced0sqY7xMAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 09:20:21
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.123.139.218 (218.139.123.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.123.139.218 (218.139.123.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 05:20:15.909436 2026] [security2:error] [pid 31443:tid 31443] [client 34.123.139.218:59118] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.dave-curtis.com"] [uri "/@fs/../../.env"] [unique_id "ap6Bz-aiySwAjttbZA7CaAAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇲🇾
Rizzy
2026-09-07 09:19:26
(3 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack
🇦🇺
2000cn.com.au
2026-09-07 09:13:12
(3 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-path-traversal-probing
Web App Attack
Hacking
🇳🇱
MyGlobalFlowers
2026-09-07 08:17:58
(4 hours ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 08:13:37
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.123.139.218 (218.139.123.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.123.139.218 (218.139.123.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 04:13:32.762765 2026] [security2:error] [pid 3213:tid 3213] [client 34.123.139.218:55222] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.lawrencehale.net"] [uri "/@fs/../.env"] [unique_id "ap5yLOnINdzALTOP3co5qwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
masterguru
2026-09-07 08:08:32
(4 hours ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.123.139.218 (US/United States/218. ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.123.139.218 (US/United States/218.139.123.34.bc.googleusercontent.com): 2 in the last 3600 secs (0-196)
show less
Hacking
🇦🇺
screwlooseit.com.au
2026-09-07 08:06:33
(4 hours ago)
Blocked by CSF 13 firewall - Rule: US/United States/218.139.123.34.bc.googleusercontent.com
Web App Attack
🇧🇪
cmbplf
2026-09-07 07:34:05
(5 hours ago)
386 requests with url.path *config.json
341 requests with url.path *.azure/*
254 requests with ur ...
show more
386 requests with url.path *config.json
341 requests with url.path *.azure/*
254 requests with url.path *.ssh/*
show less
Brute-Force
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-07 07:07:25
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.123.139.218 (218.139.123.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.123.139.218 (218.139.123.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 03:07:22.663130 2026] [security2:error] [pid 1699:tid 1699] [client 34.123.139.218:4512] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.advantagept.org"] [uri "/@fs/.env.development"] [unique_id "ap5iqkZs7OvQO5hg7YhCjQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇦
polycoda
2026-09-07 06:39:09
(5 hours ago)
AutoBlock: 🎯 Vulnerability Scanner (Non Decay-Based) - ↪️ Excessive 30X Errors (Decay-Based)
Hacking
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 06:35:19
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.123.139.218 (218.139.123.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.123.139.218 (218.139.123.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 02:35:14.501206 2026] [security2:error] [pid 28306:tid 28306] [client 34.123.139.218:30646] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.cincinnati.deubellzebub.com"] [uri "/@fs/.env.production"] [unique_id "ap5bIoryGXGtrVRCmH4zVgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 05:58:02
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.123.139.218 (218.139.123.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.123.139.218 (218.139.123.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 01:57:58.323327 2026] [security2:error] [pid 31658:tid 31658] [client 34.123.139.218:8516] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "crazycoin.net"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252froot/.env"] [unique_id "ap5SZsVFJUDPfBg0ScbWbgAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack