🇳🇱
debestelapp
2026-09-04 16:40:11
(17 hours ago)
Web App Attack
🇩🇪
4server
2026-09-04 15:54:47
(18 hours ago)
[FriSep0417:54:43.1404332026][security2:error][pid363137:tid363148][client34.124.144.156:0]ModSecuri ...
show more
[FriSep0417:54:43.1404332026][security2:error][pid363137:tid363148][client34.124.144.156:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"\(\?:\\\\\\\\b\(\?:\\\\\\\\.\(\?:ht\(\?:access\|passwd\|group\)\|www_\?acl\)\|global\\\\\\\\.asa\|httpd\\\\\\\\.conf\|boot\\\\\\\\.ini\|web.config\)\\\\\\\\b\|\(\|\^\|\\\\\\\\.\\\\\\\\.\)/etc/\|/\\\\\\\\.\(\?:history\|bash_history\|sh_history\|env\)\$\)\"atREQUEST_FILENAME.[file\"/etc/apache2/conf.d/modsec_rules/10_asl_rules.conf\"][line\"204\"][id\"390709\"][rev\"30\"][msg\"Atomicorp.comWAFRules:Attempttoaccessprotectedfileremotely\"][data\"/.env\"][severity\"CRITICAL\"][hostname\"mail.ppinvestment.ch\"][uri\"/@fs/../../../../../root/.env\"][unique_id\"aprpw1bghuNLFWcXN7_5twAAAAA\"]
show less
Port Scan
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 15:07:33
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.124.144.156 (156.144.124.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.124.144.156 (156.144.124.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 11:07:28.210623 2026] [security2:error] [pid 23003:tid 23055] [client 34.124.144.156:18162] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.briteh.com"] [uri "/@fs/.env"] [unique_id "apresCex7aGucYgIv8ZKmwAAAE4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇪🇸
librebit
2026-09-04 14:40:00
(19 hours ago)
Bad guys doing bad things, bad crawling
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-04 13:56:20
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.124.144.156 (156.144.124.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.124.144.156 (156.144.124.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 09:56:14.284038 2026] [security2:error] [pid 3074851:tid 3074926] [client 34.124.144.156:7440] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.backcountrygardens.com"] [uri "/@fs/../../.env"] [unique_id "aprN_kDpNL1xUW6C5o1VSQAAAIs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 12:52:44
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.124.144.156 (156.144.124.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.124.144.156 (156.144.124.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 08:52:37.360928 2026] [security2:error] [pid 29066:tid 29066] [client 34.124.144.156:28332] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "myemail.navy"] [uri "/@fs/../../.env"] [unique_id "apq_FbolRLjhixvjKcFy2wAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 11:39:56
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.124.144.156 (156.144.124.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.124.144.156 (156.144.124.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 07:39:50.479524 2026] [security2:error] [pid 30608:tid 30634] [client 34.124.144.156:62994] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "baggymaggy.docdalton.com"] [uri "/@fs/app/.env"] [unique_id "apquBpcqTOpxVutVsfvT-AAAAYs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
masterguru
2026-09-04 11:05:33
(22 hours ago)
BAD BOT - Detected and Blocked.. Matched phrase "GPTBot" at REQUEST_HEADERS:User-Agent. (1100000-135 ...
show more
BAD BOT - Detected and Blocked.. Matched phrase "GPTBot" at REQUEST_HEADERS:User-Agent. (1100000-135)
show less
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-04 10:55:16
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.124.144.156 (156.144.124.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.124.144.156 (156.144.124.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:55:05.636954 2026] [security2:error] [pid 19635:tid 19635] [client 34.124.144.156:10506] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.englishmagic.us"] [uri "/@fs/root/.env"] [unique_id "apqjiQE4X_jLlzEFNUxAdAAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 08:01:58
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.124.144.156 (156.144.124.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.124.144.156 (156.144.124.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 04:01:54.004300 2026] [security2:error] [pid 7406:tid 7406] [client 34.124.144.156:64720] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sykesclan.com"] [uri "/@fs/app/.env"] [unique_id "app68ku-wBYXboysQKcF8QAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 07:40:24
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.124.144.156 (156.144.124.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.124.144.156 (156.144.124.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 03:40:19.523402 2026] [security2:error] [pid 15660:tid 15660] [client 34.124.144.156:6336] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "graphicsbyrc.zavijava.net"] [uri "/@fs/app/.env"] [unique_id "app144hrR-nCnSJrgNlcxwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
masterguru
2026-09-04 07:34:10
(1 day ago)
BAD BOT - Detected and Blocked.. Matched phrase "bytespider" at REQUEST_HEADERS:User-Agent. (1100000 ...
show more
BAD BOT - Detected and Blocked.. Matched phrase "bytespider" at REQUEST_HEADERS:User-Agent. (1100000-201)
show less
Bad Web Bot
🇺🇸
WizardsToolkit
2026-09-04 06:49:10
(1 day ago)
attempted to access /@fs/..%252f..%252f..%252f..%252f..%252fapp/.env?raw??
Web App Attack
Anonymous
2026-09-04 06:35:17
(1 day ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
🇮🇹
CoreTech srl
2026-09-04 06:18:57
(1 day ago)
cloudlinux2 fail2ban: 2026-09-04 08:14:41,253 fail2ban.actions [1594]: NOTICE [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-09-04 08:14:41,253 fail2ban.actions [1594]: NOTICE [plesk-modsecurity] Unban 34.89.248.139cloudlinux2 fail2ban: 2026-09-04 08:15:24,515 fail2ban.actions [1594]: NOTICE [plesk-modsecurity] Unban 34.159.230.148cloudlinux2 fail2ban: 2026-09-04 08:15:50,763 fail2ban.filter [1594]: INFO [recidive] Found 34.124.144.156 - 2026-09-04 08:15:50cloudlinux2 fail2ban: 2026-09-04 08:15:50,636 fail2ban.filter [1594]: INFO [plesk-modsecurity] Found 34.124.144.156 - 2026-09-04 08:15:50cloudlinux2 fail2ban: 2026-09-04 08:15:50,626 fail2ban.filter [1594]: INFO [plesk-modsecurity] Found 34.124.144.156 - 2026-09-04 08:15:50cloudlinux2 fail2ban: 2026-09-04 08:15:50,659 fail2ban.filter [1594]: INFO [plesk-modsecurity] Found 34.124.144.156 - 2026-09-04 08:15:50cloudlinux2 fail2ban: 2026-09-04 08:15:50,678 fail2ban.filter [1594]: INFO [plesk-modsecurity] Found 34.124.144.156 - 2026-09-04 08:15:50cloudlinux2 fail2ban: 2026-09-04 08:15:50,
show less
Brute-Force