🇧🇪
cmbplf
2026-09-08 22:43:12
(15 hours ago)
102 requests with url.path *.azure/*
Brute-Force
Bad Web Bot
🇺🇸
WellSpring
2026-09-08 19:41:26
(18 hours ago)
good bot honeypot on 212.today/@fs/.env — WellSpr.ing/NetSentinel civic-AI security layer
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-08 19:23:42
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.124.195.210 (210.195.124.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.124.195.210 (210.195.124.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 15:23:38.951426 2026] [security2:error] [pid 1246:tid 1275] [client 34.124.195.210:61824] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "peapage.com"] [uri "/@fs/../.env"] [unique_id "aqBgugxm6dtPr82acgojsAAAAFc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇭
zynex
2026-09-08 19:19:08
(19 hours ago)
URL Probing: /@fs/var/www/html/.env
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 18:39:20
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.124.195.210 (210.195.124.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.124.195.210 (210.195.124.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 14:39:14.556193 2026] [security2:error] [pid 11001:tid 11001] [client 34.124.195.210:4416] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.roigcorporativo.com"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252froot/.env"] [unique_id "aqBWUjPoEJqt05sfcG1LrQAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 18:03:54
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.124.195.210 (210.195.124.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.124.195.210 (210.195.124.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 14:03:49.997771 2026] [security2:error] [pid 5832:tid 5832] [client 34.124.195.210:14456] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "scpublicity.com"] [uri "/@fs/.env"] [unique_id "aqBOBZjZATF9obzUU4PAVQAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇦🇺
screwlooseit.com.au
2026-09-08 17:49:19
(20 hours ago)
Blocked by CSF 13 firewall - Rule: US/United States/210.195.124.34.bc.googleusercontent.com
Web App Attack
🇸🇪
vaia.cloud
2026-09-08 17:40:01
(20 hours ago)
crowdsecurity/http-probing
Brute-Force
Web App Attack
🇫🇷
dynamix
2026-09-08 17:10:26
(21 hours ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 16:58:33
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.124.195.210 (210.195.124.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.124.195.210 (210.195.124.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 12:58:26.736045 2026] [security2:error] [pid 20837:tid 20837] [client 34.124.195.210:49254] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.wendeeholtcamp.com"] [uri "/@fs/root/.env"] [unique_id "aqA-sl28KEI4r0V8tf90EgAAAD8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
JaRoNL
2026-09-08 16:34:27
(21 hours ago)
50s.nl:443 34.124.195.210 - - [08/Sep/2026:18:34:26 +0200] "GET /@fs/.env.production?raw?? HTTP/1.1" ...
show more
50s.nl:443 34.124.195.210 - - [08/Sep/2026:18:34:26 +0200] "GET /@fs/.env.production?raw?? HTTP/1.1" 404 2684 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; OAI-SearchBot/1.3; +https://openai.com/searchbot)"
...
show less
Bad Web Bot
Web App Attack
🇳🇱
Site.eu
2026-09-08 16:10:36
(22 hours ago)
Excessive 404/403 errors
Brute-Force
🇺🇸
TPI-Abuse
2026-09-08 15:56:00
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.124.195.210 (210.195.124.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.124.195.210 (210.195.124.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 11:55:53.038062 2026] [security2:error] [pid 28398:tid 28398] [client 34.124.195.210:24194] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.k9team.org"] [uri "/@fs/.env.production"] [unique_id "aqAwCdkykl16moDwM9OC1QAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
FeG Deutschland
2026-09-08 15:45:25
(22 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 12
Exploited Host
Web App Attack
Anonymous
2026-09-08 15:28:07
(23 hours ago)
Multiple web server 400 error codes from same source ip
Web App Attack