🇧🇪
cmbplf
2026-09-08 21:37:54
(18 hours ago)
318 requests with url.path *.azure/*
Brute-Force
Bad Web Bot
🇳🇿
Antinson
2026-09-08 20:32:27
(19 hours ago)
Scraping with a high error ratio and request rate
Bad Web Bot
🇬🇧
consul.to
2026-09-08 20:02:33
(19 hours ago)
Web attack/malicious scanning detected
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 19:39:54
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.124.219.216 (216.219.124.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.124.219.216 (216.219.124.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 15:39:49.511763 2026] [security2:error] [pid 321106:tid 321226] [client 34.124.219.216:58908] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.fostexlaw.com"] [uri "/@fs/src/.env"] [unique_id "aqBkhZAptHk_PfU7Km3aFQAAAlc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
IndigoRidge
2026-09-08 19:08:04
(20 hours ago)
34.124.219.216 - - [08/Sep/2026:15:08:03 -0400] "GET /@fs/.env?raw?? HTTP/1.1" 403 3299 "-" "Mozilla ...
show more
34.124.219.216 - - [08/Sep/2026:15:08:03 -0400] "GET /@fs/.env?raw?? HTTP/1.1" 403 3299 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_0 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko; compatible; Bytespider; +https://zhanzhang.toutiao.com/) Version/16.7 Mobile/15E148 Safari/604.1"
34.124.219.216 - - [08/Sep/2026:15:08:03 -0400] "GET /@fs/..%252f..%252f..%252f..%252f..%252fapp/.env?raw?? HTTP/1.1" 403 3299 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14_6_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.2214.166 Safari/537.36; compatible; ClaudeBot/1.0; [email protected] "
34.124.219.216 - - [08/Sep/2026:15:08:03 -0400] "GET /@fs/../.env?raw?? HTTP/1.1" 403 3299 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; TelegramBot/1.0)"
...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 18:56:15
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.124.219.216 (216.219.124.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.124.219.216 (216.219.124.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 14:56:11.139849 2026] [security2:error] [pid 19044:tid 19044] [client 34.124.219.216:16786] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.janajjmcgraw.com"] [uri "/@fs/app/.env"] [unique_id "aqBaS0LzBQoewY-eFhAu2QAAAJE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
svr
2026-09-08 18:45:36
(21 hours ago)
HC-Flood Web Scanner
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 17:57:32
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.124.219.216 (216.219.124.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.124.219.216 (216.219.124.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 13:57:27.687756 2026] [security2:error] [pid 15152:tid 15152] [client 34.124.219.216:26250] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.virginialakes395.com"] [uri "/@fs/.env"] [unique_id "aqBMh5kagEVDnl3E9VXVDgAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 16:22:01
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.124.219.216 (216.219.124.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.124.219.216 (216.219.124.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 12:21:56.745604 2026] [security2:error] [pid 10956:tid 10956] [client 34.124.219.216:19936] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.thrivebeyondtoxic.com"] [uri "/@fs/app/.env"] [unique_id "aqA2JO3b1zOWCrF5igB3BgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇸🇪
vaia.cloud
2026-09-08 15:45:01
(1 day ago)
crowdsecurity/http-probing
Brute-Force
Web App Attack
Anonymous
2026-09-08 15:30:39
(1 day ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
🇩🇪
paissangroup
2026-09-08 15:25:04
(1 day ago)
Multiple WAF Violations
Web App Attack
Anonymous
2026-09-08 15:19:49
(1 day ago)
Aggressive web scan
Web App Attack
🇫🇷
guillaume illien
2026-09-08 14:56:47
(1 day ago)
34.124.219.216 - - [08/Sep/2026:14:56:28 +0000] "GET / HTTP/1.1" 301 178 "-" "Mozilla/5.0 (X11; Ubun ...
show more
34.124.219.216 - - [08/Sep/2026:14:56:28 +0000] "GET / HTTP/1.1" 301 178 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:133.0) Gecko/20100101 Firefox/133.0"
34.124.219.216 - - [08/Sep/2026:14:56:31 +0000] "GET /@fs/../../.env?raw?? HTTP/1.1" 400 166 "-" "-"
34.124.219.216 - - [08/Sep/2026:14:56:46 +0000] "GET /@fs/../../../../../root/.env?raw?? HTTP/1.1" 400 166 "-" "-"
34.124.219.216 - - [08/Sep/2026:14:56:46 +0000] "GET /@fs/..%2f..%2f..%2f..%2f..%2froot/.env?raw?? HTTP/1.1" 400 166 "-" "-"
34.124.219.216 - - [08/Sep/2026:14:56:46 +0000] "GET /@fs/../../../../../proc/self/environ?raw?? HTTP/1.1" 400 166 "-" "-"
34.124.219.216 - - [08/Sep/2026:14:56:46 +0000] "GET /@fs/..%2f..%2f..%2f..%2f..%2fapp/.env?raw?? HTTP/1.1" 400 166 "-" "-"
34.124.219.216 - - [08/Sep/2026:14:56:46 +0000] "GET /@fs/../../../../../app/.env?raw?? HTTP/1.1" 400 166 "-" "-"
...
show less
Hacking
Brute-Force
Web App Attack
SSH
🇺🇸
TPI-Abuse
2026-09-08 14:48:38
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.124.219.216 (216.219.124.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.124.219.216 (216.219.124.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 10:48:33.037247 2026] [security2:error] [pid 23092:tid 23092] [client 34.124.219.216:36042] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "isyourcorporationsafe.com.alanmariotti.com"] [uri "/@fs/root/.env"] [unique_id "aqAgQb8qNOMf2xv7q5zHFgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack