🇺🇸
TPI-Abuse
2026-09-08 13:07:34
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.124.231.129 (129.231.124.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.124.231.129 (129.231.124.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 09:07:27.004953 2026] [security2:error] [pid 26308:tid 26308] [client 34.124.231.129:52174] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.poland-yacht-registration.com"] [uri "/@fs/src/.env"] [unique_id "aqAIj2AKiJdQDQ3eXfHG9gAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Site.eu
2026-09-08 12:43:30
(6 hours ago)
Excessive multi-domain requests
Brute-Force
🇩🇪
Hazzard
2026-09-08 12:40:59
(6 hours ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted]): (CF_ENABLE)
Bad Web Bot
Anonymous
2026-09-08 11:36:12
(7 hours ago)
Bot / seems abusive / Apache connections: 45
DDoS Attack
Web Spam
Bad Web Bot
Web App Attack
🇸🇪
vaia.cloud
2026-09-08 11:35:04
(7 hours ago)
crowdsecurity/http-path-traversal-probing
Brute-Force
Web App Attack
🇱🇻
garmtech.com
2026-09-08 11:32:36
(7 hours ago)
Attempted access to sensitive endpoint (/@fs/../.env?raw??) detected. Automated scan or unauthorized ...
show more
Attempted access to sensitive endpoint (/@fs/../.env?raw??) detected. Automated scan or unauthorized probing.
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 09:52:50
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.124.231.129 (129.231.124.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.124.231.129 (129.231.124.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 05:52:41.952490 2026] [security2:error] [pid 3339637:tid 3339637] [client 34.124.231.129:32036] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "al-bukhari.org"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252froot/.env"] [unique_id "ap_a6R_ZCVAW5i9EE89WvQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 09:00:51
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.124.231.129 (129.231.124.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.124.231.129 (129.231.124.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 05:00:47.820774 2026] [security2:error] [pid 4188:tid 4214] [client 34.124.231.129:21918] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.havacubvision.com"] [uri "/@fs/.env"] [unique_id "ap_Ov0NPDzJjZjCNRaddNQAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 08:09:56
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.124.231.129 (129.231.124.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.124.231.129 (129.231.124.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 04:09:53.313990 2026] [security2:error] [pid 4277:tid 4277] [client 34.124.231.129:15924] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.eventsetcinc.com"] [uri "/@fs/.env"] [unique_id "ap_C0ejyJ4DMfu9z6EU57AAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 07:26:51
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.124.231.129 (129.231.124.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.124.231.129 (129.231.124.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 03:26:45.087012 2026] [security2:error] [pid 2496:tid 2496] [client 34.124.231.129:8294] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.specialtywebsiteservice.com"] [uri "/@fs/app/.env"] [unique_id "ap-4tXOmSKpgc_unefHdMAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇸🇬
Cloudkul Cloudkul
2026-09-08 06:54:25
(12 hours ago)
Attempted Brute Force on our application
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 06:35:10
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.124.231.129 (129.231.124.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.124.231.129 (129.231.124.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 02:35:05.986395 2026] [security2:error] [pid 16677:tid 16677] [client 34.124.231.129:43366] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.edgecombe.net"] [uri "/@fs/root/.env"] [unique_id "ap-smcF-MofFCqfLQnw3TgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇪
AutosOnShow
2026-09-08 06:21:04
(12 hours ago)
blocked for webapp attack | path requested: /.git/config | seen at 2026-09-08 06:20:48.396 |
Web App Attack
🇺🇸
its101
2026-09-08 05:55:08
(13 hours ago)
Automated detection by LockdownAccess security system. Attack type(s): env_grab, path_traversal, rce ...
show more
Automated detection by LockdownAccess security system. Attack type(s): env_grab, path_traversal, rce, scanner, config_probe, wp_probe, git_exposure, framework_probe. Reason: Nginx: env_grab attack. Path targeted: unknown. Blocked in Cloudflare.
show less
Web App Attack
Exploited Host
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-08 05:35:21
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.124.231.129 (129.231.124.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.124.231.129 (129.231.124.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 01:35:15.392296 2026] [security2:error] [pid 13553:tid 13553] [client 34.124.231.129:28692] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "electricmeatgrinder.com"] [uri "/@fs/src/.env"] [unique_id "ap-ek5xPALqDnu-qcXuAfQAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack