๐ง๐ช
cmbplf
2026-09-03 23:08:55
(9 minutes ago)
9.510 requests from abuseipdb.com blacklisted IP (1yr9mos2w)
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-03 22:47:26
(31 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.124.233.227 (227.233.124.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.124.233.227 (227.233.124.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 18:47:21.804332 2026] [security2:error] [pid 1971982:tid 1972012] [client 34.124.233.227:50918] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.achillconsulting.com"] [uri "/@fs/src/.env"] [unique_id "apn4-dVa8eF39Ox__qzeFwAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
zynex
2026-09-03 22:35:20
(43 minutes ago)
URL Probing: /@fs/.env
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-03 22:19:51
(58 minutes ago)
Excessive multi-domain requests
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-03 22:01:23
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.124.233.227 (227.233.124.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.124.233.227 (227.233.124.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 18:01:16.974565 2026] [security2:error] [pid 20848:tid 20848] [client 34.124.233.227:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.ndanetworks.com"] [uri "/@fs/root/.env"] [unique_id "apnuLA4YVXMlVq_i5HIEowAAACs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-03 21:49:22
(1 hour ago)
Aggressive web scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-03 21:45:34
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.124.233.227 (227.233.124.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.124.233.227 (227.233.124.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 17:45:30.134218 2026] [security2:error] [pid 13607:tid 13636] [client 34.124.233.227:60350] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.emjayentertainmentdj.com"] [uri "/@fs/.env.local"] [unique_id "apnqejx6hvcouXkNcW4eNQAAAFQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-09-03 21:41:01
(1 hour ago)
Multiple WAF Violations
Web App Attack
๐ง๐พ
lns.bz
2026-09-03 21:21:52
(1 hour ago)
Too many 404 requests [BY]
Web App Attack
๐ฌ๐ง
consul.to
2026-09-03 20:16:08
(3 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-03 20:12:08
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.124.233.227 (227.233.124.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.124.233.227 (227.233.124.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 16:12:03.447920 2026] [security2:error] [pid 13360:tid 13360] [client 34.124.233.227:46312] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.peonypeople.com"] [uri "/@fs/app/.env"] [unique_id "apnUkwZ0Go86S_-e1_Y2pgAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Stara
2026-09-03 19:52:45
(3 hours ago)
ModSecurity detected web attack - .env/config probing or SQLi/Code injection (Rule 949110)
Brute-Force
SSH
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-03 19:45:57
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.124.233.227 (227.233.124.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.124.233.227 (227.233.124.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 15:45:50.523737 2026] [security2:error] [pid 5380:tid 5380] [client 34.124.233.227:61490] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.lesdwiniarczyk.com"] [uri "/@fs/.env.staging"] [unique_id "apnOboBR55Co_t5G4nDqcgAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-03 19:42:06
(3 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
Anonymous
2026-09-03 19:31:48
(3 hours ago)
2026/09/03 16:31:47 [error] 1369#1369: *44809 limiting requests, excess: 20.810 by zone "general", c ...
show more
2026/09/03 16:31:47 [error] 1369#1369: *44809 limiting requests, excess: 20.810 by zone "general", client: 34.124.233.227, server: guiasorocabano.com.br, request: "GET /@fs/home/admin/.aws/credentials?raw?? HTTP/1.1", host: "www.guiasorocabano.com.br", referrer: "https://guiasorocabano.com.br/@fs/home/admin/.aws/credentials?raw??"
2026/09/03 16:31:47 [error] 1367#1367: *44815 limiting requests, excess: 20.800 by zone "general", client: 34.124.233.227, server: guiasorocabano.com.br, request: "GET /@fs/home/node/.aws/credentials?raw?? HTTP/1.1", host: "www.guiasorocabano.com.br", referrer: "https://guiasorocabano.com.br/@fs/home/node/.aws/credentials?raw??"
2026/09/03 16:31:47 [error] 1372#1372: *44821 limiting requests, excess: 20.790 by zone "general", client: 34.124.233.227, server: guiasorocabano.com.br, request: "GET /@fs/home/www-data/.aws/credentials?raw?? HTTP/1.1", host: "www.guiasorocabano.com.br", referrer: "https://guiasorocabano.com.br/@fs/home/www-data/.aws/credentials?raw?
...
show less
Port Scan
Hacking
SQL Injection
Brute-Force
Bad Web Bot
Exploited Host