🇺🇸
TPI-Abuse
2026-08-29 13:05:14
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.125.122.217 (217.122.125.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.125.122.217 (217.122.125.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 09:05:06.818328 2026] [security2:error] [pid 11730:tid 11730] [client 34.125.122.217:18084] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.khtcpl.com"] [uri "/@fs/.env"] [unique_id "apLZAlO7PCbgo9y08_-BSwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-29 12:34:04
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.125.122.217 (217.122.125.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.125.122.217 (217.122.125.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 08:34:00.410212 2026] [security2:error] [pid 32580:tid 32580] [client 34.125.122.217:51338] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.centralbaptistalcoa.org"] [uri "/@fs/root/.env"] [unique_id "apLRuP44_BtCTCl6R6Nt7QAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Skyrider
2026-08-29 12:20:16
(3 hours ago)
crowdsecurity/http-path-traversal-probing
Web App Attack
🇺🇸
TPI-Abuse
2026-08-29 12:05:41
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.125.122.217 (217.122.125.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.125.122.217 (217.122.125.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 08:05:35.281665 2026] [security2:error] [pid 1477:tid 1477] [client 34.125.122.217:33070] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bencramer.bencramerinc.com"] [uri "/@fs/root/.env"] [unique_id "apLLDzZhxwNVGsopJTw_2wAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-29 11:37:22
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.125.122.217 (217.122.125.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.125.122.217 (217.122.125.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 07:37:14.707125 2026] [security2:error] [pid 2966:tid 2966] [client 34.125.122.217:28114] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.iacarbonell.com"] [uri "/@fs/src/.env"] [unique_id "apLEakctLHXwG51eWpWefgAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇸🇪
vaia.cloud
2026-08-29 11:35:02
(3 hours ago)
crowdsecurity/http-path-traversal-probing
Brute-Force
Web App Attack
🇷🇴
clauss
2026-08-29 11:20:01
(4 hours ago)
34.125.122.217 - - [29/Aug/2026:14:20:00 +0300] "GET /@fs/.env?raw?? HTTP/1.1" 403 146 "-" "Mozilla/ ...
show more
34.125.122.217 - - [29/Aug/2026:14:20:00 +0300] "GET /@fs/.env?raw?? HTTP/1.1" 403 146 "-" "Mozilla/5.0 (compatible; ClaudeBot/1.0; [email protected] )"
34.125.122.217 - - [29/Aug/2026:14:20:00 +0300] "GET /@fs/root/.env?raw?? HTTP/1.1" 403 177 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4375.176 Safari/537.36; compatible; LinkedInBot/1.0; +http://www.linkedin.com"
...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-08-29 10:39:59
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.125.122.217 (217.122.125.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.125.122.217 (217.122.125.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 06:39:55.883409 2026] [security2:error] [pid 32170:tid 32277] [client 34.125.122.217:15938] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mensaxes.net"] [uri "/@fs/root/.env"] [unique_id "apK2-1PVz-q4Ro-1c6BauQAAAJI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
debestelapp
2026-08-29 08:45:08
(6 hours ago)
Web App Attack
🇺🇸
TPI-Abuse
2026-08-29 08:22:36
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.125.122.217 (217.122.125.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.125.122.217 (217.122.125.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 04:22:32.068994 2026] [security2:error] [pid 12659:tid 12659] [client 34.125.122.217:64478] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.conversationtalentnetwork.com"] [uri "/@fs/.env"] [unique_id "apKWyK6III3vPC55Z6zFogAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
e.fierstra
2026-08-29 07:45:04
(7 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇬🇧
Aetherweb Ark
2026-08-29 07:16:42
(8 hours ago)
(mod_security) mod_security (id:949110) triggered by 34.125.122.217 (US/United States/217.122.125.34 ...
show more
(mod_security) mod_security (id:949110) triggered by 34.125.122.217 (US/United States/217.122.125.34.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
🇦🇺
A.i.D.A.N.N
2026-08-29 06:42:16
(8 hours ago)
A.i.D.A.N.N: Anomaly Detected - Signature match Web Service - Web application attack detected
Web App Attack
🇺🇸
agenciahypelab.com.br
2026-08-29 06:28:15
(8 hours ago)
WordPress login brute-force detectado e bloqueado pelo CSF/LFD. Trigger: LF_TRIGGER
Brute-Force
SSH
🇨🇭
zynex
2026-08-29 06:02:54
(9 hours ago)
URL Probing: /@fs/.env
Web App Attack