🇺🇸
TPI-Abuse
2026-09-04 07:31:56
(41 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.125.139.41 (41.139.125.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.125.139.41 (41.139.125.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 03:31:51.099066 2026] [security2:error] [pid 22236:tid 22236] [client 34.125.139.41:31292] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.cain2012.org"] [uri "/@fs/.env"] [unique_id "appz50rShUP_2rPOxfYRpwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
ConsulHosting
2026-09-04 07:03:25
(1 hour ago)
Automatically blocked due to distributed attack
Hacking
🇺🇸
TPI-Abuse
2026-09-04 06:15:28
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.125.139.41 (41.139.125.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.125.139.41 (41.139.125.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 02:15:24.540180 2026] [security2:error] [pid 18941:tid 18941] [client 34.125.139.41:53106] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.infrared-heaters.us"] [uri "/@fs/.env"] [unique_id "apph_ID_sEtQlYkYYYCnqAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 05:42:58
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.125.139.41 (41.139.125.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.125.139.41 (41.139.125.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 01:42:51.057585 2026] [security2:error] [pid 5957:tid 5957] [client 34.125.139.41:1834] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.barrykrueger.com"] [uri "/@fs/.env"] [unique_id "appaW_j57cdDIEyuN6JuaQAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
FD-IX
2026-09-04 05:39:59
(2 hours ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
🇺🇸
mnsf
2026-09-04 05:05:34
(3 hours ago)
Abuse Detected (1)
Brute-Force
Web App Attack
🇩🇪
sdos.es
2026-09-04 04:27:18
(3 hours ago)
"Restricted File Access Attempt - Matched Data: /.env found within REQUEST_FILENAME: /@fs/app/.env"
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 03:59:47
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.125.139.41 (41.139.125.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.125.139.41 (41.139.125.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 23:59:40.654629 2026] [security2:error] [pid 12069:tid 12069] [client 34.125.139.41:61628] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.saudivista.com"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252fapp/.env"] [unique_id "appCLJhV9tze2coPs-GG4AAAAEI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Guardian
2026-09-04 03:56:40
(4 hours ago)
Multi abuses [2]: Unauthorized connection attempt / Port scanning (x16), Unauthorized attempt to ret ...
show more
Multi abuses [2]: Unauthorized connection attempt / Port scanning (x16), Unauthorized attempt to retrieve configuration file (x11)
34.125.139.41 [04/Sep/2026:05:56:34 +0200] "GET / HTTP/1.1"
34.125.139.41 [04/Sep/2026:05:56:34 +0200] "GET / HTTP/1.1"
34.125.139.41 [04/Sep/2026:05:56:39 +0200] "GET /@fs/root/.env?raw?? HTTP/1.1"
34.125.139.41 [04/Sep/2026:05:56:39 +0200] "GET /@fs/src/.env?raw?? HTTP/1.1"
34.125.139.41 [04/Sep/2026:05:56:40 +0200] "GET /@fs/root/rootkey.csv?raw?? HTTP/1.1"
34.125.139.41 [04/Sep/2026:05:56:40 +0200] "GET /@fs/..%252f..%252f..%252f..%252f..%252fapp/.env?raw?? HTTP/1.1"
34.125.139.41 [04/Sep/2026:05:56:40 +0200] "GET / HTTP/1.1"
34.125.139.41 [04/Sep/2026:05:56:40 +0200] "GET /@fs/.env?raw?? HTTP/1.1"
34.125.139.41 [04/Sep/2026:05:56:40 +0200] "GET /@fs/app/rootkey.csv?raw?? HTTP/1.1"
34.125.139.41 [04/Sep/2026:05:56:40 +0200] "GET /@fs/..%252f..%252f..%252f..%252f..%252froot/.env?raw?? HTTP/1.1"
34.125.139.41 [04/Sep/2026:05:56:40 +0200] "GET /@fs/app/.env?raw?? HTTP/1.1"
34.12
show less
Port Scan
Web App Attack
🇳🇱
Site.eu
2026-09-04 03:43:48
(4 hours ago)
Excessive multi-domain requests
Brute-Force
🇩🇪
grassau.com
2026-09-04 03:42:33
(4 hours ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 34.125.139.41 (US/Un ...
show more
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 34.125.139.41 (US/United States/Nevada/Las Vegas/41.139.125.34.bc.googleusercontent.com)
show less
Bad Web Bot
🇪🇸
elcruzado.es
2026-09-04 03:34:55
(4 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 34.125.139.41 (US/United States/41.139. ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.125.139.41 (US/United States/41.139.125.34.bc.googleusercontent.com)
show less
SQL Injection
🇫🇮
Shaik Sai Meera
2026-09-04 03:30:15
(4 hours ago)
IM360 WAF: Hidden file access
Brute-Force
🇬🇧
Apache
2026-09-04 03:21:08
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.125.139.41 (US/United States/41.139.125.34.b ...
show more
(mod_security) mod_security (id:210492) triggered by 34.125.139.41 (US/United States/41.139.125.34.bc.googleusercontent.com): 5 in the last 300 secs (CF_ENABLE)
show less
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 03:13:42
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.125.139.41 (41.139.125.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.125.139.41 (41.139.125.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 23:13:36.545488 2026] [security2:error] [pid 8844:tid 8844] [client 34.125.139.41:60538] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.maverickhousellc.com"] [uri "/@fs/.env"] [unique_id "apo3YBpONko0-EvgRbXYEQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack