🇺🇸
TPI-Abuse
2026-09-08 12:11:43
(5 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.125.144.128 (128.144.125.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.125.144.128 (128.144.125.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 08:11:36.291452 2026] [security2:error] [pid 12524:tid 12524] [client 34.125.144.128:56596] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.efgenios.com"] [uri "/@fs/.env"] [unique_id "ap_7eC3az5e26tl2SiAV4wAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇮
YF
2026-09-08 10:30:28
(1 hour ago)
Distributed subnet attack — coordinated scanning from multiple IPs in the same /24
DDoS Attack
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 10:12:19
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.125.144.128 (128.144.125.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.125.144.128 (128.144.125.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 06:12:14.690524 2026] [security2:error] [pid 13827:tid 13827] [client 34.125.144.128:26418] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.tmcbizdev.com"] [uri "/@fs/.env"] [unique_id "ap_ffh69zXOx4omtZW4rkgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 09:42:04
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.125.144.128 (128.144.125.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.125.144.128 (128.144.125.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 05:41:58.525431 2026] [security2:error] [pid 8437:tid 8437] [client 34.125.144.128:54800] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.accredo.net"] [uri "/@fs/root/.env"] [unique_id "ap_YZud74kyyYa00vIfbXgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-08 09:08:25
(3 hours ago)
XSS Attempt
Hacking
🇺🇸
dot.mg
2026-09-08 09:07:02
(3 hours ago)
Bad behaviour
Web Spam
🇩🇪
ghostwarriors
2026-09-08 08:50:42
(3 hours ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 08:43:19
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.125.144.128 (128.144.125.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.125.144.128 (128.144.125.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 04:43:14.341111 2026] [security2:error] [pid 3283:tid 3283] [client 34.125.144.128:2092] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dreamingofatlantis.com"] [uri "/@fs/.env"] [unique_id "ap_KovHUS_kPeYI2fhrDzQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-08 08:19:31
(3 hours ago)
GET /@fs/.env?raw?? HTTP/1.1
...
Web App Attack
🇩🇪
DEV-DNS
2026-09-08 08:07:13
(4 hours ago)
(mod_security) mod_security triggered on hostname [redacted])
SQL Injection
🇺🇸
TPI-Abuse
2026-09-08 07:57:04
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.125.144.128 (128.144.125.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.125.144.128 (128.144.125.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 03:56:57.263838 2026] [security2:error] [pid 3188094:tid 3188094] [client 34.125.144.128:46780] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "legionellaexperts.org"] [uri "/@fs/src/.env"] [unique_id "ap-_ySdicmkmxZ02Ei12owAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
ruusvuu
2026-09-08 07:45:56
(4 hours ago)
Automated abuse report: 25 attack/probe requests from Google LLC / US.
Targeted paths: /@fs/proc/sel ...
show more
Automated abuse report: 25 attack/probe requests from Google LLC / US.
Targeted paths: /@fs/proc/self/environ, /@fs/etc/passwd, /@fs/..%252f..%252f..%252f..%252f..%252fproc/self/environ, /@fs/var/run/secrets/kubernetes.io/serviceaccount/token, /@fs/proc/self/cmdline.
Sample log lines:
[mirassertions] 2026-09-08 00:45:56: 9/8/2026 00:45:56 34.125.144.128 GET /@fs/app/credentials.json?raw?? 404 - 12.625 ms -
[mirassertions] 2026-09-08 00:45:56: 9/8/2026 00:45:56 34.125.144.128 GET /@fs/home/ubuntu/.oci/config?raw?? 404 - 13.885 ms -
[mirassertions] 2026-09-08 00:45:56: 9/8/2026 00:45:56 34.125.144.128 GET /@fs/app/gcp-credentials.json?raw?? 404 - 15.133 ms -
Detected by an automated web-server log monitor.
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 07:38:48
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.125.144.128 (128.144.125.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.125.144.128 (128.144.125.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 03:38:43.318223 2026] [security2:error] [pid 12145:tid 12145] [client 34.125.144.128:27844] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.corangues.com"] [uri "/@fs/.env"] [unique_id "ap-7g7cFGLWDLs-7YHEujAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-08 07:30:13
(4 hours ago)
Bot / seems abusive / Apache connections: 49
DDoS Attack
Web Spam
Bad Web Bot
Web App Attack
🇩🇪
FD-IX
2026-09-08 07:20:02
(4 hours ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack