🇳🇱
middelkoopcc
2026-09-08 09:11:01
(43 minutes ago)
2026-09-08 11:09:19 GET /@fs/root/.env?raw?? [404] && 2026-09-08 11:09:19 GET /@fs/.env?raw?? [404] ...
show more
2026-09-08 11:09:19 GET /@fs/root/.env?raw?? [404] && 2026-09-08 11:09:19 GET /@fs/.env?raw?? [404] && 2026-09-08 11:09:19 GET /@fs/app/.env?raw?? [404] && 178 more within 20 minutes
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 08:55:25
(59 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.125.187.171 (171.187.125.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.125.187.171 (171.187.125.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 04:55:20.152502 2026] [security2:error] [pid 27097:tid 27097] [client 34.125.187.171:28206] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.garbothemusical.net"] [uri "/@fs/src/.env"] [unique_id "ap_NeKti8gjtMM2vFDEGewAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇹🇷
muratkaya665
2026-09-08 08:52:29
(1 hour ago)
IPS Attack Blocked by server.mura******.com.tr Fortigate-80E. Attack Name: Vite.server.fs.deny.raw.A ...
show more
IPS Attack Blocked by server.mura******.com.tr Fortigate-80E. Attack Name: Vite.server.fs.deny.raw.Arbitrary.File.Read. Dest Port: 80. Service: HTTP. Message: applications3: Vite.server.fs.deny.raw.Arbitrary.File.Read.
show less
Hacking
🇺🇸
TPI-Abuse
2026-09-08 08:14:00
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.125.187.171 (171.187.125.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.125.187.171 (171.187.125.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 04:13:55.355028 2026] [security2:error] [pid 10350:tid 10350] [client 34.125.187.171:8652] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "karohali.chevronparkett.com"] [uri "/@fs/app/.env"] [unique_id "ap_DwxE2770CDDaXKmccpQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 07:24:26
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.125.187.171 (171.187.125.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.125.187.171 (171.187.125.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 03:24:21.128004 2026] [security2:error] [pid 31826:tid 31826] [client 34.125.187.171:34022] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ferienwohnungen-eva.com"] [uri "/@fs/.env"] [unique_id "ap-4JXLKXm3zaMUx8zwKdQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 07:06:00
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.125.187.171 (171.187.125.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.125.187.171 (171.187.125.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 03:05:51.833216 2026] [security2:error] [pid 23174:tid 23174] [client 34.125.187.171:51490] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.fsbmens.com"] [uri "/@fs/../.env"] [unique_id "ap-zz9POS1kGNAP4j84GeQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇵🇹
rncbc
2026-09-08 06:57:33
(2 hours ago)
[Tue Sep 08 07:57:28.961758 2026] [authz_core:error] [pid 1096442:tid 1096442] [client 34.125.187.17 ...
show more
[Tue Sep 08 07:57:28.961758 2026] [authz_core:error] [pid 1096442:tid 1096442] [client 34.125.187.171:28306] AH01630: client denied by server configuration: /srv/www/vhosts/rncbc/
[Tue Sep 08 07:57:32.991555 2026] [authz_core:error] [pid 1096415:tid 1096415] [client 34.125.187.171:2872] AH01630: client denied by server configuration: /srv/www/vhosts/rncbc/
[Tue Sep 08 07:57:33.002172 2026] [authz_core:error] [pid 1096320:tid 1096320] [client 34.125.187.171:2888] AH01630: client denied by server configuration: /srv/www/vhosts/rncbc/@fs
...
show less
Brute-Force
Bad Web Bot
Web App Attack
SSH
🇬🇧
consul.to
2026-09-08 06:35:55
(3 hours ago)
Web attack/malicious scanning detected
Web App Attack
🇸🇪
vaia.cloud
2026-09-08 06:00:09
(3 hours ago)
crowdsecurity/http-probing
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 05:50:44
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.125.187.171 (171.187.125.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.125.187.171 (171.187.125.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 01:50:37.203283 2026] [security2:error] [pid 25123:tid 25123] [client 34.125.187.171:1586] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.mandel.vc"] [uri "/@fs/root/.env"] [unique_id "ap-iLYkGzrSeSoh9LvAm6QAAAC4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 05:14:22
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.125.187.171 (171.187.125.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.125.187.171 (171.187.125.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 01:14:15.404236 2026] [security2:error] [pid 20523:tid 20549] [client 34.125.187.171:54404] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.livetalkusa.com"] [uri "/@fs/app/.env"] [unique_id "ap-Zpxh6zayB-zbAX2oBdgAAAVg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
e.fierstra
2026-09-08 05:02:46
(4 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇩🇪
Holger
2026-09-08 04:12:09
(5 hours ago)
Bruteforce WebAttack
Brute-Force
Web App Attack
🇳🇱
SchorelWeb
2026-09-08 04:06:40
(5 hours ago)
Cluster member (Omitted) (FR/France/-) said, TEMPDENY 34.125.187.171, Reason:[(Suspicious404) Suspic ...
show more
Cluster member (Omitted) (FR/France/-) said, TEMPDENY 34.125.187.171, Reason:[(Suspicious404) Suspicious activity detected 34.125.187.171 (US/United States/171.187.125.34.bc.googleusercontent.com): 10 in the last 3600 secs]
show less
Brute-Force
SSH
🇺🇸
TPI-Abuse
2026-09-08 04:00:47
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.125.187.171 (171.187.125.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.125.187.171 (171.187.125.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 00:00:38.750506 2026] [security2:error] [pid 17932:tid 17950] [client 34.125.187.171:53108] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.strengthsmatter.com"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252fapp/.env"] [unique_id "ap-IZuYiaIC2ngCzyxoM6QAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack