🇺🇸
TPI-Abuse
2026-09-04 11:39:54
(28 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.125.8.27 (27.8.125.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.125.8.27 (27.8.125.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 07:39:45.443626 2026] [security2:error] [pid 9989:tid 9989] [client 34.125.8.27:10464] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.hollywoo9.exotic-dancers-los-angeles.com"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252froot/.env"] [unique_id "apquAaZhRvNsnrBjpi-RcgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-04 11:34:11
(34 minutes ago)
Banned by Fail2Ban on server
Web App Attack
🇵🇱
strefapi_com
2026-09-04 11:07:27
(1 hour ago)
Brute-force, web
...
Hacking
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 10:44:42
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.125.8.27 (27.8.125.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.125.8.27 (27.8.125.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:44:35.339191 2026] [security2:error] [pid 28897:tid 28897] [client 34.125.8.27:26576] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.joseluisperez.com"] [uri "/@fs/root/.env"] [unique_id "apqhE66jYfwh4eCyiSXb1AAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 10:25:06
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.125.8.27 (27.8.125.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.125.8.27 (27.8.125.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:24:58.152143 2026] [security2:error] [pid 4057:tid 4057] [client 34.125.8.27:36090] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.silvermoonpizza.com"] [uri "/@fs/app/.env"] [unique_id "apqcetRMxRwYzN0avolmlAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 09:22:00
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.125.8.27 (27.8.125.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.125.8.27 (27.8.125.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 05:21:55.313780 2026] [security2:error] [pid 30479:tid 30479] [client 34.125.8.27:52492] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.chrismcc.com"] [uri "/@fs/src/.env"] [unique_id "apqNsysbuxw7MulT2wgOMAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
updown.io
2026-09-04 08:48:15
(3 hours ago)
{"level":"info","ts":1788511662.4080408,"logger":"http.log.access.log1","msg":"handled request","req ...
show more
{"level":"info","ts":1788511662.4080408,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"34.125.8.27","remote_port":"59362","client_ip":"34.125.8.27","proto":"HTTP/1.1","method":"GET","host":"status.nicksan.com","uri":"/","headers":{"User-Agent":["Mozilla/5.0 (Linux; Android 13; SM-G935R6; Build/TP1A.180718.91) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.6261.127 Mobile Safari/537.36"],"Accept":["*/*"],"Accept-Encoding":["gzip"]}},"bytes_read":0,"user_id":"","duration":0.000164424,"size":0,"status":308,"resp_headers":{"Server":["Caddy"],"Connection":["close"],"Location":["https://status.nicksan.com/"],"Content-Type":[]}}
{"level":"info","ts":1788511667.1844895,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"34.125.8.27","remote_port":"30922","client_ip":"34.125.8.27","proto":"HTTP/1.1","method":"GET","host":"status.nicksan.com","uri":"/@fs/.env.development?raw??","headers":{"Accept":["text/html,application/xhtml+xml
...
show less
DDoS Attack
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 08:46:04
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.125.8.27 (27.8.125.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.125.8.27 (27.8.125.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 04:46:00.274426 2026] [security2:error] [pid 6721:tid 6721] [client 34.125.8.27:40038] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "athome360.com"] [uri "/@fs/.env"] [unique_id "apqFSK1jEQvAzEFXpLan3AAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Nightreaver
2026-09-04 06:12:01
(5 hours ago)
34.125.8.27 - - [04/Sep/2026:08:12:01 0200] "GET /@fs/src/.env?raw?? HTTP/1.1" 404 1015 "-" "Mozill ...
show more
34.125.8.27 - - [04/Sep/2026:08:12:01 0200] "GET /@fs/src/.env?raw?? HTTP/1.1" 404 1015 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; GPTBot/1.4; https://openai.com/gptbot)"
34.125.8.27 - - [04/Sep/2026:08:12:01 0200] "GET /@fs/root/.env?raw?? HTTP/1.1" 404 1015 "-" "Mozilla/5.0 (compatible; Applebot/0.1; http://www.apple.com/go/applebot)"
34.125.8.27 - - [04/Sep/2026:08:12:01 0200] "GET /@fs/..%2f..%2f..%2f..%2f..%2froot/.env?raw?? HTTP/1.1" 404 1015 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-SearchBot/1.0; https://www.anthropic.com/claude-searchbot)"
34.125.8.27 - - [04/Sep/2026:08:12:01 0200] "GET /@fs/proc/self/environ?raw?? HTTP/1.1" 404 1015 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:150.3) Gecko/20100101 Firefox/150.3; compatible; Claude-User/1.0; https://www.anthropic.com/claude-user"
34.125.8.27 - - [04/Sep/2026:08:12:01 0200] "GET /@fs/..%2f..%2f..%2f..%2f..%2fproc/self/environ?raw?? HTTP/1.1" 404 1015 "-" "Mozilla/5.0 [...]
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 05:45:41
(6 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.125.8.27 (27.8.125.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.125.8.27 (27.8.125.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 01:45:33.554004 2026] [security2:error] [pid 4644:tid 4644] [client 34.125.8.27:38264] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||autodiscover.imageries.net|F|2"] [data ".bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "autodiscover.imageries.net"] [uri "/@fs/root/.aws/credentials.bak"] [unique_id "appa_Y-9OSTZAz_Ab_MW0AAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
ConsulHosting
2026-09-04 05:28:03
(6 hours ago)
Automatically blocked due to distributed attack
Hacking
🇩🇪
LRob
2026-09-04 05:10:10
(6 hours ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /@fs/src/.env (+10 more) | 2026-09-04 05:10 UTC
show less
Hacking
Web App Attack
🇧🇪
taivas.nl
2026-09-04 04:33:15
(7 hours ago)
Many_bad_calls
Web App Attack
🇩🇪
FD-IX
2026-09-04 03:31:07
(8 hours ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 03:26:06
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.125.8.27 (27.8.125.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.125.8.27 (27.8.125.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 23:25:58.164342 2026] [security2:error] [pid 28427:tid 28427] [client 34.125.8.27:1056] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.stablechase.com"] [uri "/@fs/.env"] [unique_id "apo6RjcGYKWUCUDasTxbbQAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack