🇺🇸
TPI-Abuse
2026-09-09 13:16:08
(5 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.13.228.198 (198.228.13.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.13.228.198 (198.228.13.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 09:16:04.388499 2026] [security2:error] [pid 13124:tid 13124] [client 34.13.228.198:52290] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.treeofloveproductions.com"] [uri "/@fs/src/.env"] [unique_id "aqFcFMBL8m4u133B58DyDQAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-09 12:59:19
(22 minutes ago)
34.13.228.198 detected and blocked by apache-modsecurity after 1 try
Brute-Force
🇿🇦
conure.sh
2026-09-09 12:16:41
(1 hour ago)
csagent: score 20.5: secrets grab x2, 404 noise floor x2; 2 domain(s) in 4s
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 12:04:55
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.13.228.198 (198.228.13.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.13.228.198 (198.228.13.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 08:04:49.611555 2026] [security2:error] [pid 12849:tid 12849] [client 34.13.228.198:47206] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.scadco.com"] [uri "/@fs/.env"] [unique_id "aqFLYWVSPyzYqKbGYFHC8wAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-09 11:17:21
(2 hours ago)
34.13.228.198 - - [09/Sep/2026:13:16:12 +0200] "GET HTTP/1.1" 403 1852 "-" "Mozilla/5.0 (compatible ...
show more
34.13.228.198 - - [09/Sep/2026:13:16:12 +0200] "GET HTTP/1.1" 403 1852 "-" "Mozilla/5.0 (compatible; OAI-SearchBot/1.3; +https://openai.com/searchbot)"
show less
Web Spam
Blog Spam
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 10:46:53
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.13.228.198 (198.228.13.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.13.228.198 (198.228.13.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 06:46:49.929275 2026] [security2:error] [pid 29935:tid 29935] [client 34.13.228.198:60688] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.deborbonfoundation.org"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252fapp/.env"] [unique_id "aqE5GSvYXZIpA39rVmIavAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 09:48:56
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.13.228.198 (198.228.13.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.13.228.198 (198.228.13.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 05:48:53.492605 2026] [security2:error] [pid 23443:tid 23443] [client 34.13.228.198:7948] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "stinecapital.net.anthonyanimalclinic.net"] [uri "/@fs/.env"] [unique_id "aqErhXDpdbRYiuADJikTeAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Mangelot Hosting
2026-09-09 08:00:43
(5 hours ago)
(modsecurity) srv102 ModSecurity 34.13.228.198 (NL/The Netherlands/198.228.13.34.bc.googleuserconten ...
show more
(modsecurity) srv102 ModSecurity 34.13.228.198 (NL/The Netherlands/198.228.13.34.bc.googleusercontent.com): 30 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
🇳🇱
debestelapp
2026-09-09 07:50:12
(5 hours ago)
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 07:22:11
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.13.228.198 (198.228.13.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.13.228.198 (198.228.13.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 03:22:06.530557 2026] [security2:error] [pid 23182:tid 23189] [client 34.13.228.198:50644] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "oftv.hdtv55.com"] [uri "/@fs/.env"] [unique_id "aqEJHpT7fuGblUO4rvJXyQAAAUQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
masterguru
2026-09-09 07:02:56
(6 hours ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.13.228.198 (NL/The Netherlands/198 ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.13.228.198 (NL/The Netherlands/198.228.13.34.bc.googleusercontent.com): 1 in the last 3600 secs (0-195)
show less
Hacking
🇺🇸
TPI-Abuse
2026-09-09 06:17:36
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.13.228.198 (198.228.13.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.13.228.198 (198.228.13.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 02:17:30.443315 2026] [security2:error] [pid 16757:tid 16810] [client 34.13.228.198:36998] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.aisapy.com"] [uri "/@fs/root/.env"] [unique_id "aqD5-kIKZh2OyGhjAeBOhwAAAJM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 05:52:53
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.13.228.198 (198.228.13.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.13.228.198 (198.228.13.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 01:52:48.464979 2026] [security2:error] [pid 5986:tid 5986] [client 34.13.228.198:33764] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.mandavaassoc.com"] [uri "/@fs/root/.env"] [unique_id "aqD0MBTk0JpKbwdogkF4HwAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
masterguru
2026-09-09 05:36:38
(7 hours ago)
Restricted File Access Attempt. Matched phrase "/@fs/" at REQUEST_FILENAME. (930130-193)
Hacking
Web App Attack
🇧🇪
cmbplf
2026-09-09 05:10:36
(8 hours ago)
6.971 4xx requests in 1 hour (1w22h27m)
Brute-Force
Bad Web Bot