🇨🇭
chr70
2026-09-08 12:14:00
(8 hours ago)
Web Spam
🇳🇱
Lentini
2026-09-08 11:32:24
(9 hours ago)
visuitslagen.nl: malicious request:/@fs/.env.production
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 10:43:15
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.139.19.59 (59.19.139.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.139.19.59 (59.19.139.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 06:43:08.706024 2026] [security2:error] [pid 4594:tid 4594] [client 34.139.19.59:21414] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.hendersonhomes.com"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252froot/.env"] [unique_id "ap_mvFqTpPNuJzmYKh30OQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇵🇱
sigurg
2026-09-08 10:07:24
(10 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-path-traversal-probing
Web App Attack
Hacking
🇫🇷
Octopuce
2026-09-08 09:50:59
(11 hours ago)
Aggressive web search of vulnerable pages: /uploads../.env /v1/.env /assets../.env /v2/.env /img../. ...
show more
Aggressive web search of vulnerable pages: /uploads../.env /v1/.env /assets../.env /v2/.env /img../.env ...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 09:32:31
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.139.19.59 (59.19.139.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.139.19.59 (59.19.139.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 05:32:24.693836 2026] [security2:error] [pid 25280:tid 25401] [client 34.139.19.59:5224] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.moogoob.com"] [uri "/@fs/.env"] [unique_id "ap_WKFTnXNQph8hzTsYn-wAAAQY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇦🇺
electronico
2026-09-08 09:21:28
(11 hours ago)
34.139.19.59 - - [08/Sep/2026:20:21:27 +1100] "GET /@fs/app/rootkey.csv?raw?? HTTP/1.1" 404 806 "-" ...
show more
34.139.19.59 - - [08/Sep/2026:20:21:27 +1100] "GET /@fs/app/rootkey.csv?raw?? HTTP/1.1" 404 806 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14_6_1) AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexity-user) Chrome/126.0.7734.44 Safari/537.36"
34.139.19.59 - - [08/Sep/2026:20:21:27 +1100] "GET /@fs/home/node/.aws/credentials?raw?? HTTP/1.1" 404 806 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; +https://www.anthropic.com/claude-user) Chrome/114.0.934.116 Safari/537.36"
34.139.19.59 - - [08/Sep/2026:20:21:27 +1100] "GET /@fs/root/.aws/credentials?raw?? HTTP/1.1" 404 806 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/130.0.6816.73 Safari/537.36; compatible; Claude-SearchBot/1.0; +https://www.anthropic.com/claude-searchbot"
34.139.19.59 - - [08/Sep/2026:20:21:27 +1100] "GET /@fs/src/.env?raw?? HTTP/1.1" 404 806 "-" "Moz
...
show less
Brute-Force
Web App Attack
🇬🇧
consul.to
2026-09-08 09:16:28
(11 hours ago)
Web attack/malicious scanning detected
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 09:02:46
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.139.19.59 (59.19.139.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.139.19.59 (59.19.139.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 05:02:43.308678 2026] [security2:error] [pid 23563:tid 23563] [client 34.139.19.59:43292] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.conveyorizedovens.com"] [uri "/@fs/.env"] [unique_id "ap_PM1BPxob98ISGSlp0UwAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 08:46:05
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.139.19.59 (59.19.139.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.139.19.59 (59.19.139.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 04:45:57.702988 2026] [security2:error] [pid 2544:tid 2544] [client 34.139.19.59:22860] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.messengersforchrist.charity"] [uri "/@fs/app/.env"] [unique_id "ap_LRUvAUyy4AEi_7XbVSAAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 08:28:32
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.139.19.59 (59.19.139.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.139.19.59 (59.19.139.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 04:28:26.823424 2026] [security2:error] [pid 24333:tid 24333] [client 34.139.19.59:32268] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.chriscollinsplumbing.com"] [uri "/@fs/root/.env"] [unique_id "ap_HKkhLqktihpqDN_2n-QAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Site.eu
2026-09-08 08:03:27
(12 hours ago)
Excessive multi-domain requests
Brute-Force
🇩🇪
Petros Stefanakis
2026-09-08 08:01:55
(12 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 34.139.19.59 (US/United States/59.19.13 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.139.19.59 (US/United States/59.19.139.34.bc.googleusercontent.com)
show less
SQL Injection
🇺🇸
TPI-Abuse
2026-09-08 07:31:46
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.139.19.59 (59.19.139.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.139.19.59 (59.19.139.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 03:31:38.693706 2026] [security2:error] [pid 9718:tid 9718] [client 34.139.19.59:1308] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.spores101.com"] [uri "/@fs/root/.env"] [unique_id "ap-52snevVTZfdqqM2CFIwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇿
Antinson
2026-09-08 07:16:38
(13 hours ago)
Scraping with a high error ratio and request rate
Bad Web Bot