🇧🇪
cmbplf
2026-09-08 21:29:16
(1 hour ago)
877 requests with url.path *.env
640 requests with url.path *.aws/*
163 requests with url.path *. ...
show more
877 requests with url.path *.env
640 requests with url.path *.aws/*
163 requests with url.path *.ssh/*
show less
Brute-Force
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-08 20:07:32
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.142.204.107 (107.204.142.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.142.204.107 (107.204.142.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 16:07:28.081285 2026] [security2:error] [pid 7633:tid 7633] [client 34.142.204.107:8404] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "soleillavie.com"] [uri "/@fs/src/.env"] [unique_id "aqBrAHeAT8ycleTLctGzXwAAADI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 19:27:07
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.142.204.107 (107.204.142.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.142.204.107 (107.204.142.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 15:27:01.398310 2026] [security2:error] [pid 19032:tid 19032] [client 34.142.204.107:63244] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.concentricsteel.com"] [uri "/@fs/../.env"] [unique_id "aqBhhfgHYH7Ow8FBU1YWJAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
AetherFox
2026-09-08 18:50:21
(4 hours ago)
AetherFox VoidGuard detected: [Tue Sep 08 18:50:11.816342 2026] [authz_core:error] [pid 1230301:tid ...
show more
AetherFox VoidGuard detected: [Tue Sep 08 18:50:11.816342 2026] [authz_core:error] [pid 1230301:tid 1230318] [client 34.142.204.107:43596] AH01630: client denied by server configuration: proxy:https://[MASKED]/, referer: https://forum.draconigen.net/
[Tue Sep 08 18:50:11.816859 2026] [authz_core:error] [pid 1230300:tid 1230304] [client 34.142.204.107:43580] AH01630: client denied by server configuration: proxy:https://[MASKED]/, referer: https://forum.draconigen.net/
[Tue Sep 08 18:50:20.689050 2026] [authz_core:error] [pid 1230301:tid 1230332] [client 34.142.204.107:54710] AH01630: client denied by server configuration: proxy:https://[MASKED]/@fs/.env, referer: https://forum.draconigen.net/@fs/.env?raw??
[Tue Sep 08 18:50:20.689737 2026] [authz_core:error] [pid 1230301:tid 1230330] [client 34.142.204.107:54662] AH01630: client denied by server configuration: proxy:https://[MASKED]/, referer: https://forum.draconigen.net/
[Tue Sep 08 18:50:20.690992 2026
...
show less
Bad Web Bot
Web App Attack
Anonymous
2026-09-08 18:20:02
(4 hours ago)
suspicious request in access.log
Web App Attack
🇧🇷
Halux
2026-09-08 18:13:32
(4 hours ago)
34.142.204.107 Probing protected path or service
Web App Attack
🇳🇱
Site.eu
2026-09-08 17:58:46
(5 hours ago)
Excessive multi-domain requests
Brute-Force
🇺🇸
TPI-Abuse
2026-09-08 17:36:46
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.142.204.107 (107.204.142.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.142.204.107 (107.204.142.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 13:36:40.964002 2026] [security2:error] [pid 29364:tid 29364] [client 34.142.204.107:33944] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jaojoco.name"] [uri "/@fs/src/.env"] [unique_id "aqBHqOTIuxMJDKgbaztt8QAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 16:25:45
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.142.204.107 (107.204.142.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.142.204.107 (107.204.142.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 12:25:40.412992 2026] [security2:error] [pid 21770:tid 21770] [client 34.142.204.107:2070] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "alanrmariotti.com.alanmariotti.com"] [uri "/@fs/app/.env"] [unique_id "aqA3BONjUuM2H5wGLsXnnwAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
debestelapp
2026-09-08 16:20:12
(6 hours ago)
Web App Attack
🇫🇷
COMAITE
2026-09-08 16:05:53
(7 hours ago)
Suspicious URL access.
Web App Attack
🇫🇷
ELYAZ
2026-09-08 16:05:37
(7 hours ago)
(y3) Failed access -byebye- from 34.142.204.107 (SG/Singapore/107.204.142.34.bc.googleusercontent.co ...
show more
(y3) Failed access -byebye- from 34.142.204.107 (SG/Singapore/107.204.142.34.bc.googleusercontent.com): (CF_ENABLE)
show less
Hacking
🇳🇱
e.fierstra
2026-09-08 16:03:09
(7 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇳🇱
Mangelot Hosting
2026-09-08 15:39:33
(7 hours ago)
(modsecurity) srv104 ModSecurity 34.142.204.107 (SG/Singapore/107.204.142.34.bc.googleusercontent.co ...
show more
(modsecurity) srv104 ModSecurity 34.142.204.107 (SG/Singapore/107.204.142.34.bc.googleusercontent.com): 30 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 15:39:14
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.142.204.107 (107.204.142.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.142.204.107 (107.204.142.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 11:39:06.625504 2026] [security2:error] [pid 19387:tid 19387] [client 34.142.204.107:14194] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.johnpritchett.com"] [uri "/@fs/root/.env"] [unique_id "aqAsGlK7EEXkkn1k36lSAgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack