🇳🇱
homeshowdomain.nl
2026-09-04 22:02:57
(1 day ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-03.
show less
Web App Attack
SSH
Hacking
🇺🇸
TPI-Abuse
2026-09-04 15:24:25
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.142.227.143 (143.227.142.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.142.227.143 (143.227.142.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 11:24:20.660512 2026] [security2:error] [pid 7140:tid 7140] [client 34.142.227.143:48722] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.richardlyne.com"] [uri "/@fs/app/.env"] [unique_id "apripL0RslFUzZ3WAtTXmAAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 14:12:05
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.142.227.143 (143.227.142.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.142.227.143 (143.227.142.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 10:11:58.710827 2026] [security2:error] [pid 29897:tid 29897] [client 34.142.227.143:27736] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jvwebinars.vanemby.com"] [uri "/@fs/.env"] [unique_id "aprRrjAGFgFFpQms6mCMBwAAAD8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
dot.mg
2026-09-04 13:32:11
(1 day ago)
Bad behaviour
Web Spam
🇧🇪
madeit
2026-09-04 12:44:00
(1 day ago)
Web App Attack
🇳🇱
BlueWire Hosting
2026-09-04 12:18:52
(1 day ago)
High-confidence malicious configuration/VCS probe
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 11:55:05
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.142.227.143 (143.227.142.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.142.227.143 (143.227.142.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 07:54:55.450593 2026] [security2:error] [pid 26513:tid 26513] [client 34.142.227.143:60450] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.vtwins.us"] [uri "/@fs/.env"] [unique_id "apqxj2woI00Oq_WAlpbRmAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 10:03:08
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.142.227.143 (143.227.142.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.142.227.143 (143.227.142.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:02:59.999374 2026] [security2:error] [pid 13707:tid 13707] [client 34.142.227.143:20886] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "groux.net"] [uri "/@fs/root/.env"] [unique_id "apqXU53FFomdBGTtXfyFTwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 09:31:11
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.142.227.143 (143.227.142.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.142.227.143 (143.227.142.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 05:31:03.599538 2026] [security2:error] [pid 26221:tid 26221] [client 34.142.227.143:18642] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.cygnuslabs.com"] [uri "/@fs/.env.production"] [unique_id "apqP14jIhKt0yVY_yW5AqQAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
i-turnradio.nl
2026-09-04 09:04:24
(1 day ago)
2026-09-04 @ 11:04:24 (CET) ~ Blocked for trying to access: /@fs/app/.env?raw??
Web App Attack
🇳🇱
ConsulHosting
2026-09-04 06:57:07
(1 day ago)
Automatically blocked due to distributed attack
Hacking
Anonymous
2026-09-04 06:49:33
(1 day ago)
34.142.227.143 - - [04/Sep/2026:08:49:24 +0200] "GET / HTTP/1.1" 403 12583 "-" "Mozilla/5.0 (Windows ...
show more
34.142.227.143 - - [04/Sep/2026:08:49:24 +0200] "GET / HTTP/1.1" 403 12583 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
34.142.227.143 - - [04/Sep/2026:08:49:24 +0200] "GET / HTTP/1.1" 403 12583 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
34.142.227.143 - - [04/Sep/2026:08:49:33 +0200] "GET /@fs/root/.aws/credentials?raw?? HTTP/1.1" 403 12583 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_5 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.3 Mobile/15E148 Safari/604.1; compatible; Claude-User/1.0; +https://www.anthropic.com/claude-user"
34.142.227.143 - - [04/Sep/2026:08:49:33 +0200] "GET /@fs/.env?raw?? HTTP/1.1" 403 153 "-" "Mozilla/5.0 (Windows NT 10.0; rv:121.5) Gecko/20100101 Firefox/121.5; compatible; ClaudeBot/1.0; [email protected] "
34.142.227.143 - - [04/Sep/2026:08:49:33 +0200] "GET /@fs/etc/passwd?raw?? H
...
show less
Bad Web Bot
Web App Attack
🇩🇪
YF
2026-09-04 06:30:18
(1 day ago)
Distributed subnet attack — coordinated scanning from multiple IPs in the same /24
DDoS Attack
Web App Attack
🇫🇷
Stara
2026-09-04 05:01:14
(1 day ago)
ModSecurity detected web attack - .env/config probing or SQLi/Code injection (Rule 949110)
Brute-Force
SSH
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 04:39:35
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.142.227.143 (143.227.142.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.142.227.143 (143.227.142.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 00:39:29.281561 2026] [security2:error] [pid 24854:tid 24854] [client 34.142.227.143:18668] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.beirutbazar.com"] [uri "/@fs/.env"] [unique_id "appLgcUiYuZjQHhmXtKHRAAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack