🇧🇪
cmbplf
2026-09-12 11:41:25
(1 minute ago)
161 requests with url.path */@fs/*
Brute-Force
Bad Web Bot
🇬🇧
bensmithurst
2026-09-12 10:36:25
(1 hour ago)
34.145.251.191 - - [12/Sep/2026:10:36:24 +0000] "GET /..%2f.env HTTP/1.1" 400 150 "-" "-"
34.145.251 ...
show more
34.145.251.191 - - [12/Sep/2026:10:36:24 +0000] "GET /..%2f.env HTTP/1.1" 400 150 "-" "-"
34.145.251.191 - - [12/Sep/2026:10:36:24 +0000] "GET /%2e%2e/.env HTTP/1.1" 400 150 "-" "-"
34.145.251.191 - - [12/Sep/2026:10:36:24 +0000] "GET /%2e%2e/.env HTTP/1.1" 400 150 "-" "-"
... [host=LAN***]
show less
Web App Attack
🇫🇷
regishoussin
2026-09-12 10:29:30
(1 hour ago)
Automated web scanning detected by Wazuh (rule 100241): repeated 400/404 errors from mass probing of ...
show more
Automated web scanning detected by Wazuh (rule 100241): repeated 400/404 errors from mass probing of admin/backdoor paths (e.g. wp-login.php, known CMS shell filenames) on an Apache web server, on 2026-09-12 10:29 UTC.
show less
Bad Web Bot
Web App Attack
🇸🇪
vaia.cloud
2026-09-12 10:05:02
(1 hour ago)
crowdsecurity/http-probing
Brute-Force
Web App Attack
🇲🇽
octageeks.com
2026-09-12 04:18:59
(7 hours ago)
Wordpress malicious attack:[octablocked]
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 02:18:51
(9 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.145.251.191 (191.251.145.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 34.145.251.191 (191.251.145.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 22:18:47.014030 2026] [security2:error] [pid 14675:tid 14675] [client 34.145.251.191:55514] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.ecomim.com|F|2"] [data ".ecomim.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.ecomim.com"] [uri "/z9x8c7v6b5-debug-trigger-mail.ecomim.com"] [unique_id "aqS2h8g3xlZ4RUwIKxM_qwAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 18:30:48
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.145.251.191 (191.251.145.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.145.251.191 (191.251.145.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 14:30:45.145034 2026] [security2:error] [pid 20635:tid 20635] [client 34.145.251.191:56828] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "effectivefirearms.com"] [uri "/.env"] [unique_id "aqRI1awuChlQFbFjQG1MwgAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
Octopuce
2026-09-11 18:15:50
(17 hours ago)
Aggressive web search of vulnerable pages: /@fs/app/.env?raw?? /@fs/src/.env?raw?? /.env?raw?? /.env ...
show more
Aggressive web search of vulnerable pages: /@fs/app/.env?raw?? /@fs/src/.env?raw?? /.env?raw?? /.env /@fs/..%252f..%252f..%252f..%252f..%252fro ...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 18:13:55
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.145.251.191 (191.251.145.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.145.251.191 (191.251.145.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 14:13:50.089124 2026] [security2:error] [pid 12907:tid 12907] [client 34.145.251.191:53974] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "eefinchco.com"] [uri "/images../.env"] [unique_id "aqRE3kuf9ReT9JCH2fcyNgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
mnsf
2026-09-11 18:05:14
(17 hours ago)
Too many Status 40X (12)
Brute-Force
Web App Attack
🇬🇧
bensmithurst
2026-09-11 18:01:06
(17 hours ago)
34.145.251.191 - - [11/Sep/2026:18:01:06 +0000] "GET /%2E%2E/%2E%2E/%2E%2E/%2E%2E/proc/self/environ ...
show more
34.145.251.191 - - [11/Sep/2026:18:01:06 +0000] "GET /%2E%2E/%2E%2E/%2E%2E/%2E%2E/proc/self/environ HTTP/1.1" 400 150 "-" "-"
34.145.251.191 - - [11/Sep/2026:18:01:06 +0000] "GET /@fs/..%2f..%2f..%2f..%2f..%2froot/.env HTTP/1.1" 400 150 "-" "-"
34.145.251.191 - - [11/Sep/2026:18:01:06 +0000] "GET /@fs/..%2f..%2f..%2f..%2f..%2froot/.env HTTP/1.1" 400 150 "-" "-"
34.145.251.191 - - [11/Sep/2026:18:01:06 +0000] "GET /@fs/..%2f..%2f..%2f..%2f..%2fproc/self/environ HTTP/1.1" 400 150 "-" "-"
... [host=LAN***]
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 17:56:22
(17 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.145.251.191 (191.251.145.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 34.145.251.191 (191.251.145.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 13:56:18.823792 2026] [security2:error] [pid 2783:tid 2783] [client 34.145.251.191:42424] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||edwardchrisman.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "edwardchrisman.com"] [uri "/z9x8c7v6b5-debug-trigger-edwardchrisman.com"] [unique_id "aqRAwvBD18GClekSHW6PqQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
bensmithurst
2026-09-11 17:16:18
(18 hours ago)
34.145.251.191 - - [11/Sep/2026:17:16:17 +0000] "GET /%2e%2e/.env HTTP/1.1" 400 150 "-" "-"
34.145.2 ...
show more
34.145.251.191 - - [11/Sep/2026:17:16:17 +0000] "GET /%2e%2e/.env HTTP/1.1" 400 150 "-" "-"
34.145.251.191 - - [11/Sep/2026:17:16:17 +0000] "GET /..%2f.env HTTP/1.1" 400 150 "-" "-"
34.145.251.191 - - [11/Sep/2026:17:16:17 +0000] "GET /..%2f..%2f.env HTTP/1.1" 400 150 "-" "-"
34.145.251.191 - - [11/Sep/2026:17:16:17 +0000] "GET /api/uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2fproc/self/environ HTTP/1.1" 400 150 "-" "-"
34.145.251.191 - - [11/Sep/2026:17:16:18 +0000] "GET /public/plugins/alertlist/../../../../../../../../proc/self/environ HTTP/1.1" 400 150 "-" "-"
... [host=LAN***]
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 17:05:06
(18 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.145.251.191 (191.251.145.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 34.145.251.191 (191.251.145.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 13:05:02.145455 2026] [security2:error] [pid 13727:tid 13727] [client 34.145.251.191:56894] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||edjpropertysolutions.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "edjpropertysolutions.com"] [uri "/rclone.conf"] [unique_id "aqQ0vkt0FQ930SEDkUTRlQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
WizardsToolkit
2026-09-11 17:05:05
(18 hours ago)
tried to access forbidden files; attempted to access /404.php?import&raw??
Web App Attack