🇳🇱
homeshowdomain.nl
2026-09-09 22:01:58
(1 day ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-08.
show less
Web App Attack
SSH
Hacking
🇺🇸
TPI-Abuse
2026-09-08 20:03:53
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.146.1.101 (101.1.146.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.146.1.101 (101.1.146.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 16:03:50.188629 2026] [security2:error] [pid 10216:tid 10216] [client 34.146.1.101:5872] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.peacefulsteps.com"] [uri "/@fs/root/.env"] [unique_id "aqBqJtV3m8bwNSekGObzKAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
debestelapp
2026-09-08 19:50:12
(2 days ago)
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 19:35:13
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.146.1.101 (101.1.146.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.146.1.101 (101.1.146.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 15:35:05.720714 2026] [security2:error] [pid 25790:tid 25790] [client 34.146.1.101:38028] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.dayspapass.com"] [uri "/@fs/root/.env"] [unique_id "aqBjaVj9zeU4DA-Rc_ZHuAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-08 18:50:03
(2 days ago)
suspicious request in access.log
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 18:44:18
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.146.1.101 (101.1.146.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.146.1.101 (101.1.146.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 14:44:14.608800 2026] [security2:error] [pid 5681:tid 5681] [client 34.146.1.101:46318] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.nexthop.com"] [uri "/@fs/.env"] [unique_id "aqBXfs0ErX_s--NYBpC-1QAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-08 18:34:32
(2 days ago)
[da.kdns.gr] httpd-config-scan: sites=www.onar-pension.gr; logs=/var/log/httpd/domains/onar-pension. ...
show more
[da.kdns.gr] httpd-config-scan: sites=www.onar-pension.gr; logs=/var/log/httpd/domains/onar-pension.gr.log; samples=/@fs/.env?raw?? | /@fs/root/.env?raw?? | /@fs/src/.env?raw??
show less
Hacking
Web App Attack
🇦🇺
screwlooseit.com.au
2026-09-08 18:21:32
(2 days ago)
Blocked by CSF 13 firewall - Rule: US/United States/101.1.146.34.bc.googleusercontent.com
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 18:14:58
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.146.1.101 (101.1.146.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.146.1.101 (101.1.146.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 14:14:52.951394 2026] [security2:error] [pid 22347:tid 22347] [client 34.146.1.101:38060] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "atsfoundation.com.helpkccare.org"] [uri "/@fs/.env"] [unique_id "aqBQnPSFOnR3j9xF6aZAQgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
dynamix
2026-09-08 17:55:57
(2 days ago)
Multiple WAF Violations
Web App Attack
🇧🇪
cmbplf
2026-09-08 17:43:45
(2 days ago)
790 requests with url.path *.aws/*
Brute-Force
Bad Web Bot
🇫🇷
Octopuce
2026-09-08 17:16:48
(2 days ago)
Aggressive web search of vulnerable pages: /v1/.env /v2/.env /.env /app/.env /api/.env ...
Web App Attack
🇨🇭
backslash
2026-09-08 16:57:01
(2 days ago)
block ruleset 3D3AFA921A373ECE19B6BA285C2D722163304638
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-08 16:37:17
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.146.1.101 (101.1.146.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.146.1.101 (101.1.146.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 12:37:09.307735 2026] [security2:error] [pid 5305:tid 5305] [client 34.146.1.101:15856] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.lo-family.org"] [uri "/@fs/.env"] [unique_id "aqA5tT-2zyht-Ix5tp2xwwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 16:17:59
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.146.1.101 (101.1.146.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.146.1.101 (101.1.146.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 12:17:51.214161 2026] [security2:error] [pid 29645:tid 29645] [client 34.146.1.101:56116] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.stepiz62.com.appsdips.com"] [uri "/@fs/.env"] [unique_id "aqA1LzlHsaYntIIgmVJyJwAAAIc"]
show less
Brute-Force
Bad Web Bot
Web App Attack