🇧🇪
cmbplf
2026-09-08 22:28:27
(20 minutes ago)
1.650 requests with url.path */@fs/*
264 requests with url.path *.config/*
258 requests with url. ...
show more
1.650 requests with url.path */@fs/*
264 requests with url.path *.config/*
258 requests with url.path *credentials.json
125 requests with url.path */proc/*
103 requests with url.path *.ssh/*
show less
Brute-Force
Bad Web Bot
🇬🇧
Bytemark
2026-09-08 20:23:07
(2 hours ago)
34.146.108.178 - - [08/Sep/2026:21:23:06 +0100] "GET /@fs/etc/apache2/apache2.conf?raw?? HTTP/1.1" 3 ...
show more
34.146.108.178 - - [08/Sep/2026:21:23:06 +0100] "GET /@fs/etc/apache2/apache2.conf?raw?? HTTP/1.1" 301 905 "https://www.distancelearningcentre.info/@fs/etc/apache2/apache2.conf?raw??" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko; compatible; GrokBot/1.0; +https://x.ai/grokbot) Chrome/134.0.9024.132 Safari/537.36 Edg/134.0.9024.132"
show less
Brute-Force
Web App Attack
🇮🇹
CoreTech srl
2026-09-08 20:04:03
(2 hours ago)
cloudlinux2 fail2ban: 2026-09-08 21:59:21,526 fail2ban.filter [1794]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-09-08 21:59:21,526 fail2ban.filter [1794]: INFO [plesk-modsecurity] Found 34.146.108.178 - 2026-09-08 21:59:21cloudlinux2 fail2ban: 2026-09-08 21:59:21,549 fail2ban.filter [1794]: INFO [plesk-modsecurity] Found 34.146.108.178 - 2026-09-08 21:59:21cloudlinux2 fail2ban: 2026-09-08 21:59:21,558 fail2ban.filter [1794]: INFO [plesk-modsecurity] Found 34.146.108.178 - 2026-09-08 21:59:21cloudlinux2 fail2ban: 2026-09-08 21:59:21,538 fail2ban.filter [1794]: INFO [plesk-modsecurity] Found 34.146.108.178 - 2026-09-08 21:59:21cloudlinux2 fail2ban: 2026-09-08 21:59:21,571 fail2ban.filter [1794]: INFO [plesk-modsecurity] Found 34.146.108.178 - 2026-09-08 21:59:21cloudlinux2 fail2ban: 2026-09-08 21:59:21,582 fail2ban.filter [1794]: INFO [plesk-modsecurity] Found 34.146.108.178 - 2026-09-08 21:59:21cloudlinux2 fail2ban: 2026-09-08 21:59:21,623 fail2ban.filter [1794]: INFO [plesk-modsecurity] Found 34.146.108.178 - 2026-09
show less
Brute-Force
🇺🇸
TPI-Abuse
2026-09-08 19:40:52
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.146.108.178 (178.108.146.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.146.108.178 (178.108.146.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 15:40:45.493204 2026] [security2:error] [pid 27156:tid 27156] [client 34.146.108.178:12476] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.unitymaine.org"] [uri "/@fs/../../.env"] [unique_id "aqBkvU8v0A25wT5t0zjitwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Site.eu
2026-09-08 19:32:42
(3 hours ago)
Excessive multi-domain requests
Brute-Force
🇩🇪
netclix.gr
2026-09-08 18:55:08
(3 hours ago)
(security_scan) Sensitive File Scan Blocked 34.146.108.178 (JP/Japan/178.108.146.34.bc.googleusercon ...
show more
(security_scan) Sensitive File Scan Blocked 34.146.108.178 (JP/Japan/178.108.146.34.bc.googleusercontent.com): 1 in the last 4600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 34.146.108.178 - - [08/Sep/2026:21:54:57 +0300] "GET /@fs/../../.env?raw?? HTTP/1.1" 400 849 "-" "-"
show less
Port Scan
Anonymous
2026-09-08 17:59:38
(4 hours ago)
Aggressive web scan
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-08 17:51:35
(4 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-path-traversal-probing
Web App Attack
Hacking
🇿🇦
conure.sh
2026-09-08 17:47:49
(5 hours ago)
csagent: score 20.0: secrets grab x2; 1 domain(s) in 5s
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 17:20:24
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.146.108.178 (178.108.146.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.146.108.178 (178.108.146.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 13:20:19.156952 2026] [security2:error] [pid 3100:tid 3116] [client 34.146.108.178:29230] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.planillas.net"] [uri "/@fs/root/.env"] [unique_id "aqBD0_sZ34QsbkhdaXvkdwAAAQ4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-08 16:59:05
(5 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
🇫🇷
dynamix
2026-09-08 16:58:13
(5 hours ago)
Multiple WAF Violations
Web App Attack
Anonymous
2026-09-08 16:47:22
(6 hours ago)
Banned by Fail2Ban on server
Web App Attack
🇸🇪
vaia.cloud
2026-09-08 16:45:02
(6 hours ago)
crowdsecurity/http-probing
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 16:44:46
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.146.108.178 (178.108.146.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.146.108.178 (178.108.146.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 12:44:41.049573 2026] [security2:error] [pid 17372:tid 17372] [client 34.146.108.178:63594] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.barnesandbrower.com"] [uri "/@fs/src/.env"] [unique_id "aqA7eQzinctE-QzwQtd9PgAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack