🇩🇪
LRob
2026-09-07 08:48:46
(22 minutes ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /@fs/.env.development (+10 more) | 2026-09-07 08:48 UTC
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 08:15:07
(56 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.148.171.165 (165.171.148.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.148.171.165 (165.171.148.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 04:15:02.264715 2026] [security2:error] [pid 23876:tid 23876] [client 34.148.171.165:56528] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kathleenhazlett.com"] [uri "/@fs/.env.local"] [unique_id "ap5yhkJKMOtQAMAUCurRBQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-09-07 08:11:34
(59 minutes ago)
Web attack/malicious scanning detected
Web App Attack
Anonymous
2026-09-07 08:08:31
(1 hour ago)
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: US, Attack patterns: Word ...
show more
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: US, Attack patterns: WordPress scanning, Backup file probing, Cloud secrets probing
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 07:52:13
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.148.171.165 (165.171.148.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.148.171.165 (165.171.148.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 03:52:06.708470 2026] [security2:error] [pid 15824:tid 15824] [client 34.148.171.165:18064] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.holdingfamily.com"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252fapp/.env"] [unique_id "ap5tJmSZh5qs8RUxy6dMJwAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 07:22:09
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.148.171.165 (165.171.148.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.148.171.165 (165.171.148.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 03:22:04.110520 2026] [security2:error] [pid 1775985:tid 1776035] [client 34.148.171.165:45960] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pacific-biologics.fevini.com"] [uri "/@fs/app/.env"] [unique_id "ap5mHAFr_IfloKDM32fIIgAAAU0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇸🇪
nekopavel
2026-09-07 06:46:31
(2 hours ago)
34.148.171.165 - - [07/Sep/2026:08:46:30 +0200]"GET /@fs/../.env?raw?? HTTP/1.1" 404 804"-" pl2.dori ...
show more
34.148.171.165 - - [07/Sep/2026:08:46:30 +0200]"GET /@fs/../.env?raw?? HTTP/1.1" 404 804"-" pl2.dorito.pavel.gg "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; +https://www.anthropic.com/claude-user)""0.000" "-""North Charleston" "US"
34.148.171.165 - - [07/Sep/2026:08:46:30 +0200]"GET /@fs/..%252f..%252f..%252f..%252f..%252froot/.env?raw?? HTTP/1.1" 404 804"-" pl2.dorito.pavel.gg "Mozilla/5.0 (Windows NT 10.0; rv:128.18) Gecko/20100101 Firefox/128.18; compatible; Bytespider; +https://zhanzhang.toutiao.com/""0.000" "-""North Charleston" "US"
34.148.171.165 - - [07/Sep/2026:08:46:30 +0200]"GET /@fs/app/.env?raw?? HTTP/1.1" 444 0"-" pl2.dorito.pavel.gg "Mozilla/5.0 (iPhone; CPU iPhone OS 18_4 like Mac OS X) AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; [email protected] ) Chrome/124.0.6446.73 Mobile Safari/537.36""0.000" "-""North Charleston" "US"
...
show less
Hacking
Bad Web Bot
Web App Attack
🇧🇪
cmbplf
2026-09-07 05:51:55
(3 hours ago)
275 requests with url.path *.config/*
Brute-Force
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-07 05:50:43
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.148.171.165 (165.171.148.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.148.171.165 (165.171.148.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 01:50:37.062601 2026] [security2:error] [pid 29503:tid 29503] [client 34.148.171.165:19508] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rahjx.rcto.us"] [uri "/@fs/.env.development"] [unique_id "ap5QrUY0JNe74j51zfG_1QAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-07 05:04:19
(4 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
Anonymous
2026-09-07 04:44:20
(4 hours ago)
Aggressive web scan
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 04:22:11
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.148.171.165 (165.171.148.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.148.171.165 (165.171.148.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 00:22:03.806717 2026] [security2:error] [pid 27331:tid 27338] [client 34.148.171.165:15722] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.aafminstitute.com"] [uri "/@fs/.env"] [unique_id "ap476_EqYSWtK3vAwhI80QAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
VHosting
2026-09-07 04:10:03
(5 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
Anonymous
2026-09-07 03:40:33
(5 hours ago)
Multiple web server 400 error codes from same source ip
Web App Attack