🇺🇸
IndigoRidge
2026-09-07 20:59:32
(19 hours ago)
[07/Sep/2026:16:59:32.103942 --0400] ap8ltEtZrdAyqh9nf98QsgAAAYI 34.150.253.212 53370 205.233.18.17 ...
show more
[07/Sep/2026:16:59:32.103942 --0400] ap8ltEtZrdAyqh9nf98QsgAAAYI 34.150.253.212 53370 205.233.18.17 7081
[07/Sep/2026:16:59:32.156445 --0400] ap8ltHsRO4LXar4glifbJgAAAgQ 34.150.253.212 53424 205.233.18.17 7081
[07/Sep/2026:16:59:32.167283 --0400] ap8ltHsRO4LXar4glifbJwAAAg0 34.150.253.212 53410 205.233.18.17 7081
[07/Sep/2026:16:59:32.183500 --0400] ap8ltNoBiitg5XEMNfr86QAAAIE 34.150.253.212 53486 205.233.18.17 7081
[07/Sep/2026:16:59:32.188750 --0400] ap8ltNoBiitg5XEMNfr87AAAAJY 34.150.253.212 53490 205.233.18.17 7081
...
show less
Hacking
🇺🇸
TPI-Abuse
2026-09-07 20:45:13
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.150.253.212 (212.253.150.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.150.253.212 (212.253.150.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 16:45:02.206890 2026] [security2:error] [pid 1364:tid 1364] [client 34.150.253.212:64590] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.growtowork.com"] [uri "/@fs/.env.local"] [unique_id "ap8iTgMgcb0W5U4TPxvuPAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 20:17:22
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.150.253.212 (212.253.150.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.150.253.212 (212.253.150.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 16:17:14.008875 2026] [security2:error] [pid 701:tid 701] [client 34.150.253.212:33226] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.bewdleypizza.com"] [uri "/@fs/app/.env"] [unique_id "ap8byvhNMqCEdtdnjZoVCgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
Octopuce
2026-09-07 20:11:07
(20 hours ago)
Aggressive web search of vulnerable pages: /_nuxt/../.env /v1/.env /.docker/.env /images../.env /.en ...
show more
Aggressive web search of vulnerable pages: /_nuxt/../.env /v1/.env /.docker/.env /images../.env /.env ...
show less
Web App Attack
🇬🇧
consul.to
2026-09-07 19:58:27
(20 hours ago)
Web attack/malicious scanning detected
Web App Attack
🇧🇪
cmbplf
2026-09-07 19:46:53
(20 hours ago)
632 requests with url.path *.aws/*
283 requests with url.path *.config/*
Brute-Force
Bad Web Bot
Anonymous
2026-09-07 19:28:58
(20 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-07 19:27:16
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.150.253.212 (212.253.150.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.150.253.212 (212.253.150.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 15:27:11.473643 2026] [security2:error] [pid 16268:tid 16268] [client 34.150.253.212:44434] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.instepdogobedience.com"] [uri "/@fs/src/.env"] [unique_id "ap8QDwDL4hlFb-4oyV05sAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 19:12:06
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.150.253.212 (212.253.150.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.150.253.212 (212.253.150.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 15:11:59.560099 2026] [security2:error] [pid 20599:tid 20599] [client 34.150.253.212:13734] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.ladylilacfarm.com"] [uri "/@fs/../.env"] [unique_id "ap8Mf3-LqjNPFuzR2yDR7wAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 18:31:42
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.150.253.212 (212.253.150.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.150.253.212 (212.253.150.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 14:31:34.464264 2026] [security2:error] [pid 29794:tid 29794] [client 34.150.253.212:11400] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "register-yacht-uk.com.yacht-register-holland.com"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252fapp/.env"] [unique_id "ap8DBqnx_DV4A8vI6DKHnwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
Aetherweb Ark
2026-09-07 18:06:31
(22 hours ago)
(mod_security) mod_security (id:949110) triggered by 34.150.253.212 (US/United States/212.253.150.34 ...
show more
(mod_security) mod_security (id:949110) triggered by 34.150.253.212 (US/United States/212.253.150.34.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 17:58:23
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.150.253.212 (212.253.150.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.150.253.212 (212.253.150.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 13:58:17.471895 2026] [security2:error] [pid 20422:tid 20422] [client 34.150.253.212:54396] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "baystarpartners.com"] [uri "/@fs/../../.env"] [unique_id "ap77OT-HB46Vyz27W2vDRgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
ConsulHosting
2026-09-07 17:53:14
(22 hours ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack
🇸🇪
vaia.cloud
2026-09-07 17:00:03
(23 hours ago)
crowdsecurity/http-path-traversal-probing
Brute-Force
Web App Attack
Anonymous
2026-09-07 16:42:04
(23 hours ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack