🇺🇸
TPI-Abuse
2026-09-08 10:46:14
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.153.192.56 (56.192.153.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.153.192.56 (56.192.153.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 06:46:10.252251 2026] [security2:error] [pid 9228:tid 9228] [client 34.153.192.56:49152] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "twccsolutions.com"] [uri "/@fs/src/.env"] [unique_id "ap_ncsFOuJrMAyTpeuRFMgAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 09:37:48
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.153.192.56 (56.192.153.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.153.192.56 (56.192.153.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 05:37:42.603905 2026] [security2:error] [pid 3327:tid 3327] [client 34.153.192.56:46584] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ferienwohnungen-eva.at"] [uri "/@fs/.env"] [unique_id "ap_XZjtntObcDHdvMs9r6AAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-08 08:20:12
(1 day ago)
Bot / seems abusive / Apache connections: 24
DDoS Attack
Web Spam
Bad Web Bot
Web App Attack
🇳🇿
Antinson
2026-09-08 08:16:27
(1 day ago)
Scraping with a high error ratio and request rate
Bad Web Bot
🇸🇪
vaia.cloud
2026-09-08 07:25:05
(1 day ago)
crowdsecurity/http-probing
Brute-Force
Web App Attack
🇺🇸
Power Ca
2026-09-08 06:55:44
(1 day ago)
34.153.192.56 - - [08/Sep/2026:06:55:32 +0000] "GET /@fs/..%252f..%252f..%252f..%252f..%252fproc/sel ...
show more
34.153.192.56 - - [08/Sep/2026:06:55:32 +0000] "GET /@fs/..%252f..%252f..%252f..%252f..%252fproc/self/environ?raw?? HTTP/2.0" 404 123 "-" "Mozilla/5.0 (compatible; Claude-User/1.0; [email protected] )"
34.153.192.56 - - [08/Sep/2026:06:55:32 +0000] "GET /@fs/app/rootkey.csv?raw?? HTTP/2.0" 404 123 "-" "Mozilla/5.0 (compatible; Claude-User/1.0; [email protected] )"
34.153.192.56 - - [08/Sep/2026:06:55:32 +0000] "GET /@fs/etc/passwd?raw?? HTTP/2.0" 404 123 "-" "Mozilla/5.0 (compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot)"
34.153.192.56 - - [08/Sep/2026:06:55:32 +0000] "GET /@fs/proc/self/environ?raw?? HTTP/2.0" 404 123 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; GPTBot/1.2; +https://openai.com/gptbot"
34.153.192.56 - - [08/Sep/2026:06:55:32 +0000] "GET /@fs/root/rootkey.csv?raw?? HTTP/2.0" 404 123 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Google-Extended/1.0; +http://www.google.com/bot.html)"
3
...
show less
Bad Web Bot
Web App Attack
🇨🇭
zynex
2026-09-08 06:33:26
(1 day ago)
URL Probing: /@fs/.env
Web App Attack
🇩🇪
FeG Deutschland
2026-09-08 06:17:15
(1 day ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 12
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 06:09:00
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.153.192.56 (56.192.153.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.153.192.56 (56.192.153.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 02:08:53.102600 2026] [security2:error] [pid 3015293:tid 3015293] [client 34.153.192.56:34570] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.midnightscribe.com"] [uri "/@fs/.env"] [unique_id "ap-mddnlTtFZSv2T2riVBQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
YF
2026-09-08 06:00:16
(1 day ago)
Distributed subnet attack — coordinated scanning from multiple IPs in the same /24
DDoS Attack
Web App Attack
🇫🇷
masterguru
2026-09-08 05:59:25
(1 day ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.153.192.56 (JP/Japan/56.192.153.34 ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.153.192.56 (JP/Japan/56.192.153.34.bc.googleusercontent.com): 2 in the last 3600 secs (0-196)
show less
Hacking
🇺🇸
TPI-Abuse
2026-09-08 05:51:59
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.153.192.56 (56.192.153.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.153.192.56 (56.192.153.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 01:51:53.491934 2026] [security2:error] [pid 19847:tid 19847] [client 34.153.192.56:39468] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.phoneresponse.com"] [uri "/@fs/.env"] [unique_id "ap-ieY273ix4HJnWFDnE9gAAACk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇦
polycoda
2026-09-08 05:14:42
(1 day ago)
AutoBlock: 🎯 Vulnerability Scanner (Non Decay-Based) - ❌ Excessive 40X Errors (Decay-Based)
Hacking
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 05:03:27
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.153.192.56 (56.192.153.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.153.192.56 (56.192.153.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 01:03:22.941343 2026] [security2:error] [pid 17345:tid 17345] [client 34.153.192.56:3770] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.haywardcarpentry.com"] [uri "/@fs/.env"] [unique_id "ap-XGucSEOENSx6glUTXuQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇪
cmbplf
2026-09-08 04:46:07
(1 day ago)
582 requests with url.path *.config/*
Brute-Force
Bad Web Bot