🇧🇪
cmbplf
2026-09-08 20:39:07
(2 hours ago)
2.535 requests with url.path */@fs/*
738 requests with url.path *.aws/*
Brute-Force
Bad Web Bot
🇬🇧
consul.to
2026-09-08 19:38:20
(3 hours ago)
Web attack/malicious scanning detected
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 19:28:46
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.153.222.9 (9.222.153.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.153.222.9 (9.222.153.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 15:28:37.728265 2026] [security2:error] [pid 11966:tid 11966] [client 34.153.222.9:47682] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thecalls.net"] [uri "/@fs/root/.env"] [unique_id "aqBh5dZpd4XcitQ22OblOgAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-08 19:17:54
(3 hours ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
🇷🇴
iulianh
2026-09-08 18:41:18
(4 hours ago)
80,443
Brute-Force
SSH
Anonymous
2026-09-08 18:30:33
(4 hours ago)
Web application attack detected.
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 17:52:23
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.153.222.9 (9.222.153.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.153.222.9 (9.222.153.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 13:52:16.950905 2026] [security2:error] [pid 28245:tid 28245] [client 34.153.222.9:42658] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "reconsideringfear.com"] [uri "/@fs/root/.env"] [unique_id "aqBLUI8wKSBGm5umqOcDZwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 17:36:16
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.153.222.9 (9.222.153.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.153.222.9 (9.222.153.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 13:36:12.227267 2026] [security2:error] [pid 20985:tid 20985] [client 34.153.222.9:58664] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.network22.net"] [uri "/@fs/app/.env"] [unique_id "aqBHjJRHhEMtNQZEpBgGXgAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
Octopuce
2026-09-08 15:39:41
(7 hours ago)
Aggressive web search of vulnerable pages: /v1/.env /v2/.env /.env.local /_nuxt/../.env /.env ...
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 15:32:58
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.153.222.9 (9.222.153.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.153.222.9 (9.222.153.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 11:32:50.973833 2026] [security2:error] [pid 7107:tid 7107] [client 34.153.222.9:11532] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.itaxcenter.com"] [uri "/@fs/.env"] [unique_id "aqAqooGJ1qPO8jgc8pGAOQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 14:56:00
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.153.222.9 (9.222.153.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.153.222.9 (9.222.153.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 10:55:54.585267 2026] [security2:error] [pid 23288:tid 23288] [client 34.153.222.9:43348] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.imaginationbyme.com"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252fapp/.env"] [unique_id "aqAh-pCxDgMP_OMPZKh__gAAADw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
VHosting
2026-09-08 14:55:03
(7 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
Anonymous
2026-09-08 14:12:26
(8 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking