🇧🇪
cmbplf
2026-09-08 20:53:14
(7 hours ago)
126 requests with url.path *.php.bak
Brute-Force
Bad Web Bot
Anonymous
2026-09-08 20:12:12
(8 hours ago)
Bot / seems abusive / Apache connections: 54
DDoS Attack
Web Spam
Bad Web Bot
Web App Attack
🇳🇱
middelkoopcc
2026-09-08 20:11:01
(8 hours ago)
2026-09-08 22:09:04 GET /@fs/root/.env?raw?? [404] && 2026-09-08 22:09:04 GET /@fs/app/.env?raw?? [4 ...
show more
2026-09-08 22:09:04 GET /@fs/root/.env?raw?? [404] && 2026-09-08 22:09:04 GET /@fs/app/.env?raw?? [404] && 2026-09-08 22:09:04 GET /@fs/..%252f..%252f..%252f..%252f..%252froot/.env?raw?? [404] && 222 more within 20 minutes
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 20:07:43
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.156.173.140 (140.173.156.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.156.173.140 (140.173.156.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 16:07:39.551578 2026] [security2:error] [pid 25289:tid 25289] [client 34.156.173.140:2124] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.cfabeachblvd.com"] [uri "/@fs/.env"] [unique_id "aqBrCwZe0iHcZceIc8zJFgAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-08 20:07:04
(8 hours ago)
Automated web scanner. Requested suspicious paths: /@fs/.env.production | /@fs/root/.aws/credentials ...
show more
Automated web scanner. Requested suspicious paths: /@fs/.env.production | /@fs/root/.aws/credentials | /@fs/..%252f..%252f..%252f..%252f..%252froot/.env | /@fs/home/ec2-user/.aws/credentials. UTC: 2026-09-08 19:51:02.
show less
Web App Attack
🇫🇷
dynamix
2026-09-08 19:40:28
(8 hours ago)
Multiple WAF Violations
Web App Attack
🇳🇱
e.fierstra
2026-09-08 19:36:10
(9 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
Anonymous
2026-09-08 19:25:03
(9 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 34.156.173.140 (BE/Belgium/140.173.156. ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.156.173.140 (BE/Belgium/140.173.156.34.bc.googleusercontent.com)
show less
SQL Injection
🇺🇸
TPI-Abuse
2026-09-08 19:08:40
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.156.173.140 (140.173.156.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.156.173.140 (140.173.156.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 15:08:35.849960 2026] [security2:error] [pid 5436:tid 5436] [client 34.156.173.140:45444] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.fibw.com"] [uri "/@fs/.env"] [unique_id "aqBdMzZBrcLr67ZLWzDdegAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇿🇦
conure.sh
2026-09-08 18:40:12
(9 hours ago)
csagent: score 20.0: secrets grab x2; 1 domain(s) in 7s
Web App Attack
Anonymous
2026-09-08 18:35:01
(10 hours ago)
suspicious request in access.log
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 18:29:33
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.156.173.140 (140.173.156.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.156.173.140 (140.173.156.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 14:29:29.016914 2026] [security2:error] [pid 2286:tid 2286] [client 34.156.173.140:4160] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.timberwolf-construction.com"] [uri "/@fs/src/.env"] [unique_id "aqBUCTKPoDPBHRqSr1N2KwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
ConsulHosting
2026-09-08 17:59:43
(10 hours ago)
Automatically blocked due to distributed attack
Hacking
🇺🇸
TPI-Abuse
2026-09-08 17:29:33
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.156.173.140 (140.173.156.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.156.173.140 (140.173.156.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 13:29:29.129056 2026] [security2:error] [pid 27813:tid 27829] [client 34.156.173.140:44874] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sandbarsteve.com"] [uri "/@fs/.env"] [unique_id "aqBF-fYrXkfFAzM4JKqx2QAAAMw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 16:26:20
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.156.173.140 (140.173.156.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.156.173.140 (140.173.156.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 12:26:14.519350 2026] [security2:error] [pid 10994:tid 11075] [client 34.156.173.140:28076] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.bullfrogsmusic.com"] [uri "/@fs/root/.env"] [unique_id "aqA3JrHYs8Qy7wu6-ml3aQAAARA"]
show less
Brute-Force
Bad Web Bot
Web App Attack