Anonymous
2026-09-08 06:10:43
(25 minutes ago)
Malicious activity detected
DDoS Attack
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 05:48:08
(48 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.158.60.234 (234.60.158.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.158.60.234 (234.60.158.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 01:48:03.896260 2026] [security2:error] [pid 8740:tid 8740] [client 34.158.60.234:60756] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.efgenios.com"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252froot/.env"] [unique_id "ap-hk4H1I07Vm0cYW-d9YQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇪
cmbplf
2026-09-08 05:01:30
(1 hour ago)
27.909 requests from untrusted country (2w6d4h)
Brute-Force
Bad Web Bot
🇳🇱
maxxsense
2026-09-08 04:57:27
(1 hour ago)
(mod_security) mod_security triggered on hostname [redacted] 34.158.60.234 (SG/Singapore/234.60.158. ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.158.60.234 (SG/Singapore/234.60.158.34.bc.googleusercontent.com)
show less
SQL Injection
🇳🇱
Mangelot Hosting
2026-09-08 04:47:14
(1 hour ago)
(modsecurity) srv104 ModSecurity 34.158.60.234 (SG/Singapore/234.60.158.34.bc.googleusercontent.com) ...
show more
(modsecurity) srv104 ModSecurity 34.158.60.234 (SG/Singapore/234.60.158.34.bc.googleusercontent.com): 30 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
🇫🇷
LRNP
2026-09-08 04:29:49
(2 hours ago)
mirror2.urbanterror.info:443 34.158.60.234 - - [08/Sep/2026:04:29:49 +0000] "GET /@fs/app/.env?raw?? ...
show more
mirror2.urbanterror.info:443 34.158.60.234 - - [08/Sep/2026:04:29:49 +0000] "GET /@fs/app/.env?raw?? HTTP/1.1" 404 181 "-" "Mozilla/5.0 (Linux; Android 14; Pixel 8) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.7697.227 Mobile Safari/537.36; compatible; Claude-User/1.0; +https://www.anthropic.com/claude-user"
mirror2.urbanterror.info:443 34.158.60.234 - - [08/Sep/2026:04:29:49 +0000] "GET /@fs/..%252f..%252f..%252f..%252f..%252froot/.env?raw?? HTTP/1.1" 404 181 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_0 like Mac OS X) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.1073.154 Mobile Safari/537.36; compatible; Amzn-SearchBot/1.0; +https://developer.amazon.com/support/amazonbot"
mirror2.urbanterror.info:443 34.158.60.234 - - [08/Sep/2026:04:29:49 +0000] "GET /@fs/root/.aws/config?raw?? HTTP/1.1" 404 181 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14_6_1) AppleWebKit/537.36 (KHTML, like Gecko; compatible; TelegramBot/1.0) Chrome/118.0.6709.239 Safari/537.36"
mirror2.urbanterror.
...
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 04:25:01
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.158.60.234 (234.60.158.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.158.60.234 (234.60.158.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 00:24:53.651603 2026] [security2:error] [pid 2902847:tid 2902847] [client 34.158.60.234:4678] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.compassionfatigue.org"] [uri "/@fs/../.env"] [unique_id "ap-OFXFXDn3JJOzBXFLP1AAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Site.eu
2026-09-08 04:21:02
(2 hours ago)
Excessive multi-domain requests
Brute-Force
🇺🇸
TPI-Abuse
2026-09-08 04:04:50
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.158.60.234 (234.60.158.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.158.60.234 (234.60.158.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 00:04:45.946742 2026] [security2:error] [pid 17532:tid 17532] [client 34.158.60.234:7762] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.grandersonheatingandcooling.com"] [uri "/@fs/.env"] [unique_id "ap-JXcHqyk7y-r1TrNKYvQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
dynamix
2026-09-08 03:36:42
(2 hours ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 03:13:37
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.158.60.234 (234.60.158.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.158.60.234 (234.60.158.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 23:13:33.394075 2026] [security2:error] [pid 28146:tid 28146] [client 34.158.60.234:18918] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.bella-vista.com"] [uri "/@fs/.env.production"] [unique_id "ap99XX7DAhGmJ-qbDTe3UgAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
e.fierstra
2026-09-08 02:46:50
(3 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
Anonymous
2026-09-08 02:29:18
(4 hours ago)
Multiple web server 400 error codes from same source ip
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 02:25:50
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.158.60.234 (234.60.158.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.158.60.234 (234.60.158.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 22:25:45.503692 2026] [security2:error] [pid 31403:tid 31403] [client 34.158.60.234:65368] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.cashforjunkcars.info"] [uri "/@fs/../.env"] [unique_id "ap9yKTJtlUwiJJOZDN_dgAAAAGk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Savvii
2026-09-08 01:58:34
(4 hours ago)
20 attempts against mh-misbehave-ban on redirect
Brute-Force
Bad Web Bot
Web App Attack