🇧🇪
cmbplf
2026-09-08 21:28:29
(10 hours ago)
2.008 requests with url.path */@fs/*
572 requests with url.path *.aws/*
197 requests with url.pat ...
show more
2.008 requests with url.path */@fs/*
572 requests with url.path *.aws/*
197 requests with url.path */proc/*
130 requests with url.path */auth.json
show less
Brute-Force
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-08 20:03:09
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.158.60.237 (237.60.158.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.158.60.237 (237.60.158.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 16:03:03.639180 2026] [security2:error] [pid 5666:tid 5666] [client 34.158.60.237:6808] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "eboredom.benlbrown.com"] [uri "/@fs/src/.env"] [unique_id "aqBp96K6vLAPgFoyGG2JVQAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
WellSpring
2026-09-08 19:50:36
(12 hours ago)
env leak on 309.today/@fs/home/ubuntu/.env — WellSpr.ing/NetSentinel civic-AI security layer
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 19:37:18
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.158.60.237 (237.60.158.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.158.60.237 (237.60.158.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 15:37:10.515656 2026] [security2:error] [pid 28841:tid 28841] [client 34.158.60.237:8658] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "joesteiner.com"] [uri "/@fs/.env.staging"] [unique_id "aqBj5kmzOenms156zpibXQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 19:21:32
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.158.60.237 (237.60.158.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.158.60.237 (237.60.158.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 15:21:26.729897 2026] [security2:error] [pid 9834:tid 9834] [client 34.158.60.237:28950] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jackierankin.com"] [uri "/@fs/root/.env"] [unique_id "aqBgNsjp6DaBawqjmZskRQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Trueforce Threat Report
2026-09-08 18:51:32
(13 hours ago)
Automated report, trolling for resource vulnerabilities
Bad Web Bot
Web App Attack
🇹🇼
ip4.tw
2026-09-08 17:49:01
(14 hours ago)
Malicious web scan
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 17:43:33
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.158.60.237 (237.60.158.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.158.60.237 (237.60.158.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 13:43:29.923275 2026] [security2:error] [pid 30166:tid 30166] [client 34.158.60.237:44714] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.shannonraevocalstudio.com"] [uri "/@fs/src/.env"] [unique_id "aqBJQTva_Ql6kWpQCpy45gAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 17:18:28
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.158.60.237 (237.60.158.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.158.60.237 (237.60.158.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 13:18:24.167718 2026] [security2:error] [pid 31631:tid 31631] [client 34.158.60.237:59758] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.senecaalumni.com"] [uri "/@fs/.env"] [unique_id "aqBDYFWEIhRSGkHlGhpeUgAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
lavnet.net
2026-09-08 17:11:57
(14 hours ago)
34.158.60.237 - - [08/Sep/2026:17:11:56 +0000] "GET /@fs/app/.env?raw?? HTTP/1.1" 404 727 "-" "Mozil ...
show more
34.158.60.237 - - [08/Sep/2026:17:11:56 +0000] "GET /@fs/app/.env?raw?? HTTP/1.1" 404 727 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; OAI-SearchBot/1.3; +https://openai.com/searchbot)"
34.158.60.237 - - [08/Sep/2026:17:11:56 +0000] "GET /@fs/root/.env?raw?? HTTP/1.1" 404 727 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/130.0.5502.203 Safari/537.36 Edg/130.0.5502.203; compatible; Claude-SearchBot/1.0; +https://www.anthropic.com/claude-searchbot"
34.158.60.237 - - [08/Sep/2026:17:11:56 +0000] "GET /@fs/etc/passwd?raw?? HTTP/1.1" 404 727 "-" "Mozilla/5.0 (compatible; Claude-User/1.0; +https://www.anthropic.com/claude-user)"
34.158.60.237 - - [08/Sep/2026:17:11:56 +0000] "GET /@fs/src/.env?raw?? HTTP/1.1" 404 727 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko; compatible; Bytespider; +https://zhanzhang.toutiao.com/) Chrome/109.0.4247.196 Safari/537.36"
34.158.60.237 - - [08/Sep/2026:17:11
...
show less
Brute-Force
🇩🇪
Bedios GmbH
2026-09-08 17:01:26
(14 hours ago)
Login credentials theft attempt
Hacking
🇺🇸
Rocky Mountain Bioengineering Symposium
2026-09-08 17:01:03
(14 hours ago)
[Tue Sep 08 11:01:03.604723 2026] [authz_core:error] [pid 131867:tid 139766129411648] [client 34.158 ...
show more
[Tue Sep 08 11:01:03.604723 2026] [authz_core:error] [pid 131867:tid 139766129411648] [client 34.158.60.237:41460] AH01630: client denied by server configuration: /var/www/horde/.env.swp
[Tue Sep 08 11:01:03.611765 2026] [authz_core:error] [pid 131736:tid 139766003652160] [client 34.158.60.237:41390] AH01630: client denied by server configuration: /var/www/horde/.env.bak
[Tue Sep 08 11:01:03.625335 2026] [authz_core:error] [pid 131605:tid 139765802096192] [client 34.158.60.237:41500] AH01630: client denied by server configuration: /var/www/horde/config/.env
...
show less
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-08 16:34:31
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.158.60.237 (237.60.158.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.158.60.237 (237.60.158.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 12:34:24.829919 2026] [security2:error] [pid 27651:tid 27651] [client 34.158.60.237:31124] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mattslivinski.com"] [uri "/@fs/root/.env"] [unique_id "aqA5EEAFaYTMHTSzeD4VUAAAAJI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-08 16:31:03
(15 hours ago)
Web application attack detected.
Web App Attack
🇳🇱
Site.eu
2026-09-08 16:28:43
(15 hours ago)
Excessive multi-domain requests
Brute-Force