Anonymous
2026-09-05 10:55:00
(4 hours ago)
Excessive crawling/scraping. Vulnerable file probing.
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
middelkoopcc
2026-09-04 16:08:01
(23 hours ago)
2026-09-04 18:06:02 GET /@fs/root/.env?raw?? [404] && 2026-09-04 18:06:05 AH01071: Got error 'Primar ...
show more
2026-09-04 18:06:02 GET /@fs/root/.env?raw?? [404] && 2026-09-04 18:06:05 AH01071: Got error 'Primary script unknown', referer https://mail.uitvaartauto.nl/config.php && 2026-09-04 18:06:05 AH01071: Got error 'Primary script unknown', referer https://mail.uitvaartauto.nl/wp-config.php && 219 more within 20 minutes
show less
Web App Attack
🇧🇪
voormedia
2026-09-04 14:59:02
(1 day ago)
Accessed trap at '/.env'
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 14:41:50
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.16.184.179 (179.184.16.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.16.184.179 (179.184.16.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 10:41:44.779174 2026] [security2:error] [pid 28021:tid 28021] [client 34.16.184.179:32772] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.jerusalem-korczak-home.com"] [uri "/@fs/root/.env"] [unique_id "aprYqLOy0K9HIUGUWqbDpwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 14:04:44
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.16.184.179 (179.184.16.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.16.184.179 (179.184.16.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 10:04:37.143388 2026] [security2:error] [pid 20590:tid 20590] [client 34.16.184.179:6588] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.technologymoods.com"] [uri "/@fs/root/.env"] [unique_id "aprP9ZT8FqhXwwHe58Dx3wAAAC8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
Starburst SysOp Team
2026-09-04 12:24:45
(1 day ago)
BAD BOT, BAD BOT, WHAT YA GONNA DO - Detected and Blocked.. Matched phrase "ClaudeBot" at REQUEST_HE ...
show more
BAD BOT, BAD BOT, WHAT YA GONNA DO - Detected and Blocked.. Matched phrase "ClaudeBot" at REQUEST_HEADERS:User-Agent. (1100000-mnz6-1)
show less
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-04 11:12:29
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.16.184.179 (179.184.16.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.16.184.179 (179.184.16.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 07:12:21.376620 2026] [security2:error] [pid 2091:tid 2091] [client 34.16.184.179:32060] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.apiceasttexas.com"] [uri "/@fs/root/.env"] [unique_id "apqnlYYKnHJQIWudKnR7KgAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇭
dalslab ltd
2026-09-04 10:55:42
(1 day ago)
[04/Sep/2026:12:55:41 +0200] - 404 404 - GET https nc.dalslab.com "/@fs/..%252f..%252f..%252f..%252f ...
show more
[04/Sep/2026:12:55:41 +0200] - 404 404 - GET https nc.dalslab.com "/@fs/..%252f..%252f..%252f..%252f..%252fproc/self/environ?raw??" [Client 34.16.184.179] [Length 1846] [Gzip -] [Sent-to 10.1.1.253] "Mozilla/5.0 (Macintosh; Intel Mac OS X 14_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.663.201 Safari/537.36; compatible; Claude-User/1.0; +https://www.anthropic.com/claude-user" "-"
[04/Sep/2026:12:55:41 +0200] - 404 404 - GET https nc.dalslab.com "/@fs/..%252f..%252f..%252f..%252f..%252froot/.env?raw??" [Client 34.16.184.179] [Length 1843] [Gzip -] [Sent-to 10.1.1.253] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.3249.94 Safari/537.36 Edg/91.0.3249.94; compatible; ChatGPT-User/1.0; +https://openai.com/bot" "-"
[04/Sep/2026:12:55:41 +0200] - 404 404 - GET https nc.dalslab.com "/@fs/.env.production?raw??" [Client 34.16.184.179] [Length 1843] [Gzip -] [Sent-to 10.1.1.253] "Mozilla/5.0 (Linux; Android 15; SM-S918B) AppleWebKit/
...
show less
Web Spam
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Gwyneth Llewelyn
2026-09-04 10:07:00
(1 day ago)
2026/09/04 11:06:58 [error] 380595#380595: *2758950 access forbidden by rule, client: 34.16.184.179, ...
show more
2026/09/04 11:06:58 [error] 380595#380595: *2758950 access forbidden by rule, client: 34.16.184.179, server: [redacted], request: "GET /uploads../.env HTTP/1.1", host: "[redacted]"
2026/09/04 11:06:58 [error] 380594#380594: *2758949 access forbidden by rule, client: 34.16.184.179, server: [redacted], request: "GET /_nuxt/../.env HTTP/1.1", host: "[redacted]"
2026/09/04 11:06:58 [error] 380595#380595: *2758951 access forbidden by rule, client: 34.16.184.179, server: [redacted], request: "GET /img../.env HTTP/1.1", host: "[redacted]"
show less
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 09:09:56
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.16.184.179 (179.184.16.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.16.184.179 (179.184.16.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 05:09:47.784659 2026] [security2:error] [pid 32303:tid 32303] [client 34.16.184.179:5872] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.jewishventura.org"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252froot/.env"] [unique_id "apqK2y0bFjL5U7yumacMVQAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 07:57:38
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.16.184.179 (179.184.16.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.16.184.179 (179.184.16.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 03:57:31.263951 2026] [security2:error] [pid 22862:tid 22862] [client 34.16.184.179:24358] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.diselet.com"] [uri "/@fs/.env.staging"] [unique_id "app56x6lavJLBRzGXxWivgAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-04 07:30:32
(1 day ago)
34.16.184.179 - - [04/Sep/2026:07:30:32 +0000] "GET /@fs/../../.env?raw?? HTTP/1.1" 400 602 "-" "Moz ...
show more
34.16.184.179 - - [04/Sep/2026:07:30:32 +0000] "GET /@fs/../../.env?raw?? HTTP/1.1" 400 602 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko; compatible; Twitterbot/1.0) Chrome/85.0.2968.162 Safari/537.36 Edg/85.0.2968.162"
...
show less
Bad Web Bot
Web App Attack
🇧🇪
madeit
2026-09-04 07:13:03
(1 day ago)
Web App Attack
🇪🇸
alferez
2026-09-04 06:57:13
(1 day ago)
Searching .(env|sql|zip|tar|rar) files
Hacking
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 05:36:21
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.16.184.179 (179.184.16.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.16.184.179 (179.184.16.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 01:36:14.241768 2026] [security2:error] [pid 33600:tid 33600] [client 34.16.184.179:62618] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.francisfindings.com"] [uri "/@fs/app/.env"] [unique_id "appYztYpDKT7qDeYQ1ILZQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack