🇺🇸
TPI-Abuse
2026-09-08 08:11:06
(19 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.16.219.43 (43.219.16.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.16.219.43 (43.219.16.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 04:10:59.185248 2026] [security2:error] [pid 6855:tid 6855] [client 34.16.219.43:13570] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.lakehousegraphics.net"] [uri "/@fs/app/.env"] [unique_id "ap_DE1FRkVwPDO0n222SjAAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
mnsf
2026-09-08 08:05:54
(24 minutes ago)
Scanning/Probing (25)
Brute-Force
Web App Attack
🇳🇱
BlueWire Hosting
2026-09-08 07:12:55
(1 hour ago)
High-confidence malicious configuration/VCS probe
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 07:02:05
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.16.219.43 (43.219.16.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.16.219.43 (43.219.16.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 03:02:02.029649 2026] [security2:error] [pid 26417:tid 26417] [client 34.16.219.43:24210] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.tigerallenyim.com"] [uri "/@fs/.env.development"] [unique_id "ap-y6tDF0hnDfmdfGd6eBQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
e.fierstra
2026-09-08 06:40:47
(1 hour ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 06:29:45
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.16.219.43 (43.219.16.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.16.219.43 (43.219.16.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 02:29:40.083389 2026] [security2:error] [pid 24296:tid 24296] [client 34.16.219.43:62924] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.pizazzsalonandspa.com"] [uri "/@fs/root/.env"] [unique_id "ap-rVE36SncO0U49Ts_UYwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
Octopuce
2026-09-08 05:59:46
(2 hours ago)
Aggressive web search of vulnerable pages: /_nuxt/../.env /img../.env /admin/.env /v2/.env /.env .. ...
show more
Aggressive web search of vulnerable pages: /_nuxt/../.env /img../.env /admin/.env /v2/.env /.env ...
show less
Web App Attack
🇩🇪
Gwyneth Llewelyn
2026-09-08 05:51:46
(2 hours ago)
2026/09/08 06:51:44 [error] 380594#380594: *3613277 access forbidden by rule, client: 34.16.219.43, ...
show more
2026/09/08 06:51:44 [error] 380594#380594: *3613277 access forbidden by rule, client: 34.16.219.43, server: lisbon-pre-1755-earthquake.org, request: "GET /images../.env HTTP/2.0", host: "lisbon-pre-1755-earthquake.org"
2026/09/08 06:51:44 [error] 380594#380594: *3613277 access forbidden by rule, client: 34.16.219.43, server: lisbon-pre-1755-earthquake.org, request: "GET /img../.env HTTP/2.0", host: "lisbon-pre-1755-earthquake.org"
2026/09/08 06:51:45 [error] 380594#380594: *3613236 access forbidden by rule, client: 34.16.219.43, server: lisbon-pre-1755-earthquake.org, request: "GET /app/.env HTTP/2.0", host: "lisbon-pre-1755-earthquake.org"
show less
Brute-Force
Web App Attack
🇳🇱
Site.eu
2026-09-08 05:18:20
(3 hours ago)
Excessive multi-domain requests
Brute-Force
🇬🇧
consul.to
2026-09-08 05:07:29
(3 hours ago)
Web attack/malicious scanning detected
Web App Attack
🇺🇸
IndigoRidge
2026-09-08 05:05:19
(3 hours ago)
34.16.219.43 - - [08/Sep/2026:01:05:19 -0400] "GET /@fs/.env?raw?? HTTP/1.1" 301 4965 "-" "Mozilla/5 ...
show more
34.16.219.43 - - [08/Sep/2026:01:05:19 -0400] "GET /@fs/.env?raw?? HTTP/1.1" 301 4965 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ChatGPT-User/1.0; +https://openai.com/bot)"
34.16.219.43 - - [08/Sep/2026:01:05:19 -0400] "GET /@fs/root/.env?raw?? HTTP/1.1" 301 4975 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; GrokBot/1.0; +https://x.ai/grokbot)"
34.16.219.43 - - [08/Sep/2026:01:05:19 -0400] "GET /@fs/src/.env?raw?? HTTP/1.1" 301 4973 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; TelegramBot/1.0"
...
show less
Web App Attack
Anonymous
2026-09-08 04:56:08
(3 hours ago)
Blocked by ModSec and CSF
Port Scan
🇨🇭
zynex
2026-09-08 04:46:40
(3 hours ago)
URL Probing: /@fs/root/.env
Web App Attack
🇫🇷
masterguru
2026-09-08 04:25:34
(4 hours ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.16.219.43 (US/United States/43.219 ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.16.219.43 (US/United States/43.219.16.34.bc.googleusercontent.com): 1 in the last 3600 secs (0-195)
show less
Hacking
🇺🇸
TPI-Abuse
2026-09-08 04:08:50
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.16.219.43 (43.219.16.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.16.219.43 (43.219.16.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 00:08:46.242484 2026] [security2:error] [pid 14607:tid 14607] [client 34.16.219.43:49078] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.balivisaservice.com"] [uri "/@fs/src/.env"] [unique_id "ap-KTjPOsY6VYkLiMy4-tQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack