🇳🇱
BlueWire Hosting
2026-09-07 20:38:07
(2 hours ago)
Bad bot ignoring robot.txt
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-07 20:08:36
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.16.241.61 (61.241.16.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.16.241.61 (61.241.16.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 16:08:31.269175 2026] [security2:error] [pid 29649:tid 29649] [client 34.16.241.61:8912] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.player-care.com"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252fapp/.env"] [unique_id "ap8Zv_5XVi2Kd8VCL5h-3wAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 19:42:28
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.16.241.61 (61.241.16.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.16.241.61 (61.241.16.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 15:42:24.406572 2026] [security2:error] [pid 4759:tid 4759] [client 34.16.241.61:49088] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.debzy.com"] [uri "/@fs/../.env"] [unique_id "ap8ToBtVb2mlYQSLNEkp3QAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
dynamix
2026-09-07 19:27:18
(4 hours ago)
Multiple WAF Violations
Web App Attack
🇫🇷
Octopuce
2026-09-07 19:23:57
(4 hours ago)
Aggressive web search of vulnerable pages: /_nuxt/../.env /uploads../.env /img../.env /.docker/.env ...
show more
Aggressive web search of vulnerable pages: /_nuxt/../.env /uploads../.env /img../.env /.docker/.env /assets../.env ...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 19:17:14
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.16.241.61 (61.241.16.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.16.241.61 (61.241.16.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 15:17:07.482567 2026] [security2:error] [pid 30678:tid 30678] [client 34.16.241.61:21978] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.launderpet.com"] [uri "/@fs/.env"] [unique_id "ap8Ns0vU9V7B9Q8_1arILAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
mnsf
2026-09-07 19:05:32
(4 hours ago)
Scanning/Probing (12)
Brute-Force
Web App Attack
🇩🇪
iNetWorker
2026-09-07 18:54:55
(4 hours ago)
trolling for resource vulnerabilities
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 18:53:59
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.16.241.61 (61.241.16.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.16.241.61 (61.241.16.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 14:53:54.143108 2026] [security2:error] [pid 7665:tid 7665] [client 34.16.241.61:48568] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "carra.org"] [uri "/@fs/.env"] [unique_id "ap8IQuLpH85K21tWnrIzqAAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
ConsulHosting
2026-09-07 18:21:07
(5 hours ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack
🇬🇧
consul.to
2026-09-07 17:50:38
(5 hours ago)
Web attack/malicious scanning detected
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 17:11:40
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.16.241.61 (61.241.16.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.16.241.61 (61.241.16.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 13:11:32.437485 2026] [security2:error] [pid 1775944:tid 1775969] [client 34.16.241.61:21748] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.sellarsmail.com"] [uri "/@fs/.env.local"] [unique_id "ap7wROU9S6JaZtNkXKqQdAAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
debestelapp
2026-09-07 17:10:12
(6 hours ago)
Web App Attack
🇧🇪
cmbplf
2026-09-07 16:58:02
(6 hours ago)
214 requests with url.path *config.json
108 requests with url.path *.ssh/*
Brute-Force
Bad Web Bot
🇩🇪
netclix.gr
2026-09-07 16:39:14
(6 hours ago)
(security_scan) Sensitive File Scan Blocked 34.16.241.61 (US/United States/61.241.16.34.bc.googleuse ...
show more
(security_scan) Sensitive File Scan Blocked 34.16.241.61 (US/United States/61.241.16.34.bc.googleusercontent.com): 1 in the last 4600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 34.16.241.61 - - [07/Sep/2026:19:39:12 +0300] "GET /@fs/../../.env?raw?? HTTP/1.1" 400 150 "-" "-"
show less
Port Scan