Anonymous
2026-09-07 03:57:11
(1 day ago)
34.169.82.44 - - [06/Sep/2026:10:07:44 -0500] "GET /.env?raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 (com ...
show more
34.169.82.44 - - [06/Sep/2026:10:07:44 -0500] "GET /.env?raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; YouBot/1.0; +https://you.com/bot)" 34.169.82.44
34.169.82.44 - - [06/Sep/2026:10:07:44 -0500] "GET /.env?import&raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; Google-Extended; +http://www.google.com/bot.html)" 34.169.82.44
34.169.82.44 - - [06/Sep/2026:10:07:44 -0500] "GET /.env?import&url&inline HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; ChatGLM-Spider/1.0; +https://zhipuai.cn/)" 34.169.82.44
34.169.82.44 - - [06/Sep/2026:10:07:44 -0500] "GET /.env.local?raw HTTP/1.1" 403 199 "-" "DuckAssistBot/1.1 (https://duckduckgo.com/duckassistbot)" 34.169.82.44
34.169.82.44 - - [06/Sep/2026:10:07:44 -0500] "GET /.env.local?import&raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; Bytespider; [email protected] ) AppleWebKit/537.36" 34.169.82.44
34.169.82.44 - - [06/Sep/2026:10:07:44 -0500] "GET /.env.production?raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 AppleWebKit/537.36
...
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 02:26:00
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.169.82.44 (44.82.169.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.169.82.44 (44.82.169.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 22:25:53.887722 2026] [security2:error] [pid 21709:tid 21709] [client 34.169.82.44:39220] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "teenybikinigirls.com"] [uri "/api/.env/public/.env"] [unique_id "ap4gsSIVW-s9hdt7XdO_9AAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 01:11:31
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.169.82.44 (44.82.169.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.169.82.44 (44.82.169.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 21:11:25.919449 2026] [security2:error] [pid 9457:tid 9457] [client 34.169.82.44:51392] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "northfultonneurology.com"] [uri "/%2E%2E/%2E%2E/%2E%2E/%2E%2E/.env"] [unique_id "ap4PPfdLwtTfmLjuxeLJGwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Savvii
2026-09-06 21:19:29
(1 day ago)
20 attempts against mh-misbehave-ban on ceres
Brute-Force
Bad Web Bot
Web App Attack
🇫🇮
Shaik Sai Meera
2026-09-06 21:15:11
(1 day ago)
IM360 WAF: Hidden file access
Brute-Force
Anonymous
2026-09-06 18:59:56
(1 day ago)
Multiple web server 400 error codes from same source ip
Web App Attack
🇨🇭
4server
2026-09-06 18:47:00
(1 day ago)
[SunSep0620:46:57.1538232026][security2:error][pid1830402:tid1830453][client34.169.82.44:0]ModSecuri ...
show more
[SunSep0620:46:57.1538232026][security2:error][pid1830402:tid1830453][client34.169.82.44:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".env\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"610\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"cpcontacts.swiss-domain-name.ch\"][uri\"/@fs/proc/self/cwd/.env\"][unique_id\"ap21IZbcTCHI77oLPeJyDgAAAZQ\"]
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 17:31:46
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.169.82.44 (44.82.169.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.169.82.44 (44.82.169.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 13:31:43.426971 2026] [security2:error] [pid 25617:tid 25617] [client 34.169.82.44:48156] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.onyxcc.com"] [uri "/%2E%2E/%2E%2E/%2E%2E/%2E%2E/.env"] [unique_id "ap2jfxQqUIOV33iT8am3_gAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇷🇴
clauss
2026-09-06 16:56:32
(1 day ago)
34.169.82.44 - - [06/Sep/2026:19:56:29 +0300] "GET /rclone.conf HTTP/2.0" 403 146 "-" "Mozilla/5.0 ( ...
show more
34.169.82.44 - - [06/Sep/2026:19:56:29 +0300] "GET /rclone.conf HTTP/2.0" 403 146 "-" "Mozilla/5.0 (compatible; KimiBot/1.0; +https://kimi.ai/)"
34.169.82.44 - - [06/Sep/2026:19:56:32 +0300] "GET /secrets.yml HTTP/2.0" 404 14099 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ChatGPT-User/1.0; +https://openai.com/bot)"
...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 14:51:27
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.169.82.44 (44.82.169.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.169.82.44 (44.82.169.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 10:51:23.025183 2026] [security2:error] [pid 2333:tid 2333] [client 34.169.82.44:52950] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.ralphharris.org"] [uri "/.env.js"] [unique_id "ap196_o2-Z2xtxi6INknFgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 14:27:25
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.169.82.44 (44.82.169.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.169.82.44 (44.82.169.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 10:27:19.664769 2026] [security2:error] [pid 20015:tid 20015] [client 34.169.82.44:58758] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.suralcopensioendesk.com"] [uri "/%2E%2E/%2E%2E/%2E%2E/%2E%2E/.env"] [unique_id "ap14R9LZAHGpt13dSsH25AAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 14:10:48
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 34.169.82.44 (44.82.169.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.169.82.44 (44.82.169.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 10:10:44.810704 2026] [security2:error] [pid 5758:tid 5758] [client 34.169.82.44:35316] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||qcyprus.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "qcyprus.com"] [uri "/rclone.conf"] [unique_id "ap10ZO7DzygaDE7axwhdOQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 13:50:06
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 34.169.82.44 (44.82.169.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.169.82.44 (44.82.169.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 09:49:57.713003 2026] [security2:error] [pid 28963:tid 28963] [client 34.169.82.44:41094] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||takeapawsboston.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "takeapawsboston.com"] [uri "/z9x8c7v6b5-debug-trigger-takeapawsboston.com"] [unique_id "ap1vhVN1ie9SJ-yzOwhhTAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 13:02:29
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 34.169.82.44 (44.82.169.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.169.82.44 (44.82.169.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 09:02:21.730999 2026] [security2:error] [pid 26031:tid 26031] [client 34.169.82.44:37778] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||www.stbms.com|F|2"] [data ".stbms.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.stbms.com"] [uri "/z9x8c7v6b5-debug-trigger-www.stbms.com"] [unique_id "ap1kXaoF0dPlv9VWuyi-XwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 12:41:26
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 34.169.82.44 (44.82.169.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.169.82.44 (44.82.169.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 08:41:20.459119 2026] [security2:error] [pid 13136:tid 13136] [client 34.169.82.44:51584] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||sellitwithsteve.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "sellitwithsteve.com"] [uri "/z9x8c7v6b5-debug-trigger-sellitwithsteve.com"] [unique_id "ap1fcEyc0bqMgJMLUamfkAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack