Anonymous
2026-09-03 22:39:20
(14 minutes ago)
Aggressive web scan
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-03 22:30:09
(24 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.178.72.6 (6.72.178.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.178.72.6 (6.72.178.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 18:30:01.833196 2026] [security2:error] [pid 1884174:tid 1884210] [client 34.178.72.6:9454] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.daviscountyossr.org"] [uri "/@fs/root/.env"] [unique_id "apn06e0JGMRJeDczWepZkwAAAM4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
e.fierstra
2026-09-03 22:25:59
(28 minutes ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
π§π·
Halux
2026-09-03 21:48:24
(1 hour ago)
34.178.72.6 Web Application Firewall multiple violations
Hacking
Web App Attack
π©πͺ
Hazzard
2026-09-03 21:22:16
(1 hour ago)
(mod_security) mod_security triggered on hostname [redacted]): (CF_ENABLE)
SQL Injection
π¬π§
consul.to
2026-09-03 21:09:25
(1 hour ago)
Web attack/malicious scanning detected
Web App Attack
πΈπͺ
konseptit
2026-09-03 20:39:06
(2 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 34.178.72.6 (6.72.178.34.bc.googleuserc ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.178.72.6 (6.72.178.34.bc.googleusercontent.com)
show less
SQL Injection
π΅π±
TaKeN
2026-09-03 20:38:35
(2 hours ago)
Automated Wazuh local observation. Wazuh rule 31151 lvl=10 detected repeated HTTP web application pr ...
show more
Automated Wazuh local observation. Wazuh rule 31151 lvl=10 detected repeated HTTP web application probing from this source IP. Observed 4 matching blocked event(s) between 2026-09-03T22:38:35+02:00 and 2026-09-03T22:38:35+02:00. Sample requested paths: /@fs/app/rootkey.csv, /@fs/var/www/.aws/credentials, /@fs/.env.production, /@fs/home/admin/.aws/credentials.
show less
Web App Attack
Hacking
πΈπͺ
vaia.cloud
2026-09-03 20:35:02
(2 hours ago)
crowdsecurity/http-probing
Brute-Force
Web App Attack
π©πͺ
initsol
2026-09-03 20:07:07
(2 hours ago)
[Thu Sep 03 22:07:02.276887 2026] [authz_core:error] [pid 1785466:tid 1785466] [client 34.178.72.6:2 ...
show more
[Thu Sep 03 22:07:02.276887 2026] [authz_core:error] [pid 1785466:tid 1785466] [client 34.178.72.6:23890] AH01630: client denied by server configuration: /var/www/
[Thu Sep 03 22:07:06.419807 2026] [authz_core:error] [pid 1785465:tid 1785465] [client 34.178.72.6:23922] AH01630: client denied by server configuration: /var/www/@fs
[Thu Sep 03 22:07:06.420092 2026] [authz_core:error] [pid 1785469:tid 1785469] [client 34.178.72.6:23970] AH01630: client denied by server configuration: /var/www/.env
...
show less
Brute-Force
πΊπΈ
TPI-Abuse
2026-09-03 19:58:30
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.178.72.6 (6.72.178.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.178.72.6 (6.72.178.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 15:58:25.790901 2026] [security2:error] [pid 11370:tid 11370] [client 34.178.72.6:62704] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.motioncontrolpartners.com"] [uri "/@fs/.env"] [unique_id "apnRYXh_n0CfMfPXV-TPjwAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-03 19:43:08
(3 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
π³π±
Site.eu
2026-09-03 19:41:45
(3 hours ago)
Excessive 404/403 errors
Brute-Force
π«π·
Octopuce
2026-09-03 19:38:37
(3 hours ago)
Aggressive web search of vulnerable pages: /_nuxt/../.env /uploads../.env /img../.env /assets../.env ...
show more
Aggressive web search of vulnerable pages: /_nuxt/../.env /uploads../.env /img../.env /assets../.env /v2/.env ...
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-03 19:24:33
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.178.72.6 (6.72.178.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.178.72.6 (6.72.178.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 15:24:26.364644 2026] [security2:error] [pid 26217:tid 26217] [client 34.178.72.6:28856] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "newcitypark.com"] [uri "/@fs/app/.env"] [unique_id "apnJapw3CN2WmD6cG9sIeQAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack