🇫🇷
masterguru
2026-09-04 03:33:15
(1 minute ago)
Restricted File Access Attempt. Matched phrase "/@fs/" at REQUEST_FILENAME. (930130-193)
Hacking
Web App Attack
🇳🇱
middelkoopcc
2026-09-04 02:46:01
(48 minutes ago)
2026-09-04 04:44:25 AH10244: invalid URI path (/@fs/../../.env?raw??) && 2026-09-04 04:44:30 AH10244 ...
show more
2026-09-04 04:44:25 AH10244: invalid URI path (/@fs/../../.env?raw??) && 2026-09-04 04:44:30 AH10244: invalid URI path (/@fs/../../../../../proc/self/environ?raw??) && 2026-09-04 04:44:30 AH10244: invalid URI path (/@fs/../../../../../root/.env?raw??) && 207 more within 20 minutes
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 02:19:22
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.182.135.212 (212.135.182.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.182.135.212 (212.135.182.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 22:19:18.483456 2026] [security2:error] [pid 2199:tid 2199] [client 34.182.135.212:42418] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.chrischamberlain.com"] [uri "/@fs/.env.staging"] [unique_id "apoqplTVkcPp7TTvYjj33AAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 01:41:23
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.182.135.212 (212.135.182.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.182.135.212 (212.135.182.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 21:41:16.677549 2026] [security2:error] [pid 10495:tid 10495] [client 34.182.135.212:16760] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.medusakenya.co.ke"] [uri "/@fs/.env.production"] [unique_id "apohvDdNUXSgE9Pj1RAzQwAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
NotCool
2026-09-04 01:38:19
(1 hour ago)
(CRAWLDELAY) Generic Bot Crawl-delay Violation 34.182.135.212 (US/United States/212.135.182.34.bc.go ...
show more
(CRAWLDELAY) Generic Bot Crawl-delay Violation 34.182.135.212 (US/United States/212.135.182.34.bc.googleusercontent.com): 50 in the last 3600 secs
show less
Bad Web Bot
🇬🇧
andypiper
2026-09-04 01:00:58
(2 hours ago)
CrowdSec ban for AbuseIPDB Top List
Brute-Force
Web App Attack
🇮🇹
CoreTech srl
2026-09-04 00:43:56
(2 hours ago)
cloudlinux2 fail2ban: 2026-09-04 02:39:40,265 fail2ban.filter [1472]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-09-04 02:39:40,265 fail2ban.filter [1472]: INFO [plesk-modsecurity] Found 34.182.135.212 - 2026-09-04 02:39:39cloudlinux2 fail2ban: 2026-09-04 02:39:40,209 fail2ban.filter [1472]: INFO [plesk-modsecurity] Found 34.182.135.212 - 2026-09-04 02:39:39cloudlinux2 fail2ban: 2026-09-04 02:39:40,391 fail2ban.actions [1472]: NOTICE [plesk-modsecurity] Ban 34.182.135.212cloudlinux2 fail2ban: 2026-09-04 02:39:40,248 fail2ban.filter [1472]: INFO [plesk-modsecurity] Found 34.182.135.212 - 2026-09-04 02:39:39cloudlinux2 fail2ban: 2026-09-04 02:39:40,281 fail2ban.filter [1472]: INFO [plesk-modsecurity] Found 34.182.135.212 - 2026-09-04 02:39:39cloudlinux2 fail2ban: 2026-09-04 02:39:40,217 fail2ban.filter [1472]: INFO [plesk-modsecurity] Found 34.182.135.212 - 2026-09-04 02:39:39cloudlinux2 fail2ban: 2026-09-04 02:39:40,239 fail2ban.filter [1472]: INFO [plesk-modsecurity] Found 34.182.135.212 - 2026-09-04 02:39:39cloudlinux2
show less
Brute-Force
🇩🇪
FeG Deutschland
2026-09-04 00:24:46
(3 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 1247
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 00:15:07
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.182.135.212 (212.135.182.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.182.135.212 (212.135.182.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 20:14:56.004344 2026] [security2:error] [pid 26672:tid 26672] [client 34.182.135.212:62218] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "powerbook.micahgartman.com"] [uri "/@fs/app/.env"] [unique_id "apoNgNqxCfiyd7Zy1SaHFwAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-03 23:56:43
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.182.135.212 (212.135.182.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.182.135.212 (212.135.182.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 19:56:37.664067 2026] [security2:error] [pid 22312:tid 22312] [client 34.182.135.212:16376] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.blindshine.com"] [uri "/@fs/root/.env"] [unique_id "apoJNUovCJDotb-d0a3aCwAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-03 23:34:15
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.182.135.212 (212.135.182.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.182.135.212 (212.135.182.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 19:34:09.636014 2026] [security2:error] [pid 9456:tid 9456] [client 34.182.135.212:10992] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.azbrooks.com"] [uri "/@fs/.env.development"] [unique_id "apoD8TLZOVhWpvUpknl9YQAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇪
cmbplf
2026-09-03 23:31:12
(4 hours ago)
8.016 requests from abuseipdb.com blacklisted IP (1yr1mo3w)
Brute-Force
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-03 22:59:17
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.182.135.212 (212.135.182.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.182.135.212 (212.135.182.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 18:59:10.366576 2026] [security2:error] [pid 29837:tid 29837] [client 34.182.135.212:51616] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.twixmixy.com"] [uri "/@fs/root/.env"] [unique_id "apn7vk0XfzV0S9lbVBJvTwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-03 22:35:38
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.182.135.212 (212.135.182.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.182.135.212 (212.135.182.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 18:35:33.962538 2026] [security2:error] [pid 5293:tid 5293] [client 34.182.135.212:52850] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.kitebeach.com"] [uri "/@fs/../.env"] [unique_id "apn2NYNWlcS_TGp0L47b1gAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-03 22:09:23
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.182.135.212 (212.135.182.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.182.135.212 (212.135.182.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 18:09:19.439164 2026] [security2:error] [pid 14008:tid 14008] [client 34.182.135.212:21428] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "andrewweigel.andrew.weigel.name"] [uri "/@fs/../.env"] [unique_id "apnwD_PXPmpDQHJ5AM-LegAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack