Anonymous
2026-09-09 09:30:08
(3 minutes ago)
Multiple web server 400 error codes from same source ip
Web App Attack
🇩🇪
EGP Abuse Dept
2026-09-09 09:12:30
(21 minutes ago)
Scanning for web/db/file exploits on www.omegamechanix.nl
SQL Injection
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 08:45:23
(48 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.182.238.31 (31.238.182.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.182.238.31 (31.238.182.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 04:45:20.124783 2026] [security2:error] [pid 25168:tid 25168] [client 34.182.238.31:64224] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.jabamail.com"] [uri "/@fs/../../.env"] [unique_id "aqEcoBGmkv1utsqkjdVUdQAAACs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇸🇪
vaia.cloud
2026-09-09 08:10:02
(1 hour ago)
crowdsecurity/http-admin-interface-probing
Brute-Force
Web App Attack
🇫🇷
Octopuce
2026-09-09 08:09:03
(1 hour ago)
Aggressive web search of vulnerable pages: /img../.env /assets../.env /images../.env /.env /uploads. ...
show more
Aggressive web search of vulnerable pages: /img../.env /assets../.env /images../.env /.env /uploads../.env ...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 07:58:53
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.182.238.31 (31.238.182.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.182.238.31 (31.238.182.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 03:58:47.591514 2026] [security2:error] [pid 16756:tid 16784] [client 34.182.238.31:33494] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.ejspizzeriahudson.com"] [uri "/@fs/.env"] [unique_id "aqERt4G2eQhs_7oFotpt0wAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇦🇺
rubixstudios
2026-09-09 07:23:02
(2 hours ago)
Excessive HTTP requests consistent with automated attack behaviour detected by Imunify360
DDoS Attack
Brute-Force
Web App Attack
🇩🇪
gadix
2026-09-09 07:18:58
(2 hours ago)
[09/Sep/2026:09:18:58.031844 +0200] aqEIYqgHs9ohNnxO9dBtGAAAAAQ 34.182.238.31 47362 127.0.0.1 7081
[ ...
show more
[09/Sep/2026:09:18:58.031844 +0200] aqEIYqgHs9ohNnxO9dBtGAAAAAQ 34.182.238.31 47362 127.0.0.1 7081
[09/Sep/2026:09:18:58.033875 +0200] aqEIYgvXtLGp9XRv8bb53gAAAAE 34.182.238.31 47388 127.0.0.1 7081
[09/Sep/2026:09:18:58.042445 +0200] aqEIYk4VVsXIwBBjWaIMagAAAAo 34.182.238.31 47418 127.0.0.1 7081
...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 06:51:25
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.182.238.31 (31.238.182.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.182.238.31 (31.238.182.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 02:51:19.188043 2026] [security2:error] [pid 4549:tid 4549] [client 34.182.238.31:15424] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.lucid-hq.com"] [uri "/@fs/root/.env"] [unique_id "aqEB592zejSnggwZpKJIhAAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 06:28:18
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.182.238.31 (31.238.182.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.182.238.31 (31.238.182.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 02:28:14.398493 2026] [security2:error] [pid 3005:tid 3005] [client 34.182.238.31:20410] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.hangrypandas.com"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252froot/.env"] [unique_id "aqD8fvfGJ8NKBNfoUvYhUAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
COMAITE
2026-09-09 05:38:51
(3 hours ago)
Common web attack from 34.182.238.31.
Web App Attack
🇺🇸
agenciahypelab.com.br
2026-09-09 04:48:21
(4 hours ago)
WordPress login brute-force detectado e bloqueado pelo CSF/LFD. Trigger: LF_TRIGGER
Brute-Force
SSH
🇺🇸
TPI-Abuse
2026-09-09 04:47:40
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.182.238.31 (31.238.182.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.182.238.31 (31.238.182.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 00:47:34.911792 2026] [security2:error] [pid 14088:tid 14088] [client 34.182.238.31:38812] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.newlifeworshipcentre-gc.org"] [uri "/@fs/.env.local"] [unique_id "aqDk5rohIEI_nnGu-jj1ewAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 04:31:21
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.182.238.31 (31.238.182.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.182.238.31 (31.238.182.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 00:31:15.860661 2026] [security2:error] [pid 13661:tid 13661] [client 34.182.238.31:49704] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.gasoilliquidsdaily.com"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252froot/.env"] [unique_id "aqDhE433VHwH1arRBOk13gAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 04:02:00
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.182.238.31 (31.238.182.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.182.238.31 (31.238.182.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 00:01:56.739528 2026] [security2:error] [pid 23622:tid 23622] [client 34.182.238.31:34526] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.armandselmwoodpark.com"] [uri "/@fs/../.env"] [unique_id "aqDaNBn0qxd2Dicbt9_iBwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack