🇺🇸
TPI-Abuse
2026-09-09 10:59:58
(44 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.187.49.69 (69.49.187.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.187.49.69 (69.49.187.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 06:59:53.960521 2026] [security2:error] [pid 29459:tid 29459] [client 34.187.49.69:58354] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.clubfansite.com"] [uri "/@fs/.env.local"] [unique_id "aqE8KSJnLLByZqgKuDxkXgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-09-09 10:42:20
(1 hour ago)
Web attack/malicious scanning detected
Web App Attack
🇦🇺
aranguren.org
2026-09-09 09:41:40
(2 hours ago)
34.187.49.69 - - [09/Sep/2026:19:41:40 +1000] "GET /@fs/.env.local?raw?? HTTP/1.1" 404 985 "-" "Mozi ...
show more
34.187.49.69 - - [09/Sep/2026:19:41:40 +1000] "GET /@fs/.env.local?raw?? HTTP/1.1" 404 985 "-" "Mozilla/5.0 (Linux; Android 15; SM-S918B) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/130.0.7643.143 Mobile Safari/537.36; compatible; Claude-SearchBot/1.0; +https://www.anthropic.com/claude-searchbot"
34.187.49.69 - - [09/Sep/2026:19:41:40 +1000] "GET /@fs/.env?raw?? HTTP/1.1" 404 985 "-" "Mozilla/5.0 (Windows NT 11.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko; compatible; facebookexternalhit/1.1; +http://www.facebook.com/externalhit_uatext.php) Chrome/148.0.551.167 Safari/537.36"
34.187.49.69 - - [09/Sep/2026:19:41:40 +1000] "GET /@fs/root/rootkey.csv?raw?? HTTP/1.1" 404 985 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko; compatible; Google-Extended/1.0; +http://www.google.com/bot.html) Chrome/133.0.755.124 Safari/537.36"
34.187.49.69 - - [09/Sep/2026:19:41:40 +1000] "GET /@fs/../.env?raw?? HTTP/1.1" 404 985 "-" "Mozilla/5.0 (compatible
...
show less
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-09 09:37:01
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.187.49.69 (69.49.187.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.187.49.69 (69.49.187.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 05:36:57.232469 2026] [security2:error] [pid 4294:tid 4294] [client 34.187.49.69:6296] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cuisine.gevieworld.com"] [uri "/@fs/.env.production"] [unique_id "aqEouR0OCoBOQb7SUPFClAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 08:23:27
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.187.49.69 (69.49.187.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.187.49.69 (69.49.187.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 04:23:23.105079 2026] [security2:error] [pid 468:tid 468] [client 34.187.49.69:47468] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.genesis-group.net"] [uri "/@fs/.env"] [unique_id "aqEXe8QNQHGeAwnIINBtmwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
FD-IX
2026-09-09 08:10:45
(3 hours ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 08:08:16
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.187.49.69 (69.49.187.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.187.49.69 (69.49.187.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 04:08:08.227102 2026] [security2:error] [pid 7810:tid 7810] [client 34.187.49.69:60564] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.firstunitedreserve.com"] [uri "/@fs/app/.env"] [unique_id "aqET6DyblRUHqwSxAPmBYwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
SCHAPPY
2026-09-09 08:05:14
(3 hours ago)
Brute-force attack to non-existent web resources, HTTP code 404.
Brute-Force
Web App Attack
Anonymous
2026-09-09 07:10:26
(4 hours ago)
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: NL, Attack patterns: Word ...
show more
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: NL, Attack patterns: WordPress scanning, Backup file probing, Cloud secrets probing
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 06:51:37
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.187.49.69 (69.49.187.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.187.49.69 (69.49.187.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 02:51:32.713066 2026] [security2:error] [pid 29329:tid 29329] [client 34.187.49.69:33222] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tools.alitcogroup.com"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252froot/.env"] [unique_id "aqEB9LnHSiphkbjuqJXQiwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇾
lns.bz
2026-09-09 06:22:47
(5 hours ago)
Too many 404 requests [BY]
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 05:56:43
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.187.49.69 (69.49.187.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.187.49.69 (69.49.187.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 01:56:37.962495 2026] [security2:error] [pid 17717:tid 17717] [client 34.187.49.69:36554] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.modestosoftwater.net"] [uri "/@fs/src/.env"] [unique_id "aqD1FXb5tQGSyrBy30PR1AAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇸🇪
vaia.cloud
2026-09-09 05:40:02
(6 hours ago)
crowdsecurity/http-probing
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 05:30:09
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.187.49.69 (69.49.187.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.187.49.69 (69.49.187.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 01:30:03.449032 2026] [security2:error] [pid 23270:tid 23270] [client 34.187.49.69:31548] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "morleysales.com"] [uri "/@fs/../../.env"] [unique_id "aqDu21hP6fnoI_WV_ByCQwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇭
backslash
2026-09-09 04:48:01
(6 hours ago)
block ruleset WAF detection and high score on abuseIPDB 149EB1B42C242111FADBBC2EF8F90219570691E1
Bad Web Bot