🇺🇸
TPI-Abuse
2026-09-04 16:53:41
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.21.155.120 (120.155.21.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.21.155.120 (120.155.21.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 12:53:36.259096 2026] [security2:error] [pid 28598:tid 28598] [client 34.21.155.120:61270] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.lunchtimers.org"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252froot/.env"] [unique_id "apr3kLqitFovVZ6mYb5JUAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇦🇹
penguin-solutions.at
2026-09-04 15:27:45
(2 days ago)
Excessive 403/404 errors
...
Brute-Force
Web App Attack
🇩🇪
bescared
2026-09-04 15:24:27
(2 days ago)
F2B - Malicious activity detected. Too many 403. -8ff06ede-
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 14:16:57
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.21.155.120 (120.155.21.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.21.155.120 (120.155.21.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 10:16:50.558937 2026] [security2:error] [pid 25954:tid 25954] [client 34.21.155.120:53624] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.otcda-ts.com"] [uri "/@fs/app/.env"] [unique_id "aprS0uWlSBQo9v8TX0lPsQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 13:52:57
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.21.155.120 (120.155.21.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.21.155.120 (120.155.21.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 09:52:52.606578 2026] [security2:error] [pid 9044:tid 9044] [client 34.21.155.120:32902] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "stats.cmabiblequizzing.org"] [uri "/@fs/root/.env"] [unique_id "aprNNJBbTNU-yKJ_H9EdwAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
FeG Deutschland
2026-09-04 11:47:28
(2 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 127
Exploited Host
Web App Attack
🇩🇪
arnisolutions
2026-09-04 11:25:58
(2 days ago)
Vulnerability scanning (requests for admin panels, shells, backup files etc.) against a production s ...
show more
Vulnerability scanning (requests for admin panels, shells, backup files etc.) against a production server. Observed on 1 day(s) between 2026-09-04 and 2026-09-04 (UTC). Sample request: GET /@fs/var/www/html/.aws/credentials?raw?? HTTP/1.1
show less
Web App Attack
Hacking
🇳🇱
ConsulHosting
2026-09-04 10:59:12
(2 days ago)
Automatically blocked due to distributed attack
Hacking
🇺🇸
TPI-Abuse
2026-09-04 10:04:17
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.21.155.120 (120.155.21.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.21.155.120 (120.155.21.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:04:12.308724 2026] [security2:error] [pid 14735:tid 14735] [client 34.21.155.120:27970] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.the-schlosser.net"] [uri "/@fs/app/.env"] [unique_id "apqXnDgbcXD3warEyMhTfQAAADU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 09:20:46
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.21.155.120 (120.155.21.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.21.155.120 (120.155.21.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 05:20:36.907277 2026] [security2:error] [pid 1741:tid 1741] [client 34.21.155.120:34198] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.travelto.info"] [uri "/@fs/root/.env"] [unique_id "apqNZH05gq36ys6ZFBmSMgAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
dbmwebdesign
2026-09-04 08:35:06
(2 days ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 07:56:46
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.21.155.120 (120.155.21.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.21.155.120 (120.155.21.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 03:56:39.433877 2026] [security2:error] [pid 9459:tid 9459] [client 34.21.155.120:54156] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.farmersmutualcallaway.com"] [uri "/@fs/.env"] [unique_id "app5t_LuchsSKISSdmD9HQAAACQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
masterguru
2026-09-04 07:46:35
(2 days ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.21.155.120 (SG/Singapore/120.155.2 ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.21.155.120 (SG/Singapore/120.155.21.34.bc.googleusercontent.com): 2 in the last 3600 secs (0-196)
show less
Hacking
🇳🇱
ConsulHosting
2026-09-04 07:05:13
(2 days ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack
🇸🇬
cybertailor
2026-09-04 06:31:05
(2 days ago)
34.21.155.120 - - [04/Sep/2026:11:31:02 +0500] "GET /@fs/app/.env?raw?? HTTP/1.1" 404 146 "-" "Mozil ...
show more
34.21.155.120 - - [04/Sep/2026:11:31:02 +0500] "GET /@fs/app/.env?raw?? HTTP/1.1" 404 146 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:78.14) Gecko/20100101 Firefox/78.14; compatible; GPTBot/1.2; +https://openai.com/gptbot"
34.21.155.120 - - [04/Sep/2026:11:31:02 +0500] "GET /@fs/..%252f..%252f..%252f..%252f..%252froot/.env?raw?? HTTP/1.1" 404 146 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Amzn-SearchBot/1.0; +https://developer.amazon.com/support/amazonbot)"
34.21.155.120 - - [04/Sep/2026:11:31:02 +0500] "GET /@fs/src/.env?raw?? HTTP/1.1" 404 146 "-" "Mozilla/5.0 (compatible; Slackbot-LinkExpanding/1.0; +https://api.slack.com/robots)"
34.21.155.120 - - [04/Sep/2026:11:31:02 +0500] "GET /@fs/root/.env?raw?? HTTP/1.1" 404 178 "-" "Mozilla/5.0 (Linux; Android 14; Pixel 8) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.8016.123 Mobile Safari/537.36; compatible; ClaudeBot/1.0; [email protected] "
34.21.155.120 - - [04/Sep/2026:11:31:02 +0500] "GET /@fs
...
show less
Web App Attack