🇩🇪
Viveronese
2026-09-08 12:28:06
(3 days ago)
HTTP vulnerability scanning
Web App Attack
🇳🇱
ConsulHosting
2026-09-08 11:56:25
(3 days ago)
Automatically blocked due to distributed attack
Hacking
🇳🇱
ConsulHosting
2026-09-08 11:13:13
(3 days ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 10:31:24
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.21.251.212 (212.251.21.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.21.251.212 (212.251.21.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 06:31:19.702516 2026] [security2:error] [pid 20859:tid 20859] [client 34.21.251.212:6690] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rail-town.com"] [uri "/@fs/src/.env"] [unique_id "ap_j9370DmKSiPFkpR9atQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇦
polycoda
2026-09-08 10:09:34
(3 days ago)
🔥 VERY AGGRESSIVE SCANNER probed over 100 inexistent files and PHP scripts in less than an hour.
Hacking
Web App Attack
🇳🇱
Site.eu
2026-09-08 10:04:54
(3 days ago)
Excessive multi-domain requests
Brute-Force
Anonymous
2026-09-08 09:54:42
(3 days ago)
34.21.251.212 - - [08/Sep/2026:11:54:41 +0200] "GET /@fs/..%252f..%252f..%252f..%252f..%252froot/.en ...
show more
34.21.251.212 - - [08/Sep/2026:11:54:41 +0200] "GET /@fs/..%252f..%252f..%252f..%252f..%252froot/.env?raw?? HTTP/1.1" 403 124 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14_6_1) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/19.3 Safari/605.1.15; compatible; ChatGPT-User/1.0; +https://openai.com/bot"
34.21.251.212 - - [08/Sep/2026:11:54:42 +0200] "GET /@fs/root/rootkey.csv?raw?? HTTP/1.1" 403 124 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_0 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko; compatible; GrokBot/1.0; +https://x.ai/grokbot) Version/16.0 Mobile/15E148 Safari/604.1"
34.21.251.212 - - [08/Sep/2026:11:54:42 +0200] "GET /@fs/app/rootkey.csv?raw?? HTTP/1.1" 403 183 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.2519.71 Safari/537.36; compatible; Claude-SearchBot/1.0; +https://www.anthropic.com/claude-searchbot"
34.21.251.212 - - [08/Sep/2026:11:54:42 +0200] "GET /@fs/.env.production?raw?? HTTP/1.1" 403 124 "-" "Mozilla/5.0
...
show less
Bad Web Bot
Web App Attack
🇸🇪
Lemmy
2026-09-08 09:54:25
(3 days ago)
Web App Attack
Web App Attack
🇦🇺
nzhost.co.nz
2026-09-08 09:50:41
(3 days ago)
$f2bV_matches
Hacking
Brute-Force
🇺🇸
TPI-Abuse
2026-09-08 09:26:22
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.21.251.212 (212.251.21.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.21.251.212 (212.251.21.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 05:26:17.903522 2026] [security2:error] [pid 592:tid 592] [client 34.21.251.212:11046] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.ridefilmsinc.com"] [uri "/@fs/app/.env"] [unique_id "ap_UuR63DNCYhH0PVpKy6AAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇪🇸
elcruzado.es
2026-09-08 09:20:43
(3 days ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 34.21.251.212 (SG/Si ...
show more
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 34.21.251.212 (SG/Singapore/212.251.21.34.bc.googleusercontent.com)
show less
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-08 09:10:43
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.21.251.212 (212.251.21.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.21.251.212 (212.251.21.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 05:10:38.204567 2026] [security2:error] [pid 21376:tid 21376] [client 34.21.251.212:8100] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.lamporix.com"] [uri "/@fs/src/.env"] [unique_id "ap_RDtKg8SHKj5zwAjLMuwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 08:50:53
(3 days ago)
(mod_security) mod_security (id:949110) triggered by 34.21.251.212 (212.251.21.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:949110) triggered by 34.21.251.212 (212.251.21.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 04:50:46.339937 2026] [security2:error] [pid 28060:tid 28060] [client 34.21.251.212:43420] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 20)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "clintess.biz"] [uri "/@fs/..%2f..%2f..%2f..%2f..%2fapp/.env"] [unique_id "ap_MZnK3KB45IhhdO9SVOAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 08:30:18
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.21.251.212 (212.251.21.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.21.251.212 (212.251.21.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 04:30:10.292712 2026] [security2:error] [pid 13327:tid 13327] [client 34.21.251.212:30366] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.trancelucid.com"] [uri "/@fs/.env"] [unique_id "ap_HkuiPHanOTimRuE15hgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 07:42:26
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.21.251.212 (212.251.21.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.21.251.212 (212.251.21.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 03:42:18.592976 2026] [security2:error] [pid 11443:tid 11443] [client 34.21.251.212:64162] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.kathiepontinen.com"] [uri "/@fs/src/.env"] [unique_id "ap-8WrQCPOjDCdir2EFaLwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack