🇲🇾
Rizzy
2026-09-08 06:57:27
(32 minutes ago)
Multiple WAF Violations
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 06:28:04
(1 hour ago)
(mod_security) mod_security (id:243420) triggered by 34.23.23.144 (144.23.23.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:243420) triggered by 34.23.23.144 (144.23.23.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 02:27:57.866744 2026] [security2:error] [pid 12686:tid 12686] [client 34.23.23.144:27570] ModSecurity: Access denied with code 403 (phase 3). Match of "validateByteRange 0-31" against "ARGS:raw??" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "6640"] [id "243420"] [rev "4"] [msg "COMODO WAF: Information disclosure vulnerability in Eclipse Jetty before 9.2.9.v20150224 (CVE-2015-2080)||www.register-yacht-st-kitts-and-nevis.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.register-yacht-st-kitts-and-nevis.com"] [uri "/.env"] [unique_id "ap-q7axSmMM9NW8eH_DO1AAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
macrob
2026-09-08 05:58:31
(1 hour ago)
2026/09/08 05:58:29 [error] 3640633#3640633: *569480978 access forbidden by rule, client: 34.23.23.1 ...
show more
2026/09/08 05:58:29 [error] 3640633#3640633: *569480978 access forbidden by rule, client: 34.23.23.144, server: ca5h.win, request: "GET /@fs/.env?raw?? HTTP/1.1", host: "ca5h.win"
2026/09/08 05:58:29 [error] 3640633#3640633: *569481064 access forbidden by rule, client: 34.23.23.144, server: ca5h.win, request: "GET /@fs/root/.env?raw?? HTTP/1.1", host: "ca5h.win"
2026/09/08 05:58:29 [error] 3640633#3640633: *569481065 access forbidden by rule, client: 34.23.23.144, server: ca5h.win, request: "GET /@fs/app/.env?raw?? HTTP/1.1", host: "ca5h.win"
...
show less
Web App Attack
Anonymous
2026-09-08 05:50:44
(1 hour ago)
Multiple web server 400 error codes from same source ip
Web App Attack
🇨🇭
zynex
2026-09-08 05:47:32
(1 hour ago)
URL Probing: /@fs/.env
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 05:27:47
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.23.23.144 (144.23.23.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.23.23.144 (144.23.23.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 01:27:41.138957 2026] [security2:error] [pid 31734:tid 31734] [client 34.23.23.144:17652] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.ciptaconindotara.com"] [uri "/@fs/src/.env"] [unique_id "ap-czTreUDpaFYfntFnHVwAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 05:07:03
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.23.23.144 (144.23.23.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.23.23.144 (144.23.23.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 01:06:58.701970 2026] [security2:error] [pid 4628:tid 4628] [client 34.23.23.144:55374] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jamescreates.org"] [uri "/@fs/.env"] [unique_id "ap-X8mdc_JkwyzR_vA34VQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
masterguru
2026-09-08 04:59:41
(2 hours ago)
Restricted File Access Attempt. Matched phrase "/@fs/" at REQUEST_FILENAME. (930130-197)
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 04:26:14
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.23.23.144 (144.23.23.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.23.23.144 (144.23.23.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 00:26:07.422465 2026] [security2:error] [pid 21623:tid 21623] [client 34.23.23.144:49688] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "reliableitc.com"] [uri "/@fs/src/.env"] [unique_id "ap-OX9N4JQ_OCiH0YHBo-AAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
ruusvuu
2026-09-08 04:24:48
(3 hours ago)
Automated abuse report: 25 attack/probe requests from Google LLC / US.
Targeted paths: /@fs/etc/pass ...
show more
Automated abuse report: 25 attack/probe requests from Google LLC / US.
Targeted paths: /@fs/etc/passwd, /@fs/..%252f..%252f..%252f..%252f..%252fproc/self/environ, /@fs/proc/self/environ, /@fs/root/terraform.tfstate.
Sample log lines:
[review-snippet] [2026-09-07 21:24:43 MST] 34.23.23.144 GET /@fs/..%252f..%252f..%252f..%252f..%252fproc/self/environ?raw?? 404 - 8.966 ms
[review-snippet] [2026-09-07 21:24:43 MST] 34.23.23.144 GET /@fs/proc/self/environ?raw?? 404 - 9.972 ms
[review-snippet] [2026-09-07 21:24:47 MST] 34.23.23.144 GET /@fs/root/terraform.tfstate?raw?? 404 - 8.733 ms
Detected by an automated web-server log monitor.
show less
Web App Attack
🇩🇪
onlyops.app
2026-09-08 04:00:11
(3 hours ago)
Web application firewall (ModSecurity) detected malicious traffic | detected by Fail2Ban (plesk-mods ...
show more
Web application firewall (ModSecurity) detected malicious traffic | detected by Fail2Ban (plesk-modsecurity jail) | onlyops.app
show less
Exploited Host
🇫🇷
COMAITE
2026-09-08 03:52:36
(3 hours ago)
Common web attack from 34.23.23.144.
Web App Attack
🇩🇪
LRob
2026-09-08 03:47:31
(3 hours ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /@fs/../../.env (+11 more) | 2026-09-08 03:47 UTC
show less
Hacking
Web App Attack
🇩🇪
ger-stg-sifi1
2026-09-08 03:35:56
(3 hours ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 03:30:58
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.23.23.144 (144.23.23.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.23.23.144 (144.23.23.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 23:30:51.516477 2026] [security2:error] [pid 19836:tid 19836] [client 34.23.23.144:44974] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.arsenaultartistmanagement.com"] [uri "/@fs/.env.local"] [unique_id "ap-Ba-N9ROIrfrvxJo7h0QAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack