🇳🇱
middelkoopcc
2026-09-09 18:16:01
(5 hours ago)
2026-09-09 20:14:27 AH10244: invalid URI path (/@fs/../../.env?raw??) && 2026-09-09 20:14:39 AH10244 ...
show more
2026-09-09 20:14:27 AH10244: invalid URI path (/@fs/../../.env?raw??) && 2026-09-09 20:14:39 AH10244: invalid URI path (/@fs/../../../../../root/.env?raw??) && 2026-09-09 20:14:39 AH10244: invalid URI path (/@fs/../../../../../proc/self/environ?raw??) && 139 more within 20 minutes
show less
Web App Attack
🇵🇱
wielorzeczownik
2026-09-09 17:53:04
(5 hours ago)
5 failed attempts
2026-09-09 19:53:03 GET /@fs/.env.local?raw?? -> 404
2026-09-09 19:53:03 GET / ...
show more
5 failed attempts
2026-09-09 19:53:03 GET /@fs/.env.local?raw?? -> 404
2026-09-09 19:53:03 GET /@fs/..%252f..%252f..%252f..%252f..%252froot/.env?raw?? -> 404
2026-09-09 19:53:03 GET /.env?raw?? -> 404
2026-09-09 19:53:03 GET /@fs/.env.production?raw?? -> 404
2026-09-09 19:53:03 GET /@fs/src/.env?raw?? -> 404
show less
Web App Attack
Hacking
🇮🇹
CoreTech srl
2026-09-09 16:08:57
(7 hours ago)
cloudlinux2 fail2ban: 2026-09-09 18:06:28,241 fail2ban.actions [1892]: NOTICE [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-09-09 18:06:28,241 fail2ban.actions [1892]: NOTICE [plesk-modsecurity] Unban 34.88.211.1cloudlinux2 fail2ban: 2026-09-09 18:06:34,213 fail2ban.filter [1892]: INFO [plesk-modsecurity] Found 34.23.25.80 - 2026-09-09 18:06:34cloudlinux2 fail2ban: 2026-09-09 18:06:27,629 fail2ban.actions [1892]: NOTICE [plesk-modsecurity] Unban 136.110.73.0cloudlinux2 fail2ban: 2026-09-09 18:06:34,192 fail2ban.filter [1892]: INFO [plesk-modsecurity] Found 34.23.25.80 - 2026-09-09 18:06:34cloudlinux2 fail2ban: 2026-09-09 18:06:58,288 fail2ban.actions [1892]: NOTICE [plesk-modsecurity] Ban 34.23.25.80cloudlinux2 fail2ban: 2026-09-09 18:06:58,186 fail2ban.filter [1892]: INFO [plesk-modsecurity] Found 34.23.25.80 - 2026-09-09 18:06:58cloudlinux2 fail2ban: 2026-09-09 18:06:58,215 fail2ban.filter [1892]: INFO [plesk-modsecurity] Found 34.23.25.80 - 2026-09-09 18:06:58cloudlinux2 fail2ban: 2026-09-09 18:06:58,294 fail2ban.filter [1892]
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 16:02:46
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.23.25.80 (80.25.23.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.23.25.80 (80.25.23.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 12:02:38.339816 2026] [security2:error] [pid 3461:tid 3461] [client 34.23.25.80:60496] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "southshorestreetrods.com.nashes.net"] [uri "/@fs/.env"] [unique_id "aqGDHqS-LW396UfJIIgcYAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 14:26:53
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.23.25.80 (80.25.23.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.23.25.80 (80.25.23.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 10:26:47.110735 2026] [security2:error] [pid 17319:tid 17319] [client 34.23.25.80:46692] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.capassoart.com"] [uri "/@fs/../../.env"] [unique_id "aqFspyS7a6xwDwW6RrXSpgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 13:23:00
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.23.25.80 (80.25.23.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.23.25.80 (80.25.23.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 09:22:53.756257 2026] [security2:error] [pid 13724:tid 13724] [client 34.23.25.80:56160] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.denisfrison.com"] [uri "/@fs/root/.env"] [unique_id "aqFdrTreL32A-NfYoGS8MAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 12:32:48
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.23.25.80 (80.25.23.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.23.25.80 (80.25.23.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 08:32:41.022653 2026] [security2:error] [pid 28408:tid 28408] [client 34.23.25.80:30082] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.versahealthcare.com"] [uri "/@fs/.env"] [unique_id "aqFR6Tf2wyZvrMIyeS7giQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
melroy89
2026-09-09 11:00:11
(12 hours ago)
34.23.25.80 - - [09/Sep/2026:12:59:25 +0200] "GET / HTTP/1.1" 403 9 "-" "Mozilla/5.0 (X11; Linux x8 ...
show more
34.23.25.80 - - [09/Sep/2026:12:59:25 +0200] "GET / HTTP/1.1" 403 9 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/118.0.0.0 Safari/537.36" "forum.moneytips.nl" 0.000
34.23.25.80 - - [09/Sep/2026:12:59:27 +0200] "GET /@fs/proc/self/environ?raw?? HTTP/1.1" 403 9 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; Claude-User/1.0; +https://www.anthropic.com/claude-user" "forum.moneytips.nl" 0.000
34.23.25.80 - - [09/Sep/2026:12:59:27 +0200] "GET / HTTP/1.1" 403 9 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36" "forum.moneytips.nl" 0.000
34.23.25.80 - - [09/Sep/2026:12:59:27 +0200] "GET / HTTP/1.1" 403 9 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/130.0.0.0 Safari/537.36" "forum.moneytips.nl" 0.000
34.23.25.80 - - [09/Sep/2026:12:59:27 +0200] "GET /@fs/app/rootkey.csv?raw?? HTTP/1.1" 403 9 "-" "Mozilla/5.0 (M
...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 10:55:47
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.23.25.80 (80.25.23.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.23.25.80 (80.25.23.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 06:55:43.107777 2026] [security2:error] [pid 4258:tid 4258] [client 34.23.25.80:53732] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.chickenchristmascards.com"] [uri "/@fs/root/.env"] [unique_id "aqE7L8vQj2R-EE7CeEELWAAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
debestelapp
2026-09-09 10:45:13
(12 hours ago)
Web App Attack
🇩🇪
webanyone
2026-09-09 10:01:49
(13 hours ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
🇪🇸
masterguru
2026-09-09 09:28:21
(14 hours ago)
BAD BOT - Detected and Blocked.. Matched phrase "GPTBot" at REQUEST_HEADERS:User-Agent. (1100000-122 ...
show more
BAD BOT - Detected and Blocked.. Matched phrase "GPTBot" at REQUEST_HEADERS:User-Agent. (1100000-122)
show less
Bad Web Bot
🇦🇹
penguin-solutions.at
2026-09-09 09:14:34
(14 hours ago)
Excessive 403/404 errors
...
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 08:34:06
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.23.25.80 (80.25.23.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.23.25.80 (80.25.23.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 04:34:02.131340 2026] [security2:error] [pid 28713:tid 28713] [client 34.23.25.80:32946] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.pcmec.com"] [uri "/@fs/src/.env"] [unique_id "aqEZ-s6oiXGCshHDbPJrrAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
LRob
2026-09-09 08:31:15
(15 hours ago)
Enumerating paths that do not exist (scanning) | method: GET | path: /@fs/.env | ua: Mozilla/5.0 App ...
show more
Enumerating paths that do not exist (scanning) | method: GET | path: /@fs/.env | ua: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; +https://www.anthropic.com/claude-user) | 2026-09-09 08:31 UTC
show less
Port Scan
Web App Attack