🇺🇸
mnsf
2026-09-09 01:05:11
(14 hours ago)
Scanning/Probing (25)
Brute-Force
Web App Attack
🇮🇳
evicky2002
2026-09-09 00:01:20
(15 hours ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
🇺🇸
TPI-Abuse
2026-09-08 12:29:16
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.24.41.184 (184.41.24.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.24.41.184 (184.41.24.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 08:29:11.984797 2026] [security2:error] [pid 21698:tid 21698] [client 34.24.41.184:13556] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "intnlc.org"] [uri "/@fs/.env"] [unique_id "ap__l8twWivt4kX0WlJOZgAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 11:18:04
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.24.41.184 (184.41.24.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.24.41.184 (184.41.24.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 07:17:58.711629 2026] [security2:error] [pid 19361:tid 19361] [client 34.24.41.184:52174] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.flyingcardcompany.com"] [uri "/@fs/app/.env"] [unique_id "ap_u5uMcWic3Qr2MIhDo_gAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇪
madeit
2026-09-08 10:03:01
(1 day ago)
Web App Attack
Anonymous
2026-09-08 09:35:17
(1 day ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
🇩🇪
Bedios GmbH
2026-09-08 09:05:19
(1 day ago)
Login credentials theft attempt
Hacking
Anonymous
2026-09-08 08:43:14
(1 day ago)
Bot / seems abusive / Apache connections: 58
DDoS Attack
Web Spam
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 08:28:08
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.24.41.184 (184.41.24.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.24.41.184 (184.41.24.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 04:28:04.554575 2026] [security2:error] [pid 6940:tid 6940] [client 34.24.41.184:53672] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.butterflymornings.com"] [uri "/@fs/src/.env"] [unique_id "ap_HFOsuaHYnKqTEXtitHwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 07:54:12
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.24.41.184 (184.41.24.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.24.41.184 (184.41.24.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 03:54:08.921997 2026] [security2:error] [pid 12531:tid 12612] [client 34.24.41.184:14292] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.mouserart.com"] [uri "/@fs/src/.env"] [unique_id "ap-_IM4OKonD9cWfTFTNOgAAAIk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
BlueWire Hosting
2026-09-08 07:39:36
(1 day ago)
High-confidence malicious configuration/VCS probe
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 07:33:39
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.24.41.184 (184.41.24.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.24.41.184 (184.41.24.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 03:33:31.823330 2026] [security2:error] [pid 6379:tid 6379] [client 34.24.41.184:16918] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.bethbornsteindunnington.com"] [uri "/@fs/root/.env"] [unique_id "ap-6Sy4uIUi3fx7BhqC8rgAAAEk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
IRISIO
2026-09-08 07:18:52
(1 day ago)
scans/SQL injection/spam posts : 817 queries
Web App Attack
SQL Injection
🇺🇸
TPI-Abuse
2026-09-08 06:23:51
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.24.41.184 (184.41.24.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.24.41.184 (184.41.24.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 02:23:46.590847 2026] [security2:error] [pid 32124:tid 32124] [client 34.24.41.184:6102] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.szeliga.com"] [uri "/@fs/root/.env"] [unique_id "ap-p8gNu2MKjUEWDPKJYUQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
masterguru
2026-09-08 06:09:54
(1 day ago)
Restricted File Access Attempt. Matched phrase "/@fs/" at REQUEST_FILENAME. (930130-193)
Hacking
Web App Attack