🇩🇪
MBombeck
2026-09-07 20:46:17
(15 minutes ago)
Fail2Ban/traefik-botsearch on apps-01: banned after 5 failures
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 20:37:29
(24 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.29.191.239 (239.191.29.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.29.191.239 (239.191.29.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 16:37:24.303212 2026] [security2:error] [pid 30966:tid 30966] [client 34.29.191.239:62324] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kinatalton.taltonfamily.com"] [uri "/@fs/../../.env"] [unique_id "ap8ghKAhewMdQDf-_1tKUQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
mnsf
2026-09-07 20:05:19
(56 minutes ago)
Scanning/Probing (20)
Brute-Force
Web App Attack
🇩🇪
Blexyel
2026-09-07 18:43:25
(2 hours ago)
34.29.191.239 - - [07/Sep/2026:20:43:25 +0200] "GET /.git/config HTTP/1.1" 200 1309 "-" "Mozilla/5.0 ...
show more
34.29.191.239 - - [07/Sep/2026:20:43:25 +0200] "GET /.git/config HTTP/1.1" 200 1309 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; Slackbot-LinkExpanding/1.0; +https://api.slack.com/robots" "kitty.s3.fomx.gay"
...
show less
Brute-Force
Web App Attack
🇳🇱
Site.eu
2026-09-07 18:42:07
(2 hours ago)
Excessive 404/403 errors
Brute-Force
🇺🇸
TPI-Abuse
2026-09-07 18:39:18
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.29.191.239 (239.191.29.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.29.191.239 (239.191.29.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 14:39:11.071224 2026] [security2:error] [pid 19963:tid 19963] [client 34.29.191.239:52798] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.tianabes.com"] [uri "/@fs/.env.local"] [unique_id "ap8Ez50xF8yuditQj4LuxgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
big-cloud.nl
2026-09-07 18:29:12
(2 hours ago)
Try to access /@fs/root/.env?raw??
Web App Attack
🇫🇷
dynamix
2026-09-07 18:18:41
(2 hours ago)
Multiple WAF Violations
Web App Attack
Anonymous
2026-09-07 18:07:23
(2 hours ago)
34.29.191.239 - - [07/Sep/2026:13:07:18 -0500] "GET /.env.backup HTTP/1.1" 302 245 "-" "Mozilla/5.0 ...
show more
34.29.191.239 - - [07/Sep/2026:13:07:18 -0500] "GET /.env.backup HTTP/1.1" 302 245 "-" "Mozilla/5.0 (compatible; Claude-User/1.0; [email protected] )" 104.22.64.71
34.29.191.239 - - [07/Sep/2026:13:07:18 -0500] "GET /.env.staging HTTP/1.1" 302 246 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; OAI-SearchBot/1.4; robots.txt; +https://openai.com/searchbot)" 172.71.255.101
34.29.191.239 - - [07/Sep/2026:13:07:18 -0500] "GET /.env HTTP/1.1" 302 238 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; OAI-SearchBot/1.3; +https://openai.com/searchbot" 104.22.64.71
34.29.191.239 - - [07/Sep/2026:13:07:18 -0500] "GET /.env.local HTTP/1.1" 302 244 "-" "Mozilla/5.0 (compatible; Applebot/0.1; +http://www.apple.com/go/applebot)" 172.71.255.101
34.29.191.239 - - [07/Sep/2026:13:07:18 -0500] "GET /.env.development HTTP/1.1" 302 250 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; GrokBot/1.0; +https://x.ai/grokbot)" 172.69.17.20
34.29.1
...
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-07 18:02:10
(3 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-07 18:00:22
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.29.191.239 (239.191.29.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.29.191.239 (239.191.29.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 14:00:14.254363 2026] [security2:error] [pid 8263:tid 8263] [client 34.29.191.239:31632] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.jerrylogoluso.com"] [uri "/@fs/.env"] [unique_id "ap77rg7hNvCC_ylTltsKHwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇪🇸
pipeline.es
2026-09-07 17:58:53
(3 hours ago)
Web scanning / probing for vulnerable paths | URL: /core/.env | Evidence: iristourvacances.com 34.29 ...
show more
Web scanning / probing for vulnerable paths | URL: /core/.env | Evidence: iristourvacances.com 34.29.191.239 - - [07/Sep/2026:19:58:07 +0200] \"GET /core/.env HTTP/1.1\" 404 3537 \"-\" \"Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/19.0 Safari/605.1.15; compatible; GrokBot/1.0; +https://x.ai/grokbot\" GEOIP_COUNTRY_CODE=US | ASN: GOOGLE-CLOUD-PLATFORM | Country: US
show less
Port Scan
Web App Attack
🇬🇧
consul.to
2026-09-07 17:46:00
(3 hours ago)
Web attack/malicious scanning detected
Web App Attack
Anonymous
2026-09-07 17:07:57
(3 hours ago)
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: US, Attack patterns: Word ...
show more
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: US, Attack patterns: WordPress scanning, Backup file probing, Cloud secrets probing
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 17:03:51
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.29.191.239 (239.191.29.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.29.191.239 (239.191.29.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 13:03:44.469043 2026] [security2:error] [pid 5978:tid 5978] [client 34.29.191.239:24138] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "travelimts.com"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252froot/.env"] [unique_id "ap7ucIQtsqUaHW06SDvEzAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack