🇪🇸
librebit
2026-09-09 02:50:42
(6 hours ago)
Bad guys doing bad things, bad crawling
Bad Web Bot
🇬🇧
consul.to
2026-09-08 20:10:20
(13 hours ago)
Web attack/malicious scanning detected
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 20:06:11
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.32.166.105 (105.166.32.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.32.166.105 (105.166.32.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 16:06:03.266486 2026] [security2:error] [pid 24430:tid 24430] [client 34.32.166.105:36382] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bbc.my1611.com"] [uri "/@fs/src/.env"] [unique_id "aqBqq8I9LJWsst2UpacKrQAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 19:23:45
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.32.166.105 (105.166.32.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.32.166.105 (105.166.32.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 15:23:38.407640 2026] [security2:error] [pid 7163:tid 7163] [client 34.32.166.105:34544] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.illumoonatedtarot.com"] [uri "/@fs/root/.env"] [unique_id "aqBgupc89vB1CSpc01Iw-wAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
FD-IX
2026-09-08 19:20:29
(14 hours ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 19:05:16
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.32.166.105 (105.166.32.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.32.166.105 (105.166.32.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 15:05:10.465235 2026] [security2:error] [pid 28923:tid 28923] [client 34.32.166.105:39722] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.mympizzas.com.mx"] [uri "/@fs/.env"] [unique_id "aqBcZosBTPd91c3_ivbsngAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
gigatech
2026-09-08 18:40:04
(14 hours ago)
Webserver Probing
Web App Attack
🇫🇷
COMAITE
2026-09-08 18:39:54
(14 hours ago)
Suspicious URL access.
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 18:03:21
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.32.166.105 (105.166.32.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.32.166.105 (105.166.32.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 14:03:16.416623 2026] [security2:error] [pid 19428:tid 19428] [client 34.32.166.105:59602] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.vicrp.com"] [uri "/@fs/.env.development"] [unique_id "aqBN5E4i4IFvsDMLIHDOcQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 17:39:36
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.32.166.105 (105.166.32.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.32.166.105 (105.166.32.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 13:39:29.985978 2026] [security2:error] [pid 24877:tid 24877] [client 34.32.166.105:15874] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.wedemandabetterplan.empoweruohio.org"] [uri "/@fs/../../.env"] [unique_id "aqBIUTaBzhf5iQlV2Ey3zwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 17:18:41
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.32.166.105 (105.166.32.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.32.166.105 (105.166.32.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 13:18:35.297342 2026] [security2:error] [pid 12925:tid 12925] [client 34.32.166.105:9916] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "3wf.com"] [uri "/@fs/root/.env"] [unique_id "aqBDa7DwcMUQBLLga-WmegAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 16:55:24
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.32.166.105 (105.166.32.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.32.166.105 (105.166.32.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 12:55:16.515510 2026] [security2:error] [pid 9887:tid 9887] [client 34.32.166.105:57578] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.register-yacht-delaware.com"] [uri "/@fs/src/.env"] [unique_id "aqA99Fm6AGgJPYlD5O4O6AAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇭
zynex
2026-09-08 16:39:24
(16 hours ago)
URL Probing: /@fs/var/www/html/.env
Web App Attack
🇵🇱
Budyn
2026-09-08 16:26:32
(17 hours ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit Block. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: h.budyn.ovh | URI: /@fs/home/ec2-user/.aws/credentials?raw?? | UA: Mozilla/5.0 (compatible; Claude-User/1.0; +https://www.anthropic.com/claude-user) | BODY: [Empty / GET Request]
show less
Hacking
Web App Attack
🇳🇱
Site.eu
2026-09-08 16:09:51
(17 hours ago)
Excessive multi-domain requests
Brute-Force