🇧🇪
cmbplf
2026-09-08 21:28:07
(10 hours ago)
516 requests with url.path *config.json
502 requests with url.path *credentials.json
371 requests ...
show more
516 requests with url.path *config.json
502 requests with url.path *credentials.json
371 requests with url.path *.config/*
219 requests with url.path */proc/*
106 requests with url.path */auth.json
show less
Brute-Force
Bad Web Bot
🇳🇱
Site.eu
2026-09-08 20:26:52
(11 hours ago)
Excessive multi-domain requests
Brute-Force
🇺🇸
TPI-Abuse
2026-09-08 19:48:04
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.32.178.38 (38.178.32.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.32.178.38 (38.178.32.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 15:48:00.199007 2026] [security2:error] [pid 17990:tid 17990] [client 34.32.178.38:24192] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.veenstras.com"] [uri "/@fs/root/.env"] [unique_id "aqBmcH7iLS37fZdMW5iaiAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 19:19:21
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.32.178.38 (38.178.32.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.32.178.38 (38.178.32.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 15:19:14.242444 2026] [security2:error] [pid 3233:tid 3233] [client 34.32.178.38:33600] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.sheargrafix.com"] [uri "/@fs/.env"] [unique_id "aqBfslOOJHwDFbhZwj7XZQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇪🇸
Michael McCarthy
2026-09-08 18:54:05
(13 hours ago)
Web Spam
🇺🇸
TPI-Abuse
2026-09-08 18:48:21
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.32.178.38 (38.178.32.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.32.178.38 (38.178.32.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 14:48:15.172950 2026] [security2:error] [pid 25599:tid 25599] [client 34.32.178.38:56422] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.wisdomsco.com"] [uri "/@fs/src/.env"] [unique_id "aqBYbxxcaQZxr0CcPIUadQAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 18:27:43
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.32.178.38 (38.178.32.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.32.178.38 (38.178.32.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 14:27:40.350876 2026] [security2:error] [pid 23219:tid 23219] [client 34.32.178.38:7214] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.hatsizes.com"] [uri "/@fs/.env"] [unique_id "aqBTnLsdo0ip6oTeBsUprAAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
bensmithurst
2026-09-08 18:21:39
(13 hours ago)
34.32.178.38 - - [08/Sep/2026:18:21:26 +0000] "GET /@fs/../../.env?raw?? HTTP/1.1" 400 150 "-" "-"
3 ...
show more
34.32.178.38 - - [08/Sep/2026:18:21:26 +0000] "GET /@fs/../../.env?raw?? HTTP/1.1" 400 150 "-" "-"
34.32.178.38 - - [08/Sep/2026:18:21:38 +0000] "GET /@fs/..%2f..%2f..%2f..%2f..%2fapp/.env?raw?? HTTP/1.1" 400 150 "-" "-"
34.32.178.38 - - [08/Sep/2026:18:21:38 +0000] "GET /@fs/../../../../../app/.env?raw?? HTTP/1.1" 400 150 "-" "-"
34.32.178.38 - - [08/Sep/2026:18:21:38 +0000] "GET /@fs/..%2f..%2f..%2f..%2f..%2fproc/self/environ?raw?? HTTP/1.1" 400 150 "-" "-"
34.32.178.38 - - [08/Sep/2026:18:21:38 +0000] "GET /@fs/../../../../../root/.env?raw?? HTTP/1.1" 400 150 "-" "-"
... [host=LAN***]
show less
Web App Attack
🇩🇪
Petros Stefanakis
2026-09-08 18:11:27
(13 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 34.32.178.38 (38.178.32.34.bc.googleuse ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.32.178.38 (38.178.32.34.bc.googleusercontent.com)
show less
SQL Injection
🇺🇸
TPI-Abuse
2026-09-08 18:09:29
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.32.178.38 (38.178.32.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.32.178.38 (38.178.32.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 14:09:23.141530 2026] [security2:error] [pid 30306:tid 30306] [client 34.32.178.38:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.ndanetworks.com"] [uri "/@fs/../.env"] [unique_id "aqBPU4daBnpysYnFKeMc4QAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇿🇦
conure.sh
2026-09-08 17:25:00
(14 hours ago)
csagent: score 20.0: secrets grab x2; 2 domain(s) in 6s
Web App Attack
🇩🇪
LRob
2026-09-08 17:23:09
(14 hours ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /@fs/../../.env (+10 more) | 2026-09-08 17:23 UTC
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 17:15:55
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.32.178.38 (38.178.32.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.32.178.38 (38.178.32.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 13:15:49.043955 2026] [security2:error] [pid 12610:tid 12610] [client 34.32.178.38:32910] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "whitecranemanagement.com"] [uri "/@fs/.env"] [unique_id "aqBCxeO2XF1Ffdb8Bj5orQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
e.fierstra
2026-09-08 17:15:45
(14 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇳🇱
Savvii
2026-09-08 16:53:25
(15 hours ago)
20 attempts against mh-misbehave-ban on takeover-test
Brute-Force
Bad Web Bot
Web App Attack