🇳🇱
Mangelot Hosting
2026-09-08 09:54:47
(29 minutes ago)
(modsecurity) srv104 ModSecurity 34.34.55.238 (NL/The Netherlands/238.55.34.34.bc.googleusercontent. ...
show more
(modsecurity) srv104 ModSecurity 34.34.55.238 (NL/The Netherlands/238.55.34.34.bc.googleusercontent.com): 30 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
🇩🇪
ghostwarriors
2026-09-08 09:50:11
(33 minutes ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
🇩🇪
yitzhaq
2026-09-08 09:47:33
(36 minutes ago)
34.34.55.238 - - [08/Sep/2026:11:47:28 +0200] "GET /@fs/root/.aws/credentials.bak?raw?? HTTP/1.1" 40 ...
show more
34.34.55.238 - - [08/Sep/2026:11:47:28 +0200] "GET /@fs/root/.aws/credentials.bak?raw?? HTTP/1.1" 404 27009 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:133.6) Gecko/20100101 Firefox/133.6; compatible; meta-externalagent/1.1; +https://developers.facebook.com/docs/sharing/webmasters/crawler"
34.34.55.238 - - [08/Sep/2026:11:47:28 +0200] "GET /@fs/root/.aws/config?raw?? HTTP/1.1" 404 27009 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexity-user"
34.34.55.238 - - [08/Sep/2026:11:47:28 +0200] "GET /@fs/root/.aws/credentials?raw?? HTTP/1.1" 404 27009 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko; compatible; LinkedInBot/1.0; +http://www.linkedin.com) Version/18.1 Safari/605.1.15"
34.34.55.238 - - [08/Sep/2026:11:47:28 +0200] "GET /@fs/.env?raw?? HTTP/1.1" 404 27009 "-" "Mozilla/5.0 (compatible; Twitterbot/1.0)"
34.34.55.238 - - [08/Sep/2026:11:47:28 +0200] "GET /@fs/src
show less
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-08 09:37:28
(46 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.34.55.238 (238.55.34.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.34.55.238 (238.55.34.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 05:37:21.216255 2026] [security2:error] [pid 14555:tid 14555] [client 34.34.55.238:39854] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.portraitsinblues.com"] [uri "/@fs/src/.env"] [unique_id "ap_XUe_FEfocQlYh4XfpAQAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 09:12:12
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.34.55.238 (238.55.34.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.34.55.238 (238.55.34.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 05:12:04.579697 2026] [security2:error] [pid 24611:tid 24611] [client 34.34.55.238:22672] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ourredeemeroxnard.vccemail.net"] [uri "/@fs/.env.staging"] [unique_id "ap_RZGaiOy912q7dkAmZGgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-08 08:38:53
(1 hour ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
🇩🇪
FD-IX
2026-09-08 07:10:08
(3 hours ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
🇫🇷
masterguru
2026-09-08 07:07:56
(3 hours ago)
Restricted File Access Attempt. Matched phrase "/@fs/" at REQUEST_FILENAME. (930130-193)
Hacking
Web App Attack
🇫🇷
Octopuce
2026-09-08 06:45:55
(3 hours ago)
Aggressive web search of vulnerable pages: /uploads../.env /.docker/.env /v2/.env /.env /assets../.e ...
show more
Aggressive web search of vulnerable pages: /uploads../.env /.docker/.env /v2/.env /.env /assets../.env ...
show less
Web App Attack
Anonymous
2026-09-08 06:34:25
(3 hours ago)
XSS Attempt
Hacking
🇺🇸
TPI-Abuse
2026-09-08 06:29:49
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.34.55.238 (238.55.34.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.34.55.238 (238.55.34.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 02:29:43.771354 2026] [security2:error] [pid 14321:tid 14338] [client 34.34.55.238:60924] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jd-web-designs.com"] [uri "/@fs/.env"] [unique_id "ap-rV3Umsa4YN6gj7Ny44AAAAI4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Site.eu
2026-09-08 06:18:30
(4 hours ago)
Excessive multi-domain requests
Brute-Force
🇺🇸
TPI-Abuse
2026-09-08 06:11:24
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.34.55.238 (238.55.34.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.34.55.238 (238.55.34.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 02:11:18.473123 2026] [security2:error] [pid 4717:tid 4717] [client 34.34.55.238:28460] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.aktkaro.com"] [uri "/@fs/src/.env"] [unique_id "ap-nBpxsfg0r6CFpU7IwiwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
debestelapp
2026-09-08 06:05:12
(4 hours ago)
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 05:51:24
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.34.55.238 (238.55.34.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.34.55.238 (238.55.34.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 01:51:20.157927 2026] [security2:error] [pid 19847:tid 19847] [client 34.34.55.238:42748] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.polarisled.com"] [uri "/@fs/.env"] [unique_id "ap-iWI273ix4HJnWFDnE7QAAACk"]
show less
Brute-Force
Bad Web Bot
Web App Attack