🇩🇪
XICTRON
2026-09-08 10:55:09
(30 minutes ago)
ModSecurity rule violation detected by Fail2Ban
Web App Attack
🇩🇪
Hazzard
2026-09-08 10:07:04
(1 hour ago)
(mod_security) mod_security triggered on hostname [redacted]): (CF_ENABLE)
SQL Injection
🇫🇷
masterguru
2026-09-08 08:28:17
(2 hours ago)
Restricted File Access Attempt. Matched phrase "/@fs/" at REQUEST_FILENAME. (930130-197)
Hacking
Web App Attack
🇩🇪
LRob
2026-09-08 07:33:16
(3 hours ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /@fs/../../.env (+12 more) | 2026-09-08 07:33 UTC
show less
Hacking
Web App Attack
🇳🇱
SchorelWeb
2026-09-08 07:02:47
(4 hours ago)
Cluster member (Omitted) (FR/France/-) said, TEMPDENY 34.34.92.188, Reason:[(Suspicious404) Suspicio ...
show more
Cluster member (Omitted) (FR/France/-) said, TEMPDENY 34.34.92.188, Reason:[(Suspicious404) Suspicious activity detected 34.34.92.188 (NL/The Netherlands/188.92.34.34.bc.googleusercontent.com): 10 in the last 3600 secs]
show less
Brute-Force
SSH
🇺🇸
TPI-Abuse
2026-09-08 06:57:46
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.34.92.188 (188.92.34.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.34.92.188 (188.92.34.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 02:57:42.942585 2026] [security2:error] [pid 17611:tid 17611] [client 34.34.92.188:36616] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.bfpsamoa.com"] [uri "/@fs/.env"] [unique_id "ap-x5u42L5O0XoN25gYY2gAAADM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-08 06:54:25
(4 hours ago)
Multiple web server 400 error codes from same source ip
Web App Attack
🇳🇱
e.fierstra
2026-09-08 06:48:30
(4 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇫🇷
masterguru
2026-09-08 06:26:08
(4 hours ago)
Restricted File Access Attempt. Matched phrase "/@fs/" at REQUEST_FILENAME. (930130-201)
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 06:04:39
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.34.92.188 (188.92.34.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.34.92.188 (188.92.34.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 02:04:33.189008 2026] [security2:error] [pid 18827:tid 18827] [client 34.34.92.188:35056] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.aylinvictoria.com"] [uri "/@fs/root/.env"] [unique_id "ap-lcRNUugpVBQiPfP47jAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 05:26:18
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.34.92.188 (188.92.34.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.34.92.188 (188.92.34.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 01:26:12.713664 2026] [security2:error] [pid 11266:tid 11285] [client 34.34.92.188:25460] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.geekshop.com"] [uri "/@fs/.env"] [unique_id "ap-cdOgmRci1IT3Y4onTLgAAAEU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 05:06:16
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.34.92.188 (188.92.34.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.34.92.188 (188.92.34.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 01:06:11.925831 2026] [security2:error] [pid 399:tid 399] [client 34.34.92.188:27454] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.drstiso.com"] [uri "/@fs/src/.env"] [unique_id "ap-Xw5DPW4DuOoRfGkgbfQAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
Octopuce
2026-09-08 05:03:11
(6 hours ago)
Aggressive web search of vulnerable pages: /uploads../.env /.docker/.env /assets../.env /_nuxt/../.e ...
show more
Aggressive web search of vulnerable pages: /uploads../.env /.docker/.env /assets../.env /_nuxt/../.env /admin/.env ...
show less
Web App Attack
🇸🇪
vaia.cloud
2026-09-08 04:30:03
(6 hours ago)
crowdsecurity/http-probing
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 04:07:49
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.34.92.188 (188.92.34.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.34.92.188 (188.92.34.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 00:07:42.609864 2026] [security2:error] [pid 29746:tid 29746] [client 34.34.92.188:18352] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.495metro.com"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252froot/.env"] [unique_id "ap-KDlnRgo9xSwqbqhhjoAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack