🇸🇪
vaia.cloud
2026-09-07 10:30:03
(5 hours ago)
crowdsecurity/http-probing
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 10:13:10
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.42.115.2 (2.115.42.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.42.115.2 (2.115.42.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 06:13:04.684693 2026] [security2:error] [pid 129348:tid 129364] [client 34.42.115.2:33396] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.meanmouse.com"] [uri "/@fs/.env.local"] [unique_id "ap6OMFOHgeiS7tKlLjXC9QAAAE4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Site.eu
2026-09-07 09:48:56
(6 hours ago)
Excessive multi-domain requests
Brute-Force
🇺🇸
TPI-Abuse
2026-09-07 09:30:14
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.42.115.2 (2.115.42.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.42.115.2 (2.115.42.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 05:30:06.633008 2026] [security2:error] [pid 8674:tid 8674] [client 34.42.115.2:33136] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lfrmtmorris.encoremtmorris.com"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252fapp/.env"] [unique_id "ap6EHnpaE_ySP-e9wEGKTAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇪🇸
alferez
2026-09-07 08:32:59
(7 hours ago)
Searching .(env|sql|zip|tar|rar) files
Hacking
Exploited Host
Web App Attack
🇳🇱
Savvii
2026-09-07 08:09:34
(7 hours ago)
20 attempts against mh-misbehave-ban on redirect
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 07:54:49
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.42.115.2 (2.115.42.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.42.115.2 (2.115.42.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 03:54:44.694538 2026] [security2:error] [pid 31364:tid 31364] [client 34.42.115.2:61724] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.ebric.com"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252fapp/.env"] [unique_id "ap5txH_-SfMpkeH0iqdxzgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
ConsulHosting
2026-09-07 07:32:37
(8 hours ago)
Automatically blocked due to distributed attack
Hacking
🇳🇱
WeCloudit-Anti-Abuse
2026-09-07 07:15:44
(8 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
🇦🇺
screwlooseit.com.au
2026-09-07 07:11:15
(8 hours ago)
Blocked by CSF 13 firewall - Rule: US/United States/2.115.42.34.bc.googleusercontent.com
Web App Attack
🇫🇷
Sklurk
2026-09-07 06:53:18
(8 hours ago)
Web App Attack
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 06:45:37
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.42.115.2 (2.115.42.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.42.115.2 (2.115.42.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 02:45:32.900362 2026] [security2:error] [pid 30156:tid 30156] [client 34.42.115.2:11556] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.bjfrancislaw.com"] [uri "/@fs/.env.local"] [unique_id "ap5djPt8uJay8UpKmGWpIQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 06:16:35
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.42.115.2 (2.115.42.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.42.115.2 (2.115.42.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 02:16:27.209852 2026] [security2:error] [pid 32499:tid 32499] [client 34.42.115.2:6406] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.alissacaputo.com"] [uri "/@fs/../../.env"] [unique_id "ap5Wu7U5w5gZU3jQ-tJyfQAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇪
cmbplf
2026-09-07 05:32:30
(10 hours ago)
966 requests with url.path *.aws/*
664 requests with url.path *config.json
651 requests with url. ...
show more
966 requests with url.path *.aws/*
664 requests with url.path *config.json
651 requests with url.path *.azure/*
613 requests with url.path *credentials.json
415 requests with url.path *.config/*
293 requests with url.path *.ssh/*
214 requests with url.path */auth.json
137 requests with url.path *.local/share/*
show less
Brute-Force
Bad Web Bot
🇩🇪
Stefan Dreher
2026-09-07 05:27:51
(10 hours ago)
34.42.115.2 - - [07/Sep/2026:07:27:50 +0200] "GET /@fs/src/.env?raw?? HTTP/1.1" 404 125 "-" "Mozilla ...
show more
34.42.115.2 - - [07/Sep/2026:07:27:50 +0200] "GET /@fs/src/.env?raw?? HTTP/1.1" 404 125 "-" "Mozilla/5.0 (compatible; LinkedInBot/1.0; +http://www.linkedin.com)"
34.42.115.2 - - [07/Sep/2026:07:27:50 +0200] "GET /@fs/root/.env?raw?? HTTP/1.1" 404 125 "-" "Mozilla/5.0 (compatible; ChatGPT-User/1.0; +https://openai.com/bot)"
34.42.115.2 - - [07/Sep/2026:07:27:50 +0200] "GET /@fs/.env?raw?? HTTP/1.1" 404 125 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; OAI-SearchBot/1.3; +https://openai.com/searchbot)"
34.42.115.2 - - [07/Sep/2026:07:27:50 +0200] "GET /@fs/proc/self/environ?raw?? HTTP/1.1" 404 125 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; +https://www.anthropic.com/claude-user)"
34.42.115.2 - - [07/Sep/2026:07:27:50 +0200] "GET /@fs/../.env?raw?? HTTP/1.1" 404 125 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; OAI-SearchBot/1.3; +https://openai.com/searchbot)"
...
show less
Hacking
Brute-Force