🇨🇭
4server
2026-09-07 10:37:42
(17 hours ago)
[MonSep0712:37:37.7234322026][security2:error][pid748127:tid748148][client34.44.144.37:0]ModSecurity ...
show more
[MonSep0712:37:37.7234322026][security2:error][pid748127:tid748148][client34.44.144.37:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".env\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"610\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"swiss-domain-name.ch\"][uri\"/@fs/app/.env\"][unique_id\"ap6T8ZoTl26zj2THmBxp8wAAAMM\"]
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 10:10:00
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.44.144.37 (37.144.44.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.44.144.37 (37.144.44.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 06:09:53.771106 2026] [security2:error] [pid 8577:tid 8577] [client 34.44.144.37:23722] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.tersch.com"] [uri "/@fs/app/.env"] [unique_id "ap6NceEXM6-tuB9NVMBl9QAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 09:08:22
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.44.144.37 (37.144.44.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.44.144.37 (37.144.44.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 05:08:16.717322 2026] [security2:error] [pid 25535:tid 25535] [client 34.44.144.37:38516] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.clustershow.com"] [uri "/@fs/../.env"] [unique_id "ap5_AGM33f3REEKauy8JfQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
ConsulHosting
2026-09-07 08:57:03
(19 hours ago)
Automatically blocked due to distributed attack
Hacking
🇺🇸
TPI-Abuse
2026-09-07 08:39:56
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.44.144.37 (37.144.44.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.44.144.37 (37.144.44.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 04:39:52.255982 2026] [security2:error] [pid 13186:tid 13186] [client 34.44.144.37:12178] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.windisfun.com"] [uri "/@fs/../../.env"] [unique_id "ap54WMoj6e-6inFu604IsAAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇸🇪
vaia.cloud
2026-09-07 08:15:42
(19 hours ago)
crowdsecurity/http-probing
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 07:36:37
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.44.144.37 (37.144.44.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.44.144.37 (37.144.44.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 03:36:31.113141 2026] [security2:error] [pid 10346:tid 10346] [client 34.44.144.37:35810] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.delicatessefoods.com"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252fapp/.env"] [unique_id "ap5pfy10M6WO9naAYujELAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇪
cmbplf
2026-09-07 06:31:44
(21 hours ago)
518 requests with url.path *.azure/*
434 requests with url.path *config.json
433 requests with ur ...
show more
518 requests with url.path *.azure/*
434 requests with url.path *config.json
433 requests with url.path *credentials.json
152 requests with url.path */auth.json
show less
Brute-Force
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-07 06:30:46
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.44.144.37 (37.144.44.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.44.144.37 (37.144.44.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 02:30:40.894325 2026] [security2:error] [pid 21440:tid 21440] [client 34.44.144.37:7094] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.peazy.net"] [uri "/@fs/../../.env"] [unique_id "ap5aEI2bCEo0LSVfTHjUSgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
masterguru
2026-09-07 06:28:48
(21 hours ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-193)
Hacking
Web App Attack
Anonymous
2026-09-07 05:44:58
(22 hours ago)
Aggressive web scan
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 05:42:15
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.44.144.37 (37.144.44.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.44.144.37 (37.144.44.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 01:42:10.744645 2026] [security2:error] [pid 14493:tid 14493] [client 34.44.144.37:57640] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.iconbizpromo.com"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252froot/.env"] [unique_id "ap5OspdyoF9lo0j95WA9FAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
dynamix
2026-09-07 05:31:45
(22 hours ago)
Multiple WAF Violations
Web App Attack
🇳🇱
Site.eu
2026-09-07 05:26:57
(22 hours ago)
Excessive multi-domain requests
Brute-Force
🇺🇸
TPI-Abuse
2026-09-07 05:10:18
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.44.144.37 (37.144.44.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.44.144.37 (37.144.44.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 01:10:10.028419 2026] [security2:error] [pid 12946:tid 12946] [client 34.44.144.37:18946] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "evtoy.danged.com"] [uri "/@fs/app/.env"] [unique_id "ap5HMu9CjJ6mPhbZFqO8PgAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack