Anonymous
2026-08-29 00:45:47
(6 minutes ago)
GET /@fs/.env?raw?? HTTP/1.1
...
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 00:41:57
(10 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.52.233.48 (48.233.52.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.52.233.48 (48.233.52.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 20:41:50.942855 2026] [security2:error] [pid 18051:tid 18051] [client 34.52.233.48:58084] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.deltasouls.com"] [uri "/@fs/src/.env"] [unique_id "apIqzl0mcpJp4TWEaI3ErwAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Bedios GmbH
2026-08-29 00:40:47
(11 minutes ago)
Login credentials theft attempt
Hacking
๐บ๐ธ
IndigoRidge
2026-08-29 00:35:52
(16 minutes ago)
34.52.233.48 - - [28/Aug/2026:20:35:51 -0400] "GET /@fs/src/.env?raw?? HTTP/1.0" 403 5545 "-" "Mozil ...
show more
34.52.233.48 - - [28/Aug/2026:20:35:51 -0400] "GET /@fs/src/.env?raw?? HTTP/1.0" 403 5545 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Applebot/0.1; +http://www.apple.com/go/applebot)"
34.52.233.48 - - [28/Aug/2026:20:35:51 -0400] "GET /@fs/app/.env?raw?? HTTP/1.0" 403 5545 "-" "Mozilla/5.0 (Linux; Android 15; SM-S918B) AppleWebKit/537.36 (KHTML, like Gecko; compatible; TelegramBot/1.0) Chrome/131.0.1915.182 Mobile Safari/537.36"
34.52.233.48 - - [28/Aug/2026:20:35:51 -0400] "GET /@fs/..%252f..%252f..%252f..%252f..%252froot/.env?raw?? HTTP/1.0" 403 5545 "-" "Mozilla/5.0 (compatible; meta-externalagent/1.1; +https://developers.facebook.com/docs/sharing/webmasters/crawler)"
...
show less
Web App Attack
๐ฌ๐ง
consul.to
2026-08-29 00:19:33
(32 minutes ago)
Web attack/malicious scanning detected
Web App Attack
๐ณ๐ฑ
Alboweb B.V.
2026-08-29 00:11:22
(40 minutes ago)
Bad web bot activity detected by Fail2Ban in plesk-apache-badbot jail
Bad Web Bot
๐ซ๐ท
Octopuce
2026-08-28 23:58:25
(53 minutes ago)
Aggressive web search of vulnerable pages: /assets../.env /uploads../.env /_nuxt/../.env /.docker/.e ...
show more
Aggressive web search of vulnerable pages: /assets../.env /uploads../.env /_nuxt/../.env /.docker/.env /server/.env ...
show less
Web App Attack
๐จ๐ญ
4server
2026-08-28 23:49:56
(1 hour ago)
[SatAug2901:49:52.2650862026][security2:error][pid3531134:tid3531375][client34.52.233.48:0]ModSecuri ...
show more
[SatAug2901:49:52.2650862026][security2:error][pid3531134:tid3531375][client34.52.233.48:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".env\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"610\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"www.mio-ip.aidconsultancy.ch\"][uri\"/@fs/root/.env\"][unique_id\"apIeoGbFRd8PLAEtFCGzigAAAhQ\"]
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 23:27:37
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.52.233.48 (48.233.52.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.52.233.48 (48.233.52.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 19:27:32.989578 2026] [security2:error] [pid 14705:tid 14705] [client 34.52.233.48:57716] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.register-yacht-greece.com.yacht-register-holland.com"] [uri "/@fs/.env"] [unique_id "apIZZEsKhbhV5s_jlmbzrwAAAEE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-08-28 23:10:03
(1 hour ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 23:05:57
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.52.233.48 (48.233.52.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.52.233.48 (48.233.52.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 19:05:49.953064 2026] [security2:error] [pid 14920:tid 14920] [client 34.52.233.48:13114] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.casatualiving.com"] [uri "/@fs/.env.staging"] [unique_id "apIUTa4-PKTCErXO-zrFggAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 22:37:43
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.52.233.48 (48.233.52.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.52.233.48 (48.233.52.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 18:37:34.841341 2026] [security2:error] [pid 1790:tid 1790] [client 34.52.233.48:9308] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.planetezfind.com"] [uri "/@fs/src/.env"] [unique_id "apINrpLJ6Mf2srmy31QQJwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Savvii
2026-08-28 22:37:11
(2 hours ago)
20 attempts against mh-misbehave-ban on pea
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-28 22:35:39
(2 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 34.52.233.48 (BE/Belgium/48.233.52.34.b ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.52.233.48 (BE/Belgium/48.233.52.34.bc.googleusercontent.com)
show less
SQL Injection
๐ณ๐ฑ
ConsulHosting
2026-08-28 22:17:59
(2 hours ago)
Automatically blocked due to distributed attack
Hacking