🇳🇱
homeshowdomain.nl
2026-09-07 22:01:35
(1 hour ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-06.
show less
Web App Attack
SSH
Hacking
🇺🇸
mnsf
2026-09-07 10:05:30
(13 hours ago)
Scanning/Probing (20)
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 09:49:30
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.56.93.76 (76.93.56.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.56.93.76 (76.93.56.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 05:49:25.067118 2026] [security2:error] [pid 29878:tid 29878] [client 34.56.93.76:22586] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.dorismitchell.com"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252fapp/.env"] [unique_id "ap6IpWN70hyWBBbsluRmKgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 09:03:09
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.56.93.76 (76.93.56.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.56.93.76 (76.93.56.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 05:03:00.699900 2026] [security2:error] [pid 10370:tid 10370] [client 34.56.93.76:6774] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.register-yacht-belize.com.yacht-register-holland.com"] [uri "/@fs/.env.development"] [unique_id "ap59xKtGSFGm5VfKn1Vs6gAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇸🇪
vaia.cloud
2026-09-07 08:35:15
(15 hours ago)
crowdsecurity/http-probing
Brute-Force
Web App Attack
🇧🇪
cmbplf
2026-09-07 08:30:47
(15 hours ago)
3.514 requests with url.path */@fs/*
479 requests with url.path *config.json
448 requests with ur ...
show more
3.514 requests with url.path */@fs/*
479 requests with url.path *config.json
448 requests with url.path *.azure/*
374 requests with url.path *.config/*
309 requests with url.path *credentials.json
235 requests with url.path */proc/*
221 requests with url.path *.ssh/*
149 requests with url.path */auth.json
110 requests with url.path *config.php
108 requests with url.path *.local/share/*
show less
Brute-Force
Bad Web Bot
Anonymous
2026-09-07 08:09:39
(15 hours ago)
Aggressive web scan
Web App Attack
🇪🇸
alferez
2026-09-07 07:47:50
(16 hours ago)
Searching .(env|sql|zip|tar|rar) files
Hacking
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 07:42:50
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.56.93.76 (76.93.56.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.56.93.76 (76.93.56.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 03:42:42.743519 2026] [security2:error] [pid 15370:tid 15370] [client 34.56.93.76:28556] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.oshadega.com"] [uri "/@fs/.env"] [unique_id "ap5q8po-vuqcMniFGN0-7AAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 07:10:31
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.56.93.76 (76.93.56.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.56.93.76 (76.93.56.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 03:10:28.090912 2026] [security2:error] [pid 13429:tid 13429] [client 34.56.93.76:36146] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.mw-creations.com"] [uri "/@fs/.env.production"] [unique_id "ap5jZHFgpcJdCFWczLzBCgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇦🇹
penguin-solutions.at
2026-09-07 07:06:59
(16 hours ago)
Excessive 403/404 errors
...
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 06:49:58
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.56.93.76 (76.93.56.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.56.93.76 (76.93.56.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 02:49:49.302286 2026] [security2:error] [pid 11734:tid 11752] [client 34.56.93.76:4862] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.briteh.com"] [uri "/@fs/.env.local"] [unique_id "ap5ejaiqcDWugjfHnMJT0gAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-09-07 06:49:41
(16 hours ago)
Web attack/malicious scanning detected
Web App Attack
🇩🇪
Nightreaver
2026-09-07 06:19:49
(17 hours ago)
34.56.93.76 - - [07/Sep/2026:08:19:48 0200] "GET /@fs/.env.local?raw?? HTTP/1.1" 404 3182 "-" "Mozi ...
show more
34.56.93.76 - - [07/Sep/2026:08:19:48 0200] "GET /@fs/.env.local?raw?? HTTP/1.1" 404 3182 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14.5; rv:127.2) Gecko/20100101 Firefox/127.2; compatible; LinkedInBot/1.0; http://www.linkedin.com"
34.56.93.76 - - [07/Sep/2026:08:19:48 0200] "GET /@fs/app/.env?raw?? HTTP/1.1" 404 3174 "-" "Mozilla/5.0 (Windows NT 11.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; [email protected] ) Chrome/120.0.7026.202 Safari/537.36 Edg/120.0.7026.202"
34.56.93.76 - - [07/Sep/2026:08:19:48 0200] "GET /@fs/..%2f..%2f..%2f..%2f..%2froot/.env?raw?? HTTP/1.1" 404 3178 "-" "Mozilla/5.0 (Linux; Android 15; SM-S918B) AppleWebKit/537.36 (KHTML, like Gecko; compatible; Applebot/0.1; http://www.apple.com/go/applebot) Chrome/131.0.5465.22 Mobile Safari/537.36"
34.56.93.76 - - [07/Sep/2026:08:19:48 0200] "GET /@fs/proc/self/environ?raw?? HTTP/1.1" 404 3172 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14_5) AppleWebKit/537.36 (KHTML, like Gecko) C[...]
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 05:56:50
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.56.93.76 (76.93.56.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.56.93.76 (76.93.56.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 01:56:42.823372 2026] [security2:error] [pid 22867:tid 22889] [client 34.56.93.76:56958] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "barneysprecision.jd-web-designs.com"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252fapp/.env"] [unique_id "ap5SGsZ3yN94iy-XlgFAJwAAAZQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack