🇩🇪
todix
2026-09-06 16:44:33
(2 hours ago)
Web App Attack Exploid from 34.57.31.136
Web App Attack
🇳🇱
Site.eu
2026-09-06 16:22:02
(3 hours ago)
Excessive multi-domain requests
Brute-Force
🇺🇸
TPI-Abuse
2026-09-06 16:09:13
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.57.31.136 (136.31.57.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.57.31.136 (136.31.57.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 12:09:08.401316 2026] [security2:error] [pid 394947:tid 394947] [client 34.57.31.136:60900] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.xunhung.tonylai.com"] [uri "/@fs/../.env"] [unique_id "ap2QJJYPjZ54ts9AosVDrgAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇭
backslash
2026-09-06 15:48:00
(3 hours ago)
block ruleset WAF detection and high score on abuseIPDB 149EB1B42C242111FADBBC2EF8F90219570691E1
Bad Web Bot
🇺🇸
RamSet
2026-09-06 15:41:19
(3 hours ago)
[ycr] HTTP-Probe on port 443 (via domain). 156 distinct paths probed in 15s. Sustained 312 req/min, ...
show more
[ycr] HTTP-Probe on port 443 (via domain). 156 distinct paths probed in 15s. Sustained 312 req/min, 138 nonexistent paths (404). Paths: /.aws/config, /.aws/credentials, /.env.js, /actuator/env/server.port, /actuator/loggers, /.git/config, /.git/HEAD, /.git-credentials, /server-status, /server-info, /.env, /.env.example, /actuator/configprops, /.env.production, /.env.local, /actuator/mappings, /.env.backup, /@fs/.env?raw&url??, /.env.bak, /@fs/.env?url&raw??, /@fs/.env?import&?raw??, /api/.env, /.env.old, /admin/.env, /backend/.env, /__vite_rsc_findSourceMapURL?filename=file:///root/.aws/credentials&environmentName=rsc, /config/.env, /__vite_rsc_findSourceMapURL?filename=file:///root/.ssh/id_rsa&environmentName=rsc, /userfiles?path=../../../.env, /userfiles?path=../../.env, /userfiles?path=../../../../proc/self/environ, /userfiles?path=../../../../.env, /.env.staging, /.env.development, /.env.test, /config.env, …
show less
Bad Web Bot
Web App Attack
🇩🇪
FD-IX
2026-09-06 15:28:38
(4 hours ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
🇺🇸
NXTwoThou
2026-09-06 15:04:14
(4 hours ago)
/api/.env/public/.env
Web App Attack
🇳🇱
i-turnradio.nl
2026-09-06 14:03:38
(5 hours ago)
2026-09-06 @ 16:03:26 (CET) ~ Blocked for trying to access: /var/run/secrets/kubernetes.io/serviceac ...
show more
2026-09-06 @ 16:03:26 (CET) ~ Blocked for trying to access: /var/run/secrets/kubernetes.io/serviceaccount/token
show less
Web App Attack
🇺🇸
mnsf
2026-09-06 13:05:48
(6 hours ago)
Scanning/Probing (14)
Brute-Force
Web App Attack
🇨🇭
zynex
2026-09-06 10:23:05
(9 hours ago)
URL Probing: /.env
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 10:07:10
(9 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.57.31.136 (136.31.57.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.57.31.136 (136.31.57.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 06:07:05.708836 2026] [security2:error] [pid 686696:tid 686719] [client 34.57.31.136:45128] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||appraisalteam.net|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "appraisalteam.net"] [uri "/rclone.conf"] [unique_id "ap07SVSgEw3EPmiJ5KhcmQAAAFU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Bedios GmbH
2026-09-06 10:05:51
(9 hours ago)
Login credentials theft attempt
Hacking
Anonymous
2026-09-06 10:05:08
(9 hours ago)
WAF repeated trigger detected by Fail2Ban
Web App Attack
🇳🇱
Savvii
2026-09-06 10:03:24
(9 hours ago)
20 attempts against mh-misbehave-ban on frost
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 08:02:00
(11 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.57.31.136 (136.31.57.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.57.31.136 (136.31.57.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 04:01:52.875025 2026] [security2:error] [pid 15733:tid 15733] [client 34.57.31.136:34284] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.xygil.tracybur.net|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.xygil.tracybur.net"] [uri "/rclone.conf"] [unique_id "ap0d8AE7kQln4OOX6U0gxQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack