๐บ๐ธ
TPI-Abuse
2026-08-29 00:37:54
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.6.248.113 (113.248.6.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.6.248.113 (113.248.6.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 20:37:49.200187 2026] [security2:error] [pid 19873:tid 19873] [client 34.6.248.113:21402] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "skomax.com.alanmariotti.com"] [uri "/@fs/.env"] [unique_id "apIp3V1K-Q6qgc5Z4cL6VQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 00:16:34
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.6.248.113 (113.248.6.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.6.248.113 (113.248.6.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 20:16:28.639763 2026] [security2:error] [pid 2118:tid 2266] [client 34.6.248.113:52572] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "clmtic.es"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252fapp/.env"] [unique_id "apIk3MCENKGScZFEot5dPQAAAVY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Octopuce
2026-08-29 00:11:47
(1 hour ago)
Aggressive web search of vulnerable pages: /.env /_nuxt/../.env /assets../.env /uploads../.env /.doc ...
show more
Aggressive web search of vulnerable pages: /.env /_nuxt/../.env /assets../.env /uploads../.env /.docker/.env ...
show less
Web App Attack
๐ฌ๐ง
Celtic
2026-08-29 00:10:05
(1 hour ago)
Blocked by Fail2Ban with Jail (plesk-modsecurity)
Brute-Force
SSH
๐ฉ๐ช
Balthasar Morpheus Jรถrmundur (JKweb Service)
2026-08-28 23:54:57
(1 hour ago)
JKweb Security: Severe and dangerous web attack detected. Vulnerability Wordpress Scanning, Director ...
show more
JKweb Security: Severe and dangerous web attack detected. Vulnerability Wordpress Scanning, Directory Brute-Forcing / Content Discovery, Predictable Resource Location / Forced Browsing, Scan for administration and debugging interfaces of modern frameworks, Scan for Spring Boot Actuator Leaks, Scan for Cloud & Infrastructure Credentials, Scan for Database & Backup Dumps, Scan for IDE- und Editor-Configurations, Scan for CI/CD Pipelines & GitHub Workflows etc. The Attacker is permanently banned by Fail2Ban, configurate by JKweb Security a brand of JKweb Service.
show less
Port Scan
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 23:44:49
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.6.248.113 (113.248.6.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.6.248.113 (113.248.6.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 19:44:43.887113 2026] [security2:error] [pid 23019:tid 23019] [client 34.6.248.113:39704] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.maunakeavista.com"] [uri "/@fs/../.env"] [unique_id "apIda6i9rAeAkbn1Mt1aVAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 23:16:54
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.6.248.113 (113.248.6.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.6.248.113 (113.248.6.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 19:16:50.451926 2026] [security2:error] [pid 22442:tid 22442] [client 34.6.248.113:51782] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.scperu.net"] [uri "/@fs/app/.env"] [unique_id "apIW4slervn29FrZigCWSwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alboweb B.V.
2026-08-28 23:11:04
(2 hours ago)
Bad web bot activity detected by Fail2Ban in plesk-apache-badbot jail
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-08-28 22:59:31
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.6.248.113 (113.248.6.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.6.248.113 (113.248.6.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 18:59:25.609549 2026] [security2:error] [pid 13599:tid 13599] [client 34.6.248.113:45038] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.davidsonroadselfstorage.com"] [uri "/@fs/.env"] [unique_id "apISzb1_Eo_dNAEPBs1BMAAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ช
vaia.cloud
2026-08-28 22:50:05
(2 hours ago)
crowdsecurity/http-path-traversal-probing
Brute-Force
Web App Attack
๐ซ๐ท
dynamix
2026-08-28 22:44:56
(2 hours ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
antlac1
2026-08-28 22:33:01
(3 hours ago)
crowdsecurity/http-probing
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 22:25:17
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.6.248.113 (113.248.6.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.6.248.113 (113.248.6.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 18:25:09.041841 2026] [security2:error] [pid 16751:tid 16751] [client 34.6.248.113:53638] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "isjustanasshole.anthonyjoseph.us"] [uri "/@fs/.env"] [unique_id "apIKxfjcmU9LQtRsQLdZEQAAADA"]
show less
Brute-Force
Bad Web Bot
Web App Attack