🇺🇸
TPI-Abuse
2026-09-08 03:03:38
(19 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.6.26.171 (171.26.6.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.6.26.171 (171.26.6.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 23:03:30.959798 2026] [security2:error] [pid 4133:tid 4133] [client 34.6.26.171:36484] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.overlandpublishing.com"] [uri "/@fs/root/.env"] [unique_id "ap97AlEN1TLaYnMFxzA8dQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
masterguru
2026-09-08 02:51:37
(31 minutes ago)
Restricted File Access Attempt. Matched phrase "/@fs/" at REQUEST_FILENAME. (930130-201)
Hacking
Web App Attack
Anonymous
2026-09-08 02:37:12
(46 minutes ago)
Bot / seems abusive / Apache connections: 66
DDoS Attack
Web Spam
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 02:26:43
(56 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.6.26.171 (171.26.6.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.6.26.171 (171.26.6.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 22:26:38.135896 2026] [security2:error] [pid 29452:tid 29452] [client 34.6.26.171:30732] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.pamplonaserviciotecnico.com"] [uri "/@fs/app/.env"] [unique_id "ap9yXvDZDaiaOCKi39qJHwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
Octopuce
2026-09-08 02:19:36
(1 hour ago)
Aggressive web search of vulnerable pages: /.env.local /assets../.env /v1/.env /uploads../.env /imag ...
show more
Aggressive web search of vulnerable pages: /.env.local /assets../.env /v1/.env /uploads../.env /images../.env ...
show less
Web App Attack
🇺🇸
nyt
2026-09-08 02:05:03
(1 hour ago)
Path Traversal, Sensitive File Probe, Empty UA + error
Web App Attack
Anonymous
2026-09-08 02:00:09
(1 hour ago)
34.6.26.171 - - [08/Sep/2026:04:00:08 +0200] "GET /@fs/src/.env?raw?? HTTP/1.1" 404 124 "-" "Mozilla ...
show more
34.6.26.171 - - [08/Sep/2026:04:00:08 +0200] "GET /@fs/src/.env?raw?? HTTP/1.1" 404 124 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 13_6_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.6 Safari/605.1.15; compatible; LinkedInBot/1.0; +http://www.linkedin.com"
34.6.26.171 - - [08/Sep/2026:04:00:08 +0200] "GET /@fs/.env?raw?? HTTP/1.1" 403 124 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; GPTBot/1.4; +https://openai.com/gptbot)"
34.6.26.171 - - [08/Sep/2026:04:00:08 +0200] "GET /@fs/root/.env?raw?? HTTP/1.1" 404 124 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:121.10) Gecko/20100101 Firefox/121.10; compatible; GrokBot/1.0; +https://x.ai/grokbot"
34.6.26.171 - - [08/Sep/2026:04:00:08 +0200] "GET /@fs/etc/passwd?raw?? HTTP/1.1" 403 183 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.3341.11 Safari/537.36 Edg/126.0.3341.11; compatible; OAI-SearchBot/1.3; +https://openai.com/searchbot"
34.6.26.171 - - [08/Sep/2
...
show less
Bad Web Bot
Web App Attack
🇩🇪
bescared
2026-09-08 00:56:19
(2 hours ago)
F2B - Malicious activity detected. DoS / Heavy Crawling. -8ff06ede-
Bad Web Bot
Web App Attack
🇩🇪
XICTRON
2026-09-08 00:55:07
(2 hours ago)
ModSecurity rule violation detected by Fail2Ban
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 00:53:35
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.6.26.171 (171.26.6.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.6.26.171 (171.26.6.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 20:53:30.645011 2026] [security2:error] [pid 28680:tid 28680] [client 34.6.26.171:44876] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.delunas.thelowensteinfamily.com"] [uri "/@fs/.env"] [unique_id "ap9cihzZiiSZP_iJEhnhmQAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
poundawebsiteltd
2026-09-08 00:46:48
(2 hours ago)
Malicious activity in general-malicious. Evidence: (apache_probe) Failed Access (403/404) 34.6.26.17 ...
show more
Malicious activity in general-malicious. Evidence: (apache_probe) Failed Access (403/404) 34.6.26.171 (NL/The Netherlands/[REDACTED_DOMAIN]): 20 in the last 3600 secs | UA: (apache_probe) Failed Access (403/404) 34.6.26.171 (NL/The Netherlands/171.26.6.34.bc.googleusercontent.com): 20 in the last 3600 secs
show less
Brute-Force
Web App Attack
🇫🇷
ELYAZ
2026-09-08 00:37:39
(2 hours ago)
(y3) Failed access -byebye- from 34.6.26.171 (171.26.6.34.bc.googleusercontent.com): (CF_ENABLE)
Hacking
🇺🇸
TPI-Abuse
2026-09-08 00:27:42
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.6.26.171 (171.26.6.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.6.26.171 (171.26.6.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 20:27:34.710178 2026] [security2:error] [pid 4409:tid 4409] [client 34.6.26.171:25410] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.styxfreeworld.com"] [uri "/@fs/app/.env"] [unique_id "ap9WduX4PDkn3B6_PjTKwQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-08 00:17:09
(3 hours ago)
Multiple web server 400 error codes from same source ip
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 23:31:45
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.6.26.171 (171.26.6.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.6.26.171 (171.26.6.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 19:31:39.599576 2026] [security2:error] [pid 8239:tid 8239] [client 34.6.26.171:14002] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "estudio-altamirano.com"] [uri "/@fs/.env"] [unique_id "ap9JW4gHUr_1EZAvlLqS7gAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack