🇺🇸
TPI-Abuse
2026-09-04 15:38:10
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.6.5.194 (194.5.6.34.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:210492) triggered by 34.6.5.194 (194.5.6.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 11:38:03.939223 2026] [security2:error] [pid 12339:tid 12339] [client 34.6.5.194:18570] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.timberwolf-construction.com"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252froot/.env"] [unique_id "aprl29jLo1VBboGn2pvo6QAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
FeG Deutschland
2026-09-04 14:41:53
(3 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 1247
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 14:25:41
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.6.5.194 (194.5.6.34.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:210492) triggered by 34.6.5.194 (194.5.6.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 10:25:36.932012 2026] [security2:error] [pid 1656:tid 1656] [client 34.6.5.194:8188] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.jerren.seizetheseason.com"] [uri "/@fs/.env"] [unique_id "aprU4L0soVuCJv90RlueXgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇷🇴
clauss
2026-09-04 14:09:36
(3 hours ago)
34.6.5.194 - - [04/Sep/2026:17:09:36 +0300] "GET /@fs/home/debian/.aws/credentials?raw?? HTTP/2.0" 4 ...
show more
34.6.5.194 - - [04/Sep/2026:17:09:36 +0300] "GET /@fs/home/debian/.aws/credentials?raw?? HTTP/2.0" 404 201 "-" "Mozilla/5.0 (compatible; Applebot/0.1; +http://www.apple.com/go/applebot)"
34.6.5.194 - - [04/Sep/2026:17:09:36 +0300] "GET /@fs/.env.staging?raw?? HTTP/2.0" 403 207 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; LinkedInBot/1.0; +http://www.linkedin.com)"
...
show less
Web App Attack
🇩🇪
pscriptos
2026-09-04 11:04:40
(6 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
🇪🇸
el-brujo
2026-09-04 10:26:38
(7 hours ago)
04/Sep/2026:12:26:37.300938 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client ...
show more
04/Sep/2026:12:26:37.300938 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 34.6.5.194] ModSecurity: Warning. Matched phrase ".aws/config" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "125"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: .aws/config found within REQUEST_FILENAME: /@fs/home/node/.aws/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "hwagm.elhacker.net"] [uri "/@fs/home/node/.aws/config"] [unique_id "apqc3bOS1-CaXOmNXMYhvQADngE"]
...
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 09:49:09
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.6.5.194 (194.5.6.34.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:210492) triggered by 34.6.5.194 (194.5.6.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 05:49:05.110757 2026] [security2:error] [pid 28675:tid 28675] [client 34.6.5.194:64566] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.kalvannaawards.com"] [uri "/@fs/src/.env"] [unique_id "apqUEQhUUF7IFOcMJwSbuwAAAFQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇦🇺
rubixstudios
2026-09-04 09:34:02
(8 hours ago)
Excessive HTTP requests consistent with automated attack behaviour detected by Imunify360
DDoS Attack
Brute-Force
Web App Attack
🇬🇧
Apache
2026-09-04 07:35:57
(10 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.6.5.194 (194.5.6.34.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:210730) triggered by 34.6.5.194 (194.5.6.34.bc.googleusercontent.com): 5 in the last 300 secs
show less
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 06:29:52
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.6.5.194 (194.5.6.34.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:210492) triggered by 34.6.5.194 (194.5.6.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 02:29:45.546743 2026] [security2:error] [pid 17608:tid 17608] [client 34.6.5.194:51828] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.maverickhousellc.com"] [uri "/@fs/.env"] [unique_id "applWQ5s0JXc8jyW5J2KiwAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
masterguru
2026-09-04 06:18:47
(11 hours ago)
Restricted File Access Attempt. Matched phrase "/@fs/" at REQUEST_FILENAME. (930130-193)
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 06:07:05
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.6.5.194 (194.5.6.34.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:210492) triggered by 34.6.5.194 (194.5.6.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 02:07:00.947672 2026] [security2:error] [pid 19524:tid 19524] [client 34.6.5.194:56380] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.adoniahenterprises.com"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252fapp/.env"] [unique_id "appgBOuvggz-403Kkwp3WwAAACc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
LRob
2026-09-04 05:49:41
(12 hours ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /@fs/root/.env (+11 more) | 2026-09-04 05:49 UTC
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 05:03:36
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.6.5.194 (194.5.6.34.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:210492) triggered by 34.6.5.194 (194.5.6.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 01:03:30.739686 2026] [security2:error] [pid 14389:tid 14389] [client 34.6.5.194:28008] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.mcbear.net"] [uri "/@fs/.env"] [unique_id "appRIqPTHUm-HMWKt7y_HgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇱🇹
Evag Touf
2026-09-04 04:51:41
(13 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 34.6.5.194 (194.5.6.34.bc.googleusercon ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.6.5.194 (194.5.6.34.bc.googleusercontent.com)
show less
SQL Injection