🇺🇸
mw
2026-09-08 00:01:43
(3 hours ago)
GET /@fs/etc/passwd?raw?? HTTP/1.1
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 20:25:24
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.60.77.39 (39.77.60.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.60.77.39 (39.77.60.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 16:25:19.526657 2026] [security2:error] [pid 6194:tid 6194] [client 34.60.77.39:45154] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.darkcodedesign.com"] [uri "/@fs/../.env"] [unique_id "ap8dryUaO3OsXCoAYvaMnAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
dynamix
2026-09-07 20:22:18
(6 hours ago)
Multiple WAF Violations
Web App Attack
🇺🇸
IndigoRidge
2026-09-07 19:35:28
(7 hours ago)
34.60.77.39 - - [07/Sep/2026:15:35:25 -0400] "GET /@fs/../../.env?raw?? HTTP/1.1" 400 150 "-" "-"
34 ...
show more
34.60.77.39 - - [07/Sep/2026:15:35:25 -0400] "GET /@fs/../../.env?raw?? HTTP/1.1" 400 150 "-" "-"
34.60.77.39 - - [07/Sep/2026:15:35:25 -0400] "GET /@fs/.env?raw?? HTTP/1.1" 404 49568 "-" "Mozilla/5.0 (compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot)"
34.60.77.39 - - [07/Sep/2026:15:35:25 -0400] "GET /@fs/app/.env?raw?? HTTP/1.1" 404 49572 "-" "Mozilla/5.0 (Windows NT 11.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.266.175 Safari/537.36; compatible; Claude-SearchBot/1.0; +https://www.anthropic.com/claude-searchbot"
...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 18:36:58
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.60.77.39 (39.77.60.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.60.77.39 (39.77.60.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 14:36:53.452868 2026] [security2:error] [pid 481134:tid 481206] [client 34.60.77.39:6402] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.touficcorban.com"] [uri "/@fs/../.env"] [unique_id "ap8ERZi16DjEMFL3Oh7FwwAAAFc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
IndigoRidge
2026-09-07 18:01:44
(9 hours ago)
[Mon Sep 07 14:01:06.214130 2026] [authz_core:error] [pid 865801:tid 140274814502656] [client 34.60. ...
show more
[Mon Sep 07 14:01:06.214130 2026] [authz_core:error] [pid 865801:tid 140274814502656] [client 34.60.77.39:0] AH01630: client denied by server configuration: /var/www/vhosts/default/htdocs/@fs
[Mon Sep 07 14:01:21.352211 2026] [authz_core:error] [pid 868458:tid 140274957113088] [client 34.60.77.39:0] AH01630: client denied by server configuration: /var/www/vhosts/default/htdocs/@fs
[Mon Sep 07 14:01:29.146745 2026] [authz_core:error] [pid 865801:tid 140274797717248] [client 34.60.77.39:0] AH01630: client denied by server configuration: /var/www/vhosts/default/htdocs/@vite
[Mon Sep 07 14:01:44.133439 2026] [authz_core:error] [pid 868458:tid 140274705397504] [client 34.60.77.39:0] AH01630: client denied by server configuration: /var/www/vhosts/default/htdocs/.env.example
[Mon Sep 07 14:01:44.134998 2026] [authz_core:error] [pid 868458:tid 140274864793344] [client 34.60.77.39:0] AH01630: client denied by server configuration: /var/www/vhosts/default/htdocs/config
...
show less
Web App Attack
🇫🇷
Octopuce
2026-09-07 17:58:19
(9 hours ago)
Aggressive web search of vulnerable pages: /assets../.env /v2/.env /.docker/.env /_nuxt/../.env /v1/ ...
show more
Aggressive web search of vulnerable pages: /assets../.env /v2/.env /.docker/.env /_nuxt/../.env /v1/.env ...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 17:52:59
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.60.77.39 (39.77.60.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.60.77.39 (39.77.60.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 13:52:52.823492 2026] [security2:error] [pid 10390:tid 10390] [client 34.60.77.39:34176] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kristinmoore.com"] [uri "/@fs/app/.env"] [unique_id "ap759FfebNPJvS-ZFFuEowAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 17:35:18
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.60.77.39 (39.77.60.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.60.77.39 (39.77.60.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 13:35:11.731926 2026] [security2:error] [pid 12844:tid 12844] [client 34.60.77.39:20364] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.bsa1688.com"] [uri "/@fs/src/.env"] [unique_id "ap71z-k0_wCJsEwCykHb8gAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇪
cmbplf
2026-09-07 17:35:02
(9 hours ago)
2.466 requests with url.path */@fs/*
626 requests with url.path *.aws/*
225 requests with url.pat ...
show more
2.466 requests with url.path */@fs/*
626 requests with url.path *.aws/*
225 requests with url.path *.config/*
show less
Brute-Force
Bad Web Bot
🇨🇭
backslash
2026-09-07 17:12:00
(10 hours ago)
block ruleset bad bot: misc bad content F608233CC4C86EE814CE8DDDA9C4A0D3C79882F6
Bad Web Bot
🇨🇭
zynex
2026-09-07 17:07:26
(10 hours ago)
URL Probing: /@fs/var/www/html/.env
Web App Attack
🇺🇸
mnsf
2026-09-07 17:05:44
(10 hours ago)
Too many Status 40X (11)
Brute-Force
Web App Attack
🇪🇸
pipeline.es
2026-09-07 16:37:49
(10 hours ago)
Web scanning / probing for vulnerable paths | URL: /@fs/app/.env?raw?? | Evidence: www.intranetnauta ...
show more
Web scanning / probing for vulnerable paths | URL: /@fs/app/.env?raw?? | Evidence: www.intranetnautaliaviajes.es 34.60.77.39 - - [07/Sep/2026:18:36:54 +0200] \"GET /@fs/app/.env?raw?? HTTP/1.1\" 403 214 \"-\" \"Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Google-Extended/1.0; +http://www.google.com/bot.html)\" GEOIP_COUNTRY_CODE=US | ASN: GOOGLE-CLOUD-PLATFORM | Country: US
show less
Port Scan
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 16:17:24
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.60.77.39 (39.77.60.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.60.77.39 (39.77.60.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 12:17:17.967735 2026] [security2:error] [pid 26675:tid 26675] [client 34.60.77.39:23532] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.aivosminerals.soviaenterprises.com"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252froot/.env"] [unique_id "ap7jjcMVa5vkegwnJvEyLQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack