Anonymous
2026-09-07 08:58:11
(13 minutes ago)
Bot / seems abusive / Apache connections: 40
DDoS Attack
Web Spam
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 08:54:45
(16 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.63.131.94 (94.131.63.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.63.131.94 (94.131.63.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 04:54:39.587475 2026] [security2:error] [pid 5604:tid 5612] [client 34.63.131.94:34228] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.love-spells-magic.com"] [uri "/@fs/app/.env"] [unique_id "ap57z4nqs0skZHdXxkLrWwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 08:35:37
(35 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.63.131.94 (94.131.63.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.63.131.94 (94.131.63.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 04:35:31.508373 2026] [security2:error] [pid 17506:tid 17519] [client 34.63.131.94:12334] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.despachosyoficinas.com"] [uri "/@fs/app/.env"] [unique_id "ap53U_7ILz7Tpwqo1NIWQQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
big-cloud.nl
2026-09-07 08:34:01
(37 minutes ago)
Try to access /@fs/.env?raw??
Web App Attack
🇫🇷
dynamix
2026-09-07 08:28:19
(42 minutes ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 08:12:37
(58 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.63.131.94 (94.131.63.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.63.131.94 (94.131.63.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 04:12:29.795294 2026] [security2:error] [pid 24388:tid 24388] [client 34.63.131.94:6538] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.brickyardinn.com"] [uri "/@fs/.env.local"] [unique_id "ap5x7eKUxi_OEo6w5HxyggAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇲🇾
Rizzy
2026-09-07 08:11:35
(59 minutes ago)
Multiple WAF Violations
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 07:53:14
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.63.131.94 (94.131.63.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.63.131.94 (94.131.63.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 03:53:07.714588 2026] [security2:error] [pid 3746:tid 3746] [client 34.63.131.94:24268] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.escribaniasmith.com.ar"] [uri "/@fs/.env.local"] [unique_id "ap5tYwccdXiCz1j3ZiZ0MwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇪
cmbplf
2026-09-07 07:33:34
(1 hour ago)
3.476 requests with url.path */@fs/*
798 requests with url.path *.aws/*
215 requests with url.pat ...
show more
3.476 requests with url.path */@fs/*
798 requests with url.path *.aws/*
215 requests with url.path *.ssh/*
show less
Brute-Force
Bad Web Bot
🇫🇷
COMAITE
2026-09-07 07:20:47
(1 hour ago)
Common web attack from 34.63.131.94.
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-07 07:14:25
(1 hour ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
🇳🇱
Site.eu
2026-09-07 07:05:14
(2 hours ago)
Excessive multi-domain requests
Brute-Force
🇨🇦
polycoda
2026-09-07 06:57:35
(2 hours ago)
AutoBlock: 🎯 Vulnerability Scanner (Non Decay-Based)
Hacking
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 06:18:01
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.63.131.94 (94.131.63.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.63.131.94 (94.131.63.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 02:17:55.379810 2026] [security2:error] [pid 12523:tid 12523] [client 34.63.131.94:18176] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.gisresults.com"] [uri "/@fs/.env.local"] [unique_id "ap5XE-RNzZBdum-pAG6e7AAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
eselpcore.com
2026-09-07 06:09:47
(3 hours ago)
Requests to non‑existent PHP scripts (web‑shell probing)
Web App Attack