🇺🇸
TPI-Abuse
2026-09-07 10:40:24
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.74.245.137 (137.245.74.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.74.245.137 (137.245.74.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 06:40:20.585042 2026] [security2:error] [pid 22348:tid 22348] [client 34.74.245.137:43572] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "frickandfracks.com"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252fapp/.env"] [unique_id "ap6UlAT5Dpw9y-s6RSdZdQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
FeG Deutschland
2026-09-07 10:37:29
(19 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 127
Exploited Host
Web App Attack
🇸🇪
vaia.cloud
2026-09-07 10:15:02
(19 hours ago)
crowdsecurity/http-probing
Brute-Force
Web App Attack
🇺🇸
WellSpring
2026-09-07 09:39:13
(20 hours ago)
env leak on 626.today/@fs/var/www/html/.env — WellSpr.ing/NetSentinel civic-AI security layer
Web App Attack
🇳🇱
debestelapp
2026-09-07 09:35:12
(20 hours ago)
Web App Attack
🇸🇬
naveeddaros
2026-09-07 09:31:47
(20 hours ago)
HTTP Flood DDoS attack detected
Brute-Force
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-07 08:50:55
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.74.245.137 (137.245.74.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.74.245.137 (137.245.74.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 04:50:49.998619 2026] [security2:error] [pid 20976:tid 20976] [client 34.74.245.137:17244] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.anchordown.jbaydeliveries.com"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252froot/.env"] [unique_id "ap566f0S6kVCk3y9mXyjDQAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇪
cmbplf
2026-09-07 08:50:11
(21 hours ago)
115 requests with url.path */auth.json
Brute-Force
Bad Web Bot
Anonymous
2026-09-07 08:07:39
(21 hours ago)
[Mon Sep 07 10:07:39.427914 2026] [access_compat:error] [pid 2114322:tid 2114322] [client 34.74.245. ...
show more
[Mon Sep 07 10:07:39.427914 2026] [access_compat:error] [pid 2114322:tid 2114322] [client 34.74.245.137:34474] AH01797: client denied by server configuration: /var/www/html/@fs
[Mon Sep 07 10:07:39.457519 2026] [access_compat:error] [pid 2099232:tid 2099232] [client 34.74.245.137:34438] AH01797: client denied by server configuration: /var/www/html/@fs
...
show less
Bad Web Bot
Web App Attack
🇺🇸
mnsf
2026-09-07 08:05:17
(21 hours ago)
Scanning/Probing (12)
Brute-Force
Web App Attack
🇮🇪
AutosOnShow
2026-09-07 07:56:04
(22 hours ago)
blocked for webapp attack | path requested: /.git/config | seen at 2026-09-07 07:55:23.702 |
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 07:16:14
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.74.245.137 (137.245.74.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.74.245.137 (137.245.74.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 03:16:10.491785 2026] [security2:error] [pid 17911:tid 17911] [client 34.74.245.137:37920] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.pinhole.us"] [uri "/@fs/src/.env"] [unique_id "ap5kul3hJoe_eMp3FLHiBwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 06:04:43
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.74.245.137 (137.245.74.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.74.245.137 (137.245.74.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 02:04:39.304404 2026] [security2:error] [pid 3397:tid 3397] [client 34.74.245.137:49642] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "generationedm.joesteiner.com"] [uri "/@fs/../../.env"] [unique_id "ap5T93ei2XWIDmR30tKIXgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Site.eu
2026-09-07 06:00:16
(23 hours ago)
Excessive multi-domain requests
Brute-Force
🇫🇷
Octopuce
2026-09-07 05:38:13
(1 day ago)
Aggressive web search of vulnerable pages: /.env /.env.local /v1/.env /assets../.env /v2/.env ...
Web App Attack