🇺🇸
Rocky Mountain Bioengineering Symposium
2026-09-09 17:14:08
(10 minutes ago)
[Wed Sep 09 11:14:08.018291 2026] [authz_core:error] [pid 161137:tid 139766230124096] [client 34.80. ...
show more
[Wed Sep 09 11:14:08.018291 2026] [authz_core:error] [pid 161137:tid 139766230124096] [client 34.80.162.18:33072] AH01630: client denied by server configuration: /var/www/horde/.env.bak
[Wed Sep 09 11:14:08.040647 2026] [authz_core:error] [pid 160666:tid 139763856168512] [client 34.80.162.18:33190] AH01630: client denied by server configuration: /var/www/horde/config/.env
[Wed Sep 09 11:14:08.066685 2026] [authz_core:error] [pid 160666:tid 139763763848768] [client 34.80.162.18:33116] AH01630: client denied by server configuration: /var/www/horde/.env.swp
...
show less
Bad Web Bot
🇦🇹
penguin-solutions.at
2026-09-09 16:41:41
(42 minutes ago)
Excessive 403/404 errors
...
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 16:28:54
(55 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.80.162.18 (18.162.80.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.162.18 (18.162.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 12:28:47.980533 2026] [security2:error] [pid 16436:tid 16436] [client 34.80.162.18:2780] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.hisfavorite.net"] [uri "/@fs/app/.env"] [unique_id "aqGJPy1o34zwJ7_CtfMHMAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 13:33:14
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.80.162.18 (18.162.80.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.162.18 (18.162.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 09:33:09.502526 2026] [security2:error] [pid 1492918:tid 1492918] [client 34.80.162.18:54002] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.jbernsteinpc.com"] [uri "/@fs/.env.production"] [unique_id "aqFgFbpTJdWm57PFtiiwSgAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
FeG Deutschland
2026-09-09 13:25:56
(3 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 127
Exploited Host
Web App Attack
🇨🇿
antihack.anarchista.xyz
2026-09-09 13:17:54
(4 hours ago)
404 burst: 30 hits in 10 min, URI /aws_credentials, Ref , UA Mozilla/5.0 AppleWebKit/537.36 (KHTML, ...
show more
404 burst: 30 hits in 10 min, URI /aws_credentials, Ref , UA Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; Claude-User/1.0; +https://www.anthropic.com/claude-user
show less
Brute-Force
Web App Attack
Bad Web Bot
🇩🇪
ger-stg-sifi1
2026-09-09 12:48:54
(4 hours ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 12:09:01
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.80.162.18 (18.162.80.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.162.18 (18.162.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 08:08:55.007124 2026] [security2:error] [pid 29611:tid 29618] [client 34.80.162.18:33470] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.lbakkercpa.com"] [uri "/@fs/.env"] [unique_id "aqFMV1CIwxOLgbZuZdU2RgAAAQA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇪
madeit
2026-09-09 11:52:10
(5 hours ago)
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 11:50:30
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.80.162.18 (18.162.80.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.162.18 (18.162.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 07:50:26.314345 2026] [security2:error] [pid 3074:tid 3074] [client 34.80.162.18:19232] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.johnhansonmemorial.org"] [uri "/@fs/app/.env"] [unique_id "aqFIAmcqO5Y7TWjtEVzf6QAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 09:44:47
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.80.162.18 (18.162.80.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.162.18 (18.162.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 05:44:40.296500 2026] [security2:error] [pid 32076:tid 32092] [client 34.80.162.18:63794] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.alicefaye.com"] [uri "/@fs/src/.env"] [unique_id "aqEqiF__EsbGxa-Z_Hn95gAAAUk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
masterguru
2026-09-09 09:17:46
(8 hours ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-196)
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 09:15:47
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.80.162.18 (18.162.80.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.162.18 (18.162.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 05:15:43.527275 2026] [security2:error] [pid 18271:tid 18271] [client 34.80.162.18:31294] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.intellectualcapitalmanagementsystems.com"] [uri "/@fs/root/.env"] [unique_id "aqEjvyeo0CSKNcoVw69sBgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 08:26:00
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.80.162.18 (18.162.80.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.162.18 (18.162.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 04:25:54.186746 2026] [security2:error] [pid 1093481:tid 1093752] [client 34.80.162.18:4662] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.starlinksales.net.exede-sales.com"] [uri "/@fs/root/.env"] [unique_id "aqEYEtpM8Id282k46yL-YQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇿
Antinson
2026-09-09 08:23:47
(9 hours ago)
Scraping with a high error ratio and request rate
Bad Web Bot