🇺🇦
URAN Publishing Service
2026-09-09 10:40:05
(1 hour ago)
[09/Sep/2026:13:40:05 +0300] -- 34.80.76.86 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET /@f ...
show more
[09/Sep/2026:13:40:05 +0300] -- 34.80.76.86 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET /@fs/../../.env?raw?? HTTP/1.1
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 10:27:07
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.80.76.86 (86.76.80.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.76.86 (86.76.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 06:27:03.689383 2026] [security2:error] [pid 14521:tid 14521] [client 34.80.76.86:44116] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.aprilparks.com"] [uri "/@fs/.env"] [unique_id "aqE0d-9DTj_9cxr-cA2bAAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇷🇺
ago.su
2026-09-09 10:14:54
(1 hour ago)
F2B blocked nginx activity control ddos v1 [otd]
DDoS Attack
🇩🇪
big-cloud.nl
2026-09-09 10:01:50
(1 hour ago)
Try to access /@fs/.env?raw??
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 09:58:41
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.80.76.86 (86.76.80.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.76.86 (86.76.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 05:58:34.949864 2026] [security2:error] [pid 19258:tid 19258] [client 34.80.76.86:17614] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "armstrongpartnersllc.com.ssl-grp.com"] [uri "/@fs/root/.env"] [unique_id "aqEtyvGJbvurkoF3DhqvQwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 09:36:52
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.80.76.86 (86.76.80.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.76.86 (86.76.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 05:36:47.898483 2026] [security2:error] [pid 1161445:tid 1161461] [client 34.80.76.86:49334] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cmykdesign.com"] [uri "/@fs/root/.env"] [unique_id "aqEor5ckmhtXhDtU5qdCDgAAAMs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
masterguru
2026-09-09 09:05:24
(2 hours ago)
Restricted File Access Attempt. Matched phrase "/@fs/" at REQUEST_FILENAME. (930130-201)
Hacking
Web App Attack
🇩🇪
Hazzard
2026-09-09 08:59:39
(2 hours ago)
(mod_security) mod_security triggered on hostname [redacted]): (CF_ENABLE)
SQL Injection
🇩🇪
TheDjRider
2026-09-09 08:36:44
(3 hours ago)
CrowdSec detected Web application reconnaissance. Scenario: local/framework-recon. Automatic ban tri ...
show more
CrowdSec detected Web application reconnaissance. Scenario: local/framework-recon. Automatic ban triggered. Detection time (UTC): 2026-09-09T08:36:41.620070052Z. Context: http_status=200
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 07:41:37
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.80.76.86 (86.76.80.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.76.86 (86.76.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 03:41:31.101620 2026] [security2:error] [pid 25959:tid 25959] [client 34.80.76.86:19410] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "williammaderas.com"] [uri "/@fs/.env.local"] [unique_id "aqENqzdAazA-S7nvx4tpeQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-09 07:31:13
(4 hours ago)
Bot / seems abusive / Apache connections: 30
DDoS Attack
Web Spam
Bad Web Bot
Web App Attack
🇸🇮
extremevital
2026-09-09 07:30:22
(4 hours ago)
34.80.76.86 [09/Sep/2026:09:30:22 +0200] RATELIMIT: "GET /api/v1/settings HTTP/1.1" 401 172 0.000 "M ...
show more
34.80.76.86 [09/Sep/2026:09:30:22 +0200] RATELIMIT: "GET /api/v1/settings HTTP/1.1" 401 172 0.000 "Mozilla/5.0 (iPhone; CPU iPhone OS 16_4 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko; compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot) Version/18.1 Mobile/15E148 Safari/604.1"
...
show less
Bad Web Bot
🇸🇪
vaia.cloud
2026-09-09 07:10:06
(4 hours ago)
crowdsecurity/http-probing
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 06:18:27
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.80.76.86 (86.76.80.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.76.86 (86.76.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 02:18:22.049947 2026] [security2:error] [pid 24511:tid 24511] [client 34.80.76.86:11846] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "juca.imerka.com.mx"] [uri "/@fs/src/.env"] [unique_id "aqD6LvZDDKwGWkUe3YoZXwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
paissangroup
2026-09-09 06:15:53
(5 hours ago)
Multiple WAF Violations
Web App Attack