🇺🇸
mw
2026-09-04 01:15:02
(2 hours ago)
GET /@fs/.env.local?raw?? HTTP/1.1
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 00:50:01
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.81.198.210 (210.198.81.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.81.198.210 (210.198.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 20:49:53.181665 2026] [security2:error] [pid 9105:tid 9105] [client 34.81.198.210:47128] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "roommategames.banis-associates.com"] [uri "/@fs/.env"] [unique_id "apoVsXz54MsC1YQF-MMmbgAAACs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
MBombeck
2026-09-04 00:46:08
(2 hours ago)
Fail2Ban/traefik-botsearch on apps-01: banned after 5 failures
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 00:01:23
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.81.198.210 (210.198.81.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.81.198.210 (210.198.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 20:01:12.109480 2026] [security2:error] [pid 24054:tid 24054] [client 34.81.198.210:16806] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "entetanimiento.com"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252fapp/.env"] [unique_id "apoKSIpGAoJ780Bq0ErjwAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-03 23:28:26
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.81.198.210 (210.198.81.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.81.198.210 (210.198.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 19:28:19.635231 2026] [security2:error] [pid 2108:tid 2108] [client 34.81.198.210:57630] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.muebleriamac.com"] [uri "/@fs/app/.env"] [unique_id "apoCkyuao_xiGTzFlSru5gAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇪
cmbplf
2026-09-03 23:11:28
(4 hours ago)
8.250 requests from abuseipdb.com blacklisted IP (1yr5mos14h)
Brute-Force
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-03 22:24:16
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.81.198.210 (210.198.81.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.81.198.210 (210.198.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 18:24:10.638831 2026] [security2:error] [pid 10753:tid 10753] [client 34.81.198.210:48934] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bayinsights.com"] [uri "/@fs/root/.env"] [unique_id "apnzih2jMljU60sNV6lmfgAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-03 22:12:41
(5 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-03 21:45:16
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.81.198.210 (210.198.81.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.81.198.210 (210.198.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 17:45:08.300553 2026] [security2:error] [pid 7940:tid 7940] [client 34.81.198.210:12896] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.namefinder.com"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252froot/.env"] [unique_id "apnqZGisPeoWgOlfhHLCRAAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇸🇪
vaia.cloud
2026-09-03 21:20:06
(5 hours ago)
crowdsecurity/http-probing
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-03 21:01:41
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.81.198.210 (210.198.81.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.81.198.210 (210.198.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 17:01:35.966714 2026] [security2:error] [pid 3128:tid 3128] [client 34.81.198.210:15452] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.grandriverhomes.com"] [uri "/@fs/root/.env"] [unique_id "apngL_wDwZLUihJUzs5Y8AAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
ruusvuu
2026-09-03 21:00:27
(6 hours ago)
Automated abuse report: 25 attack/probe requests from Google LLC / TW.
Targeted paths: /@fs/..%252f. ...
show more
Automated abuse report: 25 attack/probe requests from Google LLC / TW.
Targeted paths: /@fs/..%252f..%252f..%252f..%252f..%252fproc/self/environ, /@fs/etc/passwd, /@fs/proc/self/environ, /@fs/app/amplifyconfiguration.json.
Sample log lines:
[icantell] 34.81.198.210 - - [03/Sep/2026:21:00:19 +0000] "GET /@fs/etc/passwd?raw?? HTTP/1.1" 404 2651 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; +https://w…
[icantell] 34.81.198.210 - - [03/Sep/2026:21:00:19 +0000] "GET /@fs/proc/self/environ?raw?? HTTP/1.1" 404 2651 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; WhatsApp/10.0.2.1"
[icantell] 34.81.198.210 - - [03/Sep/2026:21:00:25 +0000] "GET /@fs/app/amplifyconfiguration.json?raw?? HTTP/1.1" 404 2651 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64) AppleWebKit/537.36 (KHTML, like…
Detected by an automated web-server log monitor.
show less
Web App Attack
🇳🇱
Site.eu
2026-09-03 20:13:31
(7 hours ago)
Excessive multi-domain requests
Brute-Force
🇺🇸
TPI-Abuse
2026-09-03 19:52:12
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.81.198.210 (210.198.81.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.81.198.210 (210.198.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 15:52:07.445841 2026] [security2:error] [pid 27863:tid 27863] [client 34.81.198.210:62124] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.truecontrarian.com"] [uri "/@fs/app/.env"] [unique_id "apnP52PHlIjgq_xT49ubEAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-03 19:33:10
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.81.198.210 (210.198.81.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.81.198.210 (210.198.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 15:33:06.442313 2026] [security2:error] [pid 25100:tid 25100] [client 34.81.198.210:63002] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.livingminimal.com"] [uri "/@fs/.env"] [unique_id "apnLchNzMyH_lGlKfBho5QAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack