🇺🇸
TPI-Abuse
2026-09-09 10:10:25
(52 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.84.152.203 (203.152.84.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.84.152.203 (203.152.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 06:10:19.837912 2026] [security2:error] [pid 22793:tid 22793] [client 34.84.152.203:19442] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.rookscpa.com"] [uri "/@fs/.env"] [unique_id "aqEwi63-GGm6CdS_cu6u0QAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
masterguru
2026-09-09 09:23:45
(1 hour ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.84.152.203 (203.152.84.34.bc.googl ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.84.152.203 (203.152.84.34.bc.googleusercontent.com): 1 in the last 3600 secs (0-195)
show less
Hacking
🇺🇸
TPI-Abuse
2026-09-09 09:12:01
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.84.152.203 (203.152.84.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.84.152.203 (203.152.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 05:11:54.797508 2026] [security2:error] [pid 6110:tid 6110] [client 34.84.152.203:51476] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.catherineclayton.com"] [uri "/@fs/root/.env"] [unique_id "aqEi2rTU2ymqxn99LB_AsgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 08:54:50
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.84.152.203 (203.152.84.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.84.152.203 (203.152.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 04:54:43.595871 2026] [security2:error] [pid 32129:tid 32129] [client 34.84.152.203:3648] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.manninglandservices.com"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252fapp/.env"] [unique_id "aqEe0zQvaloWp9Qm1bAfRAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇪
taivas.nl
2026-09-09 07:32:15
(3 hours ago)
Bad_requests
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-09 07:27:48
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.84.152.203 (203.152.84.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.84.152.203 (203.152.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 03:27:43.122214 2026] [security2:error] [pid 16238:tid 16261] [client 34.84.152.203:63240] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.retnetsos.com"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252fapp/.env"] [unique_id "aqEKbyJWapWaewqknRPOIQAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
e.fierstra
2026-09-09 07:17:15
(3 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 07:09:54
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.84.152.203 (203.152.84.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.84.152.203 (203.152.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 03:09:50.656471 2026] [security2:error] [pid 23781:tid 23781] [client 34.84.152.203:58730] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pacsai.com"] [uri "/@fs/.env"] [unique_id "aqEGPo1UqeQm2e0VyYqP8QAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
FD-IX
2026-09-09 07:06:22
(3 hours ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 06:28:29
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.84.152.203 (203.152.84.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.84.152.203 (203.152.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 02:28:23.747729 2026] [security2:error] [pid 26679:tid 26679] [client 34.84.152.203:9796] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.asociacionmutualsanjose.com"] [uri "/@fs/src/.env"] [unique_id "aqD8h0rZEDROHXpYIenT_wAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇸🇪
vaia.cloud
2026-09-09 05:55:02
(5 hours ago)
crowdsecurity/http-path-traversal-probing
Brute-Force
Web App Attack
🇫🇷
Octopuce
2026-09-09 05:05:52
(5 hours ago)
Aggressive web search of vulnerable pages: /assets../.env /img../.env /v1/.env /_nuxt/../.env /.dock ...
show more
Aggressive web search of vulnerable pages: /assets../.env /img../.env /v1/.env /_nuxt/../.env /.docker/.env ...
show less
Web App Attack
Anonymous
2026-09-09 05:03:59
(5 hours ago)
Multiple web server 400 error codes from same source ip
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 04:54:16
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.84.152.203 (203.152.84.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.84.152.203 (203.152.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 00:54:10.369318 2026] [security2:error] [pid 5668:tid 5668] [client 34.84.152.203:56956] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.federallog.com"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252froot/.env"] [unique_id "aqDmcvDagHTghR6VV7o8mQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 04:37:35
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.84.152.203 (203.152.84.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.84.152.203 (203.152.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 00:37:30.874323 2026] [security2:error] [pid 6710:tid 6710] [client 34.84.152.203:19508] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.allafricaadventures.com"] [uri "/@fs/app/.env"] [unique_id "aqDiig2iRdINkSl0gQLtowAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack