🇧🇪
cmbplf
2026-09-08 21:29:50
(2 days ago)
2.135 requests with url.path */@fs/*
174 requests with url.path */proc/*
Brute-Force
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-08 20:19:21
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.84.182.145 (145.182.84.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.84.182.145 (145.182.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 16:19:15.410669 2026] [security2:error] [pid 12718:tid 12718] [client 34.84.182.145:5572] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "visithavelock.ca"] [uri "/@fs/root/.env"] [unique_id "aqBtw57WSY_39AtsyP6G2AAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
Starburst SysOp Team
2026-09-08 20:09:12
(2 days ago)
Restricted File Access Attempt. Matched phrase "/@fs/" at REQUEST_FILENAME. (930130-mnz6-1)
Hacking
Web App Attack
🇵🇱
tomkolp
2026-09-08 20:01:32
(2 days ago)
CrowdSec - Scenario: crowdsecurity/http-probing. Duration: 4h.
Port Scan
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-08 19:23:25
(2 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-08 19:09:40
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.84.182.145 (145.182.84.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.84.182.145 (145.182.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 15:09:33.291379 2026] [security2:error] [pid 133685:tid 133767] [client 34.84.182.145:28518] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "doorways.info"] [uri "/@fs/.env"] [unique_id "aqBdbS9LffOl39NJj_pAegAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 18:43:13
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.84.182.145 (145.182.84.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.84.182.145 (145.182.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 14:43:09.781024 2026] [security2:error] [pid 4282:tid 4282] [client 34.84.182.145:15848] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.tatethegreat.com"] [uri "/@fs/.env"] [unique_id "aqBXPWVevp8Gjrr-qpd4VwAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Site.eu
2026-09-08 18:11:53
(2 days ago)
Excessive multi-domain requests
Brute-Force
🇺🇸
TPI-Abuse
2026-09-08 17:46:05
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.84.182.145 (145.182.84.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.84.182.145 (145.182.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 13:45:57.470321 2026] [security2:error] [pid 1078:tid 1129] [client 34.84.182.145:62458] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "iguanablue.com"] [uri "/@fs/app/.env"] [unique_id "aqBJ1aZ0nG5pim-t1aYpxwAAAdM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
LRob
2026-09-08 17:42:45
(2 days ago)
Enumerating paths that do not exist (scanning) | method: GET | path: /@fs/etc/passwd (+7 more) | ua: ...
show more
Enumerating paths that do not exist (scanning) | method: GET | path: /@fs/etc/passwd (+7 more) | ua: Mozilla/5.0 (compatible; meta-externalagent/1.1; +https://developers.facebook.com/docs/sharing/webmasters/crawler) (+6 more) | 2026-09-08 17:42 UTC
show less
Port Scan
Web App Attack
🇩🇪
Phenix Info
2026-09-08 16:51:44
(2 days ago)
SmallGuard.fr/Prestashop Forbidden Ext.
Web App Attack
🇵🇱
strefapi_com
2026-09-08 16:09:04
(2 days ago)
Brute-force, web
...
Hacking
Brute-Force
Web App Attack
🇳🇱
middelkoopcc
2026-09-08 16:09:01
(2 days ago)
2026-09-08 18:07:18 AH10244: invalid URI path (/@fs/../../.env?raw??) && 2026-09-08 18:07:49 AH10244 ...
show more
2026-09-08 18:07:18 AH10244: invalid URI path (/@fs/../../.env?raw??) && 2026-09-08 18:07:49 AH10244: invalid URI path (/@fs/../../../../../root/.env?raw??) && 2026-09-08 18:07:49 AH10244: invalid URI path (/@fs/../../../../../app/.env?raw??) && 150 more within 20 minutes
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 16:07:07
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.84.182.145 (145.182.84.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.84.182.145 (145.182.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 12:06:59.893775 2026] [security2:error] [pid 5610:tid 5610] [client 34.84.182.145:56056] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.sislau.net"] [uri "/@fs/.env.production"] [unique_id "aqAyoyCG9BnYKTD8zDJxEwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 15:51:00
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.84.182.145 (145.182.84.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.84.182.145 (145.182.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 11:50:55.449257 2026] [security2:error] [pid 19599:tid 19599] [client 34.84.182.145:6542] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.snowmanchristmascards.net"] [uri "/@fs/.env"] [unique_id "aqAu33A-EYPbXK1zzFix9wAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack