🇺🇸
TPI-Abuse
2026-09-08 20:24:06
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.84.242.219 (219.242.84.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.84.242.219 (219.242.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 16:23:59.441431 2026] [security2:error] [pid 1068:tid 1192] [client 34.84.242.219:12696] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.wnsi.org"] [uri "/@fs/src/.env"] [unique_id "aqBu355yXN0L6KJ2SlCO_AAAAM8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-08 19:40:07
(1 day ago)
| Suspicious URL access.
Web App Attack
Hacking
SQL Injection
🇺🇸
TPI-Abuse
2026-09-08 19:27:08
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.84.242.219 (219.242.84.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.84.242.219 (219.242.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 15:27:01.232116 2026] [security2:error] [pid 2288:tid 2288] [client 34.84.242.219:43626] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.bigskyprints.com"] [uri "/@fs/.env.local"] [unique_id "aqBhhTXAMqiupD1xM1MOhgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 18:51:57
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.84.242.219 (219.242.84.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.84.242.219 (219.242.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 14:51:51.182687 2026] [security2:error] [pid 32608:tid 32608] [client 34.84.242.219:63836] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.jacksonlimobus.com"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252fapp/.env"] [unique_id "aqBZR8Q6_cDPDx27CIPLnAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
Octopuce
2026-09-08 18:46:15
(1 day ago)
Aggressive web search of vulnerable pages: /phpmailer/test//phpmailer/ /phpmailer/docs//phpmailer/ / ...
show more
Aggressive web search of vulnerable pages: /phpmailer/test//phpmailer/ /phpmailer/docs//phpmailer/ /phpmailer/extras//phpmailer/ /phpmailer/lan ...
show less
Web App Attack
🇩🇪
filstal.org
2026-09-08 18:42:58
(1 day ago)
Web reconnaissance detected: automated probing for sensitive files, backup archives, admin panels an ...
show more
Web reconnaissance detected: automated probing for sensitive files, backup archives, admin panels and known vulnerability paths.
show less
Hacking
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 18:36:54
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.84.242.219 (219.242.84.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.84.242.219 (219.242.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 14:36:49.467239 2026] [security2:error] [pid 20373:tid 20373] [client 34.84.242.219:12604] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.holland-kadaster-registration.com"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252fapp/.env"] [unique_id "aqBVwX9SPwIzgbBEL8APLQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
itsvic.dev
2026-09-08 18:36:46
(1 day ago)
34.84.242.219 - - [08/Sep/2026:18:36:45 +0000] "webmail.itsvic.dev" "GET /@fs/.env.local?raw?? HTTP/ ...
show more
34.84.242.219 - - [08/Sep/2026:18:36:45 +0000] "webmail.itsvic.dev" "GET /@fs/.env.local?raw?? HTTP/1.1" 404 146 "-" "Mozilla/5.0 (compatible; Claude-SearchBot/1.0; +https://www.anthropic.com/claude-searchbot)"
34.84.242.219 - - [08/Sep/2026:18:36:45 +0000] "webmail.itsvic.dev" "GET /@fs/..%252f..%252f..%252f..%252f..%252froot/.env?raw?? HTTP/1.1" 404 146 "-" "Mozilla/5.0 (compatible; OAI-SearchBot/1.3; +https://openai.com/searchbot)"
34.84.242.219 - - [08/Sep/2026:18:36:45 +0000] "webmail.itsvic.dev" "GET /@fs/..%252f..%252f..%252f..%252f..%252fapp/.env?raw?? HTTP/1.1" 404 180 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14_6_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/148.0.2526.196 Safari/537.36; compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot"
...
show less
Brute-Force
Web App Attack
🇵🇱
strefapi_com
2026-09-08 17:58:34
(1 day ago)
Brute-force, web
...
Hacking
Brute-Force
Web App Attack
🇳🇱
e.fierstra
2026-09-08 17:42:01
(1 day ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-09-08 17:37:45
(1 day ago)
Web attack/malicious scanning detected
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 17:01:48
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.84.242.219 (219.242.84.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.84.242.219 (219.242.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 13:01:44.763457 2026] [security2:error] [pid 25585:tid 25585] [client 34.84.242.219:57160] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "littlehorndesign.com"] [uri "/@fs/../.env"] [unique_id "aqA_eNefJmQPM0COmayG9wAAADw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Savvii
2026-09-08 16:42:54
(1 day ago)
20 attempts against mh-misbehave-ban on ceres
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 16:18:30
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.84.242.219 (219.242.84.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.84.242.219 (219.242.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 12:18:23.988179 2026] [security2:error] [pid 26386:tid 26386] [client 34.84.242.219:38206] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.westernchristmascards.com"] [uri "/@fs/.env"] [unique_id "aqA1T_p57yFoMhyXM0Z7WgAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-08 15:38:05
(1 day ago)
34.84.242.219 - - [08/Sep/2026:17:38:04 +0200] "GET /@fs/..%252f..%252f..%252f..%252f..%252fapp/.env ...
show more
34.84.242.219 - - [08/Sep/2026:17:38:04 +0200] "GET /@fs/..%252f..%252f..%252f..%252f..%252fapp/.env?raw?? HTTP/1.1" 403 117 "https://schmittel-it.de/@fs/..%252f..%252f..%252f..%252f..%252fapp/.env?raw??" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; GPTBot/1.4; +https://openai.com/gptbot)"
...
show less
Hacking
Bad Web Bot
Web App Attack