🇪🇸
librebit
2026-09-09 02:57:56
(1 hour ago)
Bad guys doing bad things, bad crawling
Bad Web Bot
🇧🇪
cmbplf
2026-09-08 22:40:05
(5 hours ago)
300 requests with url.path *.aws/*
Brute-Force
Bad Web Bot
🇫🇷
Octopuce
2026-09-08 20:25:03
(8 hours ago)
Aggressive web search of vulnerable pages: /uploads../.env /.docker/.env /images../.env /img../.env ...
show more
Aggressive web search of vulnerable pages: /uploads../.env /.docker/.env /images../.env /img../.env /assets../.env ...
show less
Web App Attack
🇳🇱
Savvii
2026-09-08 19:43:49
(8 hours ago)
20 attempts against mh-misbehave-ban on redirect
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Petros Stefanakis
2026-09-08 19:18:54
(9 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 34.84.31.234 (JP/Japan/234.31.84.34.bc. ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.84.31.234 (JP/Japan/234.31.84.34.bc.googleusercontent.com)
show less
SQL Injection
🇺🇸
TPI-Abuse
2026-09-08 19:04:59
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.84.31.234 (234.31.84.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.84.31.234 (234.31.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 15:04:52.703961 2026] [security2:error] [pid 18158:tid 18158] [client 34.84.31.234:46720] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "draindoctor.us"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252froot/.env"] [unique_id "aqBcVD8HPQxOIKVAGGqGvwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇸🇪
vaia.cloud
2026-09-08 18:45:01
(9 hours ago)
crowdsecurity/http-probing
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 18:02:58
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.84.31.234 (234.31.84.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.84.31.234 (234.31.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 14:02:51.146343 2026] [security2:error] [pid 31655:tid 31655] [client 34.84.31.234:43368] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.dunningtons.com"] [uri "/@fs/.env"] [unique_id "aqBNy6PQnoppkRLbsf4MHgAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
todix
2026-09-08 17:52:20
(10 hours ago)
Web App Attack Exploid from 34.84.31.234
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 17:29:50
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.84.31.234 (234.31.84.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.84.31.234 (234.31.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 13:29:44.076600 2026] [security2:error] [pid 19034:tid 19034] [client 34.84.31.234:20486] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jimhermelband.com"] [uri "/@fs/../.env"] [unique_id "aqBGCFyanJ7JSw2sigcNZQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 16:52:59
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.84.31.234 (234.31.84.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.84.31.234 (234.31.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 12:52:53.435396 2026] [security2:error] [pid 1339:tid 1372] [client 34.84.31.234:10860] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.fnaandpartners.com"] [uri "/@fs/../.env"] [unique_id "aqA9ZQrP3EOguvVEFYq2owAAAYQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
FeG Deutschland
2026-09-08 16:29:38
(12 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 1247
Exploited Host
Web App Attack
🇳🇿
Antinson
2026-09-08 16:14:04
(12 hours ago)
Scraping with a high error ratio and request rate
Bad Web Bot
Anonymous
2026-09-08 16:07:57
(12 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-08 15:56:52
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.84.31.234 (234.31.84.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.84.31.234 (234.31.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 11:56:49.718392 2026] [security2:error] [pid 4568:tid 4568] [client 34.84.31.234:62260] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.livinghopehighschool.org"] [uri "/@fs/../../.env"] [unique_id "aqAwQa7_5J0jKdF8iz_VVgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack