Anonymous
2026-09-08 20:16:38
(4 hours ago)
Fuzzing/Looking for credentials files.
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 18:38:54
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.84.40.251 (251.40.84.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.84.40.251 (251.40.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 14:38:47.952018 2026] [security2:error] [pid 29943:tid 29943] [client 34.84.40.251:43176] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.achillespress.com.tandm.us"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252fapp/.env"] [unique_id "aqBWN49IuAKMnZtDN4Gd2AAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
FeG Deutschland
2026-09-08 18:12:37
(6 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 12
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 18:10:52
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.84.40.251 (251.40.84.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.84.40.251 (251.40.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 14:10:46.904905 2026] [security2:error] [pid 25940:tid 25940] [client 34.84.40.251:35148] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "criticalthinkingbook.banis-associates.com"] [uri "/@fs/root/.env"] [unique_id "aqBPpj6351p--0TqoCGxkgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇵🇱
Budyn
2026-09-08 18:08:47
(6 hours ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit Block. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: url.budyn.ovh | URI: /@fs/.env.local?raw?? | UA: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; +https://www.anthropic.com/claude-user) | BODY: [Empty / GET Request]
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 17:32:43
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.84.40.251 (251.40.84.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.84.40.251 (251.40.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 13:32:39.549622 2026] [security2:error] [pid 17484:tid 17484] [client 34.84.40.251:5300] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.paintscapeabroad.com"] [uri "/@fs/app/.env"] [unique_id "aqBGt5oAkpRavrGAq_ptBQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Site.eu
2026-09-08 17:30:28
(7 hours ago)
Excessive multi-domain requests
Brute-Force
🇲🇾
Rizzy
2026-09-08 17:08:20
(7 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack
Anonymous
2026-09-08 17:07:16
(7 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-08 16:54:26
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.84.40.251 (251.40.84.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.84.40.251 (251.40.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 12:54:22.641271 2026] [security2:error] [pid 11339:tid 11339] [client 34.84.40.251:17058] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.mountainararattrek.com"] [uri "/@fs/root/.env"] [unique_id "aqA9vjQr__naXU5yolsGwgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-08 16:08:11
(8 hours ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
🇫🇷
dynamix
2026-09-08 16:07:43
(8 hours ago)
Multiple WAF Violations
Web App Attack
Anonymous
2026-09-08 16:00:29
(9 hours ago)
Aggressive web scan
Web App Attack
Anonymous
2026-09-08 15:57:38
(9 hours ago)
[ssd5.kdns.gr] httpd-config-scan: logs=/var/log/httpd/access_log; samples=/@fs/..%252f..%252f..%252f ...
show more
[ssd5.kdns.gr] httpd-config-scan: logs=/var/log/httpd/access_log; samples=/@fs/..%252f..%252f..%252f..%252f..%252froot/.env?raw?? | /@fs/root/rootkey.csv?raw?? | /@fs/.env.production?raw??
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 15:32:08
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.84.40.251 (251.40.84.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.84.40.251 (251.40.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 11:32:01.461507 2026] [security2:error] [pid 10832:tid 10832] [client 34.84.40.251:35886] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.johnatuttle.com"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252fapp/.env"] [unique_id "aqAqcTOc2bJQZspzs15IsAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack