🇬🇧
Aetherweb Ark
2026-09-08 04:14:30
(30 minutes ago)
(mod_security) mod_security (id:949110) triggered by 34.90.13.180 (180.13.90.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:949110) triggered by 34.90.13.180 (180.13.90.34.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
🇫🇷
Entalpi.net
2026-09-08 04:07:52
(37 minutes ago)
Repeated requests against sensitive web endpoints
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 04:06:33
(38 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.90.13.180 (180.13.90.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.90.13.180 (180.13.90.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 00:06:29.176813 2026] [security2:error] [pid 30783:tid 30783] [client 34.90.13.180:18516] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.malamutian.net"] [uri "/@fs/.env"] [unique_id "ap-JxfoVG4QPS90yCV-y0QAAAE8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-08 03:30:17
(1 hour ago)
34.90.13.180 - - [08/Sep/2026:05:28:20 +0200] "GET HTTP/1.1" 403 1856 "-" "Mozilla/5.0 AppleWebKit/ ...
show more
34.90.13.180 - - [08/Sep/2026:05:28:20 +0200] "GET HTTP/1.1" 403 1856 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Bytespider; +https://zhanzhang.toutiao.com/)"
show less
Web Spam
Blog Spam
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 03:08:43
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.90.13.180 (180.13.90.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.90.13.180 (180.13.90.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 23:08:35.898082 2026] [security2:error] [pid 17807:tid 17807] [client 34.90.13.180:42290] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.isslv.net"] [uri "/@fs/root/.env"] [unique_id "ap98MxlqZ08GnH-_w4HuAQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
masterguru
2026-09-08 03:03:10
(1 hour ago)
Restricted File Access Attempt. Matched phrase "/@fs/" at REQUEST_FILENAME. (930130-193)
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 02:51:23
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.90.13.180 (180.13.90.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.90.13.180 (180.13.90.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 22:51:15.202418 2026] [security2:error] [pid 18002:tid 18024] [client 34.90.13.180:56388] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.yakamengen.com"] [uri "/@fs/.env"] [unique_id "ap94I1owVIS-n1LsXe0fvwAAAEY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 02:31:36
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.90.13.180 (180.13.90.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.90.13.180 (180.13.90.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 22:31:33.188983 2026] [security2:error] [pid 5717:tid 5717] [client 34.90.13.180:33472] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.needtoorder.us"] [uri "/@fs/../.env"] [unique_id "ap9zhatUAMiM9Qes5DvJyQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇸🇪
vaia.cloud
2026-09-08 02:25:02
(2 hours ago)
crowdsecurity/http-probing
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 02:01:08
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.90.13.180 (180.13.90.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.90.13.180 (180.13.90.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 22:01:04.842457 2026] [security2:error] [pid 17553:tid 17553] [client 34.90.13.180:45258] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.usoilinc.com"] [uri "/@fs/.env"] [unique_id "ap9sYO6ILjHYx5CIqfVZZAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
masterguru
2026-09-08 01:59:35
(2 hours ago)
Restricted File Access Attempt. Matched phrase "/@fs/" at REQUEST_FILENAME. (930130-201)
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 01:39:35
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.90.13.180 (180.13.90.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.90.13.180 (180.13.90.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 21:39:28.750815 2026] [security2:error] [pid 17433:tid 17433] [client 34.90.13.180:57646] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.vexxarr.com"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252froot/.env"] [unique_id "ap9nUCzNcDRfiN4X4a8zuQAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇲🇾
Rizzy
2026-09-08 01:38:22
(3 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack
🇧🇪
cmbplf
2026-09-08 01:28:52
(3 hours ago)
850 requests with url.path *.aws/*
720 requests with url.path *config.json
714 requests with url. ...
show more
850 requests with url.path *.aws/*
720 requests with url.path *config.json
714 requests with url.path *credentials.json
509 requests with url.path *.azure/*
129 requests with url.path */auth.json
show less
Brute-Force
Bad Web Bot
🇳🇱
middelkoopcc
2026-09-08 01:13:01
(3 hours ago)
2026-09-08 03:11:27 GET /@fs/.env?raw?? [301] && 2026-09-08 03:11:27 GET /@fs/app/.env?raw?? [301] & ...
show more
2026-09-08 03:11:27 GET /@fs/.env?raw?? [301] && 2026-09-08 03:11:27 GET /@fs/app/.env?raw?? [301] && 2026-09-08 03:11:27 GET /@fs/proc/self/environ?raw?? [301] && 132 more within 20 minutes
show less
Web App Attack