๐บ๐ธ
TPI-Abuse
2026-08-28 01:07:58
(15 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.91.34.193 (193.34.91.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.91.34.193 (193.34.91.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 21:07:51.206656 2026] [security2:error] [pid 29109:tid 29109] [client 34.91.34.193:13638] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.wildimaginings.org"] [uri "/@fs/.env"] [unique_id "apDfZ8xrlqp_j1xcdkfQxAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 00:03:06
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.91.34.193 (193.34.91.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.91.34.193 (193.34.91.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 20:02:59.725193 2026] [security2:error] [pid 24238:tid 24238] [client 34.91.34.193:29158] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.dc406.org"] [uri "/@fs/.env"] [unique_id "apDQMxz_QKdjhHtyX3cpVgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-08-28 00:01:58
(1 hour ago)
Try to access /@fs/.env?raw??
Web App Attack
๐ฉ๐ช
arnisolutions
2026-08-27 23:42:04
(1 hour ago)
Vulnerability scanning (requests for admin panels, shells, backup files etc.) against a production s ...
show more
Vulnerability scanning (requests for admin panels, shells, backup files etc.) against a production server. Observed on 1 day(s) between 2026-08-27 and 2026-08-27 (UTC). Sample request: GET /config.json.js HTTP/2.0
show less
Web App Attack
Hacking
๐จ๐ญ
zynex
2026-08-27 23:23:57
(1 hour ago)
URL Probing: /@fs/var/www/.env
Web App Attack
๐ณ๐ฑ
Savvii
2026-08-27 23:01:19
(2 hours ago)
20 attempts against mh_ha-misbehave-ban on crop
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 22:39:00
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.91.34.193 (193.34.91.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.91.34.193 (193.34.91.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 18:38:57.138633 2026] [security2:error] [pid 19275:tid 19275] [client 34.91.34.193:49380] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.garantaconsulting.com"] [uri "/@fs/src/.env"] [unique_id "apC8gXiKZDXhXc617qqVEQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Octopuce
2026-08-27 22:33:46
(2 hours ago)
Aggressive web search of vulnerable pages: /_nuxt/../.env /uploads../.env /img../.env /images../.env ...
show more
Aggressive web search of vulnerable pages: /_nuxt/../.env /uploads../.env /img../.env /images../.env /assets../.env ...
show less
Web App Attack
๐บ๐ธ
kosada.com
2026-08-27 21:53:16
(3 hours ago)
Web vulnerability probing: /@fs/var/run/secrets/kubernetes.io/serviceaccount/token
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 21:48:05
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.91.34.193 (193.34.91.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.91.34.193 (193.34.91.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 17:47:58.604516 2026] [security2:error] [pid 2079:tid 2079] [client 34.91.34.193:22222] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.dymesich.com"] [uri "/@fs/.env"] [unique_id "apCwjpwIoR4LA0BbXgocMAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 21:12:36
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.91.34.193 (193.34.91.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.91.34.193 (193.34.91.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 17:12:28.313576 2026] [security2:error] [pid 17579:tid 17579] [client 34.91.34.193:63250] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.philipma.com"] [uri "/@fs/.env"] [unique_id "apCoPHIKKGJOrHO-57plpgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
COMAITE
2026-08-27 20:21:06
(5 hours ago)
Common web attack from 34.91.34.193.
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 20:17:18
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.91.34.193 (193.34.91.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.91.34.193 (193.34.91.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 16:17:10.034433 2026] [security2:error] [pid 19810:tid 19810] [client 34.91.34.193:47458] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.ictsl.net"] [uri "/@fs/app/.env"] [unique_id "apCbRs1VIwFbl0PVUS5vNgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-08-27 20:13:50
(5 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-08-27 20:13:03
(5 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking