🇺🇸
TPI-Abuse
2026-09-07 20:19:43
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 8.228.2.75 (75.2.228.8.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:210492) triggered by 8.228.2.75 (75.2.228.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 16:19:38.339071 2026] [security2:error] [pid 12660:tid 12660] [client 8.228.2.75:8468] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.k2servicesinc.net"] [uri "/@fs/app/.env"] [unique_id "ap8cWqVJ9yKBv5b8OUYQeAAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 19:36:21
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 8.228.2.75 (75.2.228.8.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:210492) triggered by 8.228.2.75 (75.2.228.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 15:36:15.227751 2026] [security2:error] [pid 13622:tid 13622] [client 8.228.2.75:11806] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.onlyincanada-eh.com"] [uri "/@fs/root/.env"] [unique_id "ap8SL6kN0r-J4V51-LmBGgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇦🇺
AWW-Admin
2026-09-07 19:27:23
(7 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 8.228.2.75 (US/United States/75.2.228.8 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 8.228.2.75 (US/United States/75.2.228.8.bc.googleusercontent.com)
show less
SQL Injection
🇧🇪
cmbplf
2026-09-07 18:55:08
(8 hours ago)
446 requests with url.path *.azure/*
289 requests with url.path *credentials.json
107 requests wi ...
show more
446 requests with url.path *.azure/*
289 requests with url.path *credentials.json
107 requests with url.path */auth.json
show less
Brute-Force
Bad Web Bot
🇩🇪
palzer.IT
2026-09-07 18:41:07
(8 hours ago)
Fail2ban automatic report for plesk-apache-badbot: 8.228.2.75 - - [07/Sep/2026:20:40:52 +0200] GET / ...
show more
Fail2ban automatic report for plesk-apache-badbot: 8.228.2.75 - - [07/Sep/2026:20:40:52 +0200] GET /@fs/root/.env?raw?? [DOMAIN_REMOVED] 404 6438 [DOMAIN_REMOVED] Mozilla/5.0 (Linux; Android 13; Pixel 7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.2312.115 Mobile Safari/537.36; compatible; Bytespider; +[DOMAIN_REMOVED]
show less
Bad Web Bot
🇩🇪
Vegascosmetics
2026-09-07 18:14:16
(8 hours ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after first-seen suspicion / AbuseIPDB repu ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after first-seen suspicion / AbuseIPDB reputation policy (no URL signature). Evidence: Suspicion-Ban (Score 66>=65, Abuse 62, NonEU, first-seen)
show less
Hacking
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 18:11:22
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 8.228.2.75 (75.2.228.8.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:210492) triggered by 8.228.2.75 (75.2.228.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 14:11:17.152513 2026] [security2:error] [pid 12701:tid 12701] [client 8.228.2.75:40818] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.jvcsat.com"] [uri "/@fs/.env.development"] [unique_id "ap7-RecITrLjB1AFB67OsAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Site.eu
2026-09-07 17:58:20
(9 hours ago)
Excessive 404/403 errors
Brute-Force
🇺🇸
TPI-Abuse
2026-09-07 17:45:39
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 8.228.2.75 (75.2.228.8.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:210492) triggered by 8.228.2.75 (75.2.228.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 13:45:30.949560 2026] [security2:error] [pid 27323:tid 27323] [client 8.228.2.75:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.koshermap.nyc"] [uri "/@fs/.env.production"] [unique_id "ap74OmV3Ek9pGrJ6H8_BKgAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 17:21:42
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 8.228.2.75 (75.2.228.8.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:210492) triggered by 8.228.2.75 (75.2.228.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 13:21:37.375872 2026] [security2:error] [pid 25686:tid 25686] [client 8.228.2.75:50748] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.keymarketmedia.com"] [uri "/@fs/.env.development"] [unique_id "ap7yoRwkl-5go6P5laMd9AAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-07 17:11:25
(10 hours ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
Anonymous
2026-09-07 16:59:01
(10 hours ago)
Multiple web server 400 error codes from same source ip
Web App Attack
🇺🇸
NXTwoThou
2026-09-07 16:41:37
(10 hours ago)
/@fs/../../.env%3Fraw%3F%3F
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 16:38:56
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 8.228.2.75 (75.2.228.8.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:210492) triggered by 8.228.2.75 (75.2.228.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 12:38:50.356859 2026] [security2:error] [pid 8458:tid 8458] [client 8.228.2.75:2478] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.tavo.info"] [uri "/@fs/src/.env"] [unique_id "ap7omsfbnQPqf89asu5aYwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
Octopuce
2026-09-07 16:15:34
(10 hours ago)
Aggressive web search of vulnerable pages: /.env.local /.env /v2/.env /assets../.env /img../.env .. ...
show more
Aggressive web search of vulnerable pages: /.env.local /.env /v2/.env /assets../.env /img../.env ...
show less
Web App Attack