🇺🇸
TPI-Abuse
2026-09-04 03:42:10
(30 minutes ago)
(mod_security) mod_security (id:210492) triggered by 8.228.252.131 (131.252.228.8.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 8.228.252.131 (131.252.228.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 23:42:04.910993 2026] [security2:error] [pid 26563:tid 26563] [client 8.228.252.131:38746] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.goglobex.com"] [uri "/@fs/root/.env"] [unique_id "apo-DJsaAivtBfSy5raq7gAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇪
Savvii
2026-09-04 03:20:11
(52 minutes ago)
20 attempts against mh-misbehave-ban on escape
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 03:06:46
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 8.228.252.131 (131.252.228.8.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 8.228.252.131 (131.252.228.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 23:06:41.864875 2026] [security2:error] [pid 13967:tid 13967] [client 8.228.252.131:5814] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.compassionfatigue.org"] [uri "/@fs/app/.env"] [unique_id "apo1wcv5Ya3CkbwdxtrAxgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
BlueWire Hosting
2026-09-04 03:01:17
(1 hour ago)
High-confidence malicious configuration/VCS probe
Web App Attack
🇳🇱
debestelapp
2026-09-04 02:25:10
(1 hour ago)
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 01:32:55
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 8.228.252.131 (131.252.228.8.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 8.228.252.131 (131.252.228.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 21:32:50.070995 2026] [security2:error] [pid 20694:tid 20694] [client 8.228.252.131:49554] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "vabq.com"] [uri "/@fs/../.env"] [unique_id "apofwlqVRWCkkOPBhE3rwAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
masterguru
2026-09-04 01:29:24
(2 hours ago)
Restricted File Access Attempt. Matched phrase "/@fs/" at REQUEST_FILENAME. (930130-201)
Hacking
Web App Attack
Anonymous
2026-09-03 23:46:13
(4 hours ago)
Bot / seems abusive / Apache connections: 43
DDoS Attack
Web Spam
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-03 23:39:47
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 8.228.252.131 (131.252.228.8.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 8.228.252.131 (131.252.228.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 19:39:41.933330 2026] [security2:error] [pid 15034:tid 15034] [client 8.228.252.131:8928] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "register-yacht-belize.com.yacht-register-holland.com"] [uri "/@fs/root/.env"] [unique_id "apoFPRRdEiVtgmgNYVfrugAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-03 23:03:24
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 8.228.252.131 (131.252.228.8.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 8.228.252.131 (131.252.228.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 19:03:20.814220 2026] [security2:error] [pid 10553:tid 10553] [client 8.228.252.131:32268] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.pinebrookdesign.com"] [uri "/@fs/.env"] [unique_id "apn8uGXTx1eeNp8FSxYFlgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-03 21:59:59
(6 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
🇳🇱
homeshowdomain.nl
2026-09-03 21:59:24
(6 hours ago)
Auto-ban: >3000 req/min op 2026-09-03
Web App Attack
SSH
Hacking
🇫🇷
Octopuce
2026-09-03 21:45:51
(6 hours ago)
Aggressive web search of vulnerable pages: /assets../.env /images../.env /backend/.env /app/.env /.e ...
show more
Aggressive web search of vulnerable pages: /assets../.env /images../.env /backend/.env /app/.env /.env.local ...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-03 21:36:03
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 8.228.252.131 (131.252.228.8.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 8.228.252.131 (131.252.228.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 17:35:58.779491 2026] [security2:error] [pid 13559:tid 13572] [client 8.228.252.131:58042] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.farmerlabor.org"] [uri "/@fs/src/.env"] [unique_id "apnoPrnrRZfjoZgnWEqiAAAAAQg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇸🇪
vaia.cloud
2026-09-03 21:35:01
(6 hours ago)
crowdsecurity/http-probing
Brute-Force
Web App Attack