🇱🇻
garmtech.com
2026-09-08 11:22:46
(1 hour ago)
Attempted access to sensitive endpoint (/@fs/../.env?raw??) detected. Automated scan or unauthorized ...
show more
Attempted access to sensitive endpoint (/@fs/../.env?raw??) detected. Automated scan or unauthorized probing.
show less
Web App Attack
🇦🇺
A.i.D.A.N.N
2026-09-08 10:10:09
(2 hours ago)
A.i.D.A.N.N: Anomaly Detected - Signature match Web Service - Web application attack detected
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 10:05:48
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 8.234.218.86 (86.218.234.8.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 8.234.218.86 (86.218.234.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 06:05:40.938257 2026] [security2:error] [pid 10557:tid 10557] [client 8.234.218.86:22460] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.usfspirit.com"] [uri "/@fs/.env"] [unique_id "ap_d9Jfc922B_41QIE2aHgAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
mnsf
2026-09-08 10:05:14
(2 hours ago)
Abuse Detected (9)
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 08:57:53
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 8.234.218.86 (86.218.234.8.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 8.234.218.86 (86.218.234.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 04:57:46.247123 2026] [security2:error] [pid 21816:tid 21816] [client 8.234.218.86:18348] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.doctoredwinalvarez.com"] [uri "/@fs/.env"] [unique_id "ap_OCinAMlukYiBmTgsiygAAAC0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-08 08:53:45
(4 hours ago)
(mod_security) mod_security triggered on hostname [redacted])
SQL Injection
🇳🇱
Savvii
2026-09-08 08:51:22
(4 hours ago)
20 attempts against mh-misbehave-ban on frost
Brute-Force
Bad Web Bot
Web App Attack
🇮🇩
Burayot
2026-09-08 08:49:36
(4 hours ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 8.234.218.86 (US/United States/86.2 ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 8.234.218.86 (US/United States/86.218.234.8.bc.googleusercontent.com): 1 in the last 3600 secs
show less
Web App Attack
🇩🇪
akasolutions.de
2026-09-08 08:40:55
(4 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 8.234.218.86 (US/United States/86.218.2 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 8.234.218.86 (US/United States/86.218.234.8.bc.googleusercontent.com)
show less
SQL Injection
🇺🇸
TPI-Abuse
2026-09-08 08:21:08
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 8.234.218.86 (86.218.234.8.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 8.234.218.86 (86.218.234.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 04:21:03.803934 2026] [security2:error] [pid 24402:tid 24402] [client 8.234.218.86:45058] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.jabbosjingles.com"] [uri "/@fs/.env"] [unique_id "ap_Fb6VYekhVIOo9ePwfwgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇴
jad-abuse
2026-09-08 08:10:09
(4 hours ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: env_probe ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: env_probe, path_traversal, aws_creds, source_backup, ssh_keys, ai_secrets, git_exposure, config_backup. Observed by 1 sensor(s); 747 hits.
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 07:56:25
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 8.234.218.86 (86.218.234.8.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 8.234.218.86 (86.218.234.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 03:56:19.900161 2026] [security2:error] [pid 25933:tid 25933] [client 8.234.218.86:2108] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.tandemfamilycoaching.com"] [uri "/@fs/root/.env"] [unique_id "ap-_o1L81JLfeiaa_3qZYAAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 07:28:35
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 8.234.218.86 (86.218.234.8.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 8.234.218.86 (86.218.234.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 03:28:28.363320 2026] [security2:error] [pid 28647:tid 28647] [client 8.234.218.86:22438] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "carolinapetportraits.com"] [uri "/@fs/app/.env"] [unique_id "ap-5HPvq0s1IHxPpsYuldQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
COMAITE
2026-09-08 07:17:02
(5 hours ago)
Suspicious URL access.
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 06:58:30
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 8.234.218.86 (86.218.234.8.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 8.234.218.86 (86.218.234.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 02:58:24.133329 2026] [security2:error] [pid 21288:tid 21288] [client 8.234.218.86:16324] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.globalodit.com"] [uri "/@fs/.env"] [unique_id "ap-yEPbR9AwwtdRxdprMkAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack