Anonymous
2026-09-09 20:05:20
(58 minutes ago)
(mod_security) mod_security triggered on hostname [redacted])
SQL Injection
🇲🇾
Rizzy
2026-09-09 19:50:15
(1 hour ago)
Multiple WAF Violations
Brute-Force
Web App Attack
🇳🇱
JaRoNL
2026-09-09 18:54:36
(2 hours ago)
8.235.121.222 - - [09/Sep/2026:20:54:36 +0200] "GET /@fs/root/.env?raw?? HTTP/1.1" 404 2618 "-" "Moz ...
show more
8.235.121.222 - - [09/Sep/2026:20:54:36 +0200] "GET /@fs/root/.env?raw?? HTTP/1.1" 404 2618 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14_5) AppleWebKit/537.36 (KHTML, like Gecko; compatible; OAI-SearchBot/1.4; robots.txt; +https://openai.com/searchbot) Chrome/114.0.2345.104 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
🇩🇪
BlueWire Hosting
2026-09-09 18:50:18
(2 hours ago)
High-confidence malicious configuration/VCS probe
Web App Attack
🇨🇦
internetworld
2026-09-09 18:49:27
(2 hours ago)
8.235.121.222 - - [09/Sep/2026:18:49:25 +0000] "GET /@fs/app/.env?raw?? HTTP/1.1" 200 326 "-" "Mozil ...
show more
8.235.121.222 - - [09/Sep/2026:18:49:25 +0000] "GET /@fs/app/.env?raw?? HTTP/1.1" 200 326 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexity-user)"
...
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 17:15:42
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 8.235.121.222 (222.121.235.8.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 8.235.121.222 (222.121.235.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 13:15:38.950323 2026] [security2:error] [pid 20427:tid 20427] [client 8.235.121.222:25628] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.scottwithers.xyz"] [uri "/@fs/.env"] [unique_id "aqGUOvstXTNwMH0tShBDhgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
debestelapp
2026-09-09 16:30:13
(4 hours ago)
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 16:20:12
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 8.235.121.222 (222.121.235.8.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 8.235.121.222 (222.121.235.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 12:20:06.659479 2026] [security2:error] [pid 14080:tid 14080] [client 8.235.121.222:51012] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.sethroland.com"] [uri "/@fs/.env"] [unique_id "aqGHNmbuf__mVu-m4ZOu7wAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 15:25:10
(5 hours ago)
(mod_security) mod_security (id:210730) triggered by 8.235.121.222 (222.121.235.8.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 8.235.121.222 (222.121.235.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 11:25:04.981741 2026] [security2:error] [pid 6766:tid 6766] [client 8.235.121.222:0] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||autodiscover.portfoliolighting.net|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "autodiscover.portfoliolighting.net"] [uri "/@fs/etc/nginx/nginx.conf"] [unique_id "aqF6UMcbOwaViP_sbDlzAAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 14:08:02
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 8.235.121.222 (222.121.235.8.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 8.235.121.222 (222.121.235.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 10:07:55.742416 2026] [security2:error] [pid 15274:tid 15274] [client 8.235.121.222:38838] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.ospectra.com"] [uri "/@fs/root/.env"] [unique_id "aqFoO7e_f1JM8OQEpDD2EAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇦🇺
paulshipley.com.au
2026-09-09 13:56:12
(7 hours ago)
[Wed Sep 09 23:56:11.780520 2026] [security2:error] [pid 384159] [client 8.235.121.222:31080] [clien ...
show more
[Wed Sep 09 23:56:11.780520 2026] [security2:error] [pid 384159] [client 8.235.121.222:31080] [client 8.235.121.222] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "indigi-print-merch.com.au"] [uri "/.env"] [unique_id "aqFle9DX85Crn2-4zirNGAAAAAc"]
...
show less
Web App Attack
🇫🇷
LRob
2026-09-09 13:51:43
(7 hours ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /@fs/../.env | 2026-09-09 13:51 UTC
show less
Hacking
Web App Attack
🇩🇪
netclix.gr
2026-09-09 13:19:57
(7 hours ago)
(security_scan) Sensitive File Scan Blocked 8.235.121.222 (US/United States/222.121.235.8.bc.googleu ...
show more
(security_scan) Sensitive File Scan Blocked 8.235.121.222 (US/United States/222.121.235.8.bc.googleusercontent.com): 1 in the last 4600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 8.235.121.222 - - [09/Sep/2026:16:18:32 +0300] "GET /@fs/../../.env?raw?? HTTP/1.1" 400 150 "-" "-"
show less
Port Scan
🇺🇸
TPI-Abuse
2026-09-09 13:18:18
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 8.235.121.222 (222.121.235.8.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 8.235.121.222 (222.121.235.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 09:18:15.095738 2026] [security2:error] [pid 16534:tid 16534] [client 8.235.121.222:27312] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.forestvalleyfarm.com"] [uri "/@fs/src/.env"] [unique_id "aqFclxq6fYr8MSo52qbPRQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
middelkoopcc
2026-09-09 13:08:06
(7 hours ago)
2026-09-09 15:06:23 GET /@fs/.env?raw?? [301] && 2026-09-09 15:06:23 GET /@fs/root/.env?raw?? [301] ...
show more
2026-09-09 15:06:23 GET /@fs/.env?raw?? [301] && 2026-09-09 15:06:23 GET /@fs/root/.env?raw?? [301] && 2026-09-09 15:06:23 GET /@fs/src/.env?raw?? [301] && 123 more within 20 minutes
show less
Web App Attack