🇭🇺
DumaNet
2026-09-04 05:35:00
(5 minutes ago)
Web app attack attempts, scanning for vulnerability.
Date: 2026 Sep 03. 20:56:45
Source IP: 34.104 ...
show more
Web app attack attempts, scanning for vulnerability.
Date: 2026 Sep 03. 20:56:45
Source IP: 34.104.129.41
Portion of the log(s):
34.104.129.41 - [03/Sep/2026:20:56:45 +0200] "GET /@fs/.env.staging?raw?? HTTP/1.1" 404 555 "-" "Mozilla/5.0 (Linux; Android 15; SM-S918B) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.6675.191 Mobile Safari/537.36; compatible; LinkedInBot/1.0; +http://www.linkedin.com"
34.104.129.41 - [03/Sep/2026:20:56:45 +0200] "GET /@fs/root/.aws/config?raw?? HTTP/1.1" 404 153 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; Claude-User/1.0; +https://www.anthropic.com/claude-user"
34.104.129.41 - [03/Sep/2026:20:56:45 +0200] "GET /@fs/..%252f..%252f..%252f..%252f..%252fapp/.env?raw?? HTTP/1.1" 404 555 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko; compatible; LinkedInBot/1.0; +http://www.linkedin.com) Chrome/85.0.7476.154 Safari/537.36"
34.104.129.41 - [03/Sep/2026:20:56:45 +0200] "GET /@fs/..%252f..%252f..%252f..%252
show less
Web App Attack
🇪🇸
librebit
2026-09-04 05:08:37
(32 minutes ago)
Bad guys doing bad things, bad crawling
Bad Web Bot
🇮🇹
CoreTech srl
2026-09-04 04:58:56
(41 minutes ago)
cloudlinux2 fail2ban: 2026-09-04 06:55:11,196 fail2ban.filter [1594]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-09-04 06:55:11,196 fail2ban.filter [1594]: INFO [plesk-modsecurity] Found 35.229.235.80 - 2026-09-04 06:55:11cloudlinux2 fail2ban: 2026-09-04 06:55:55,729 fail2ban.filter [1594]: INFO [plesk-modsecurity] Found 34.104.129.41 - 2026-09-04 06:55:55cloudlinux2 fail2ban: 2026-09-04 06:55:55,753 fail2ban.filter [1594]: INFO [plesk-modsecurity] Found 34.104.129.41 - 2026-09-04 06:55:55cloudlinux2 fail2ban: 2026-09-04 06:55:55,634 fail2ban.filter [1594]: INFO [plesk-modsecurity] Found 34.104.129.41 - 2026-09-04 06:55:55cloudlinux2 fail2ban: 2026-09-04 06:55:55,708 fail2ban.filter [1594]: INFO [plesk-modsecurity] Found 34.104.129.41 - 2026-09-04 06:55:55cloudlinux2 fail2ban: 2026-09-04 06:55:55,737 fail2ban.filter [1594]: INFO [plesk-modsecurity] Found 34.104.129.41 - 2026-09-04 06:55:55cloudlinux2 fail2ban: 2026-09-04 06:55:55,696 fail2ban.filter [1594]: INFO [plesk-modsecurity] Found 34.104.129.41 - 2026-09-04 06:
show less
Brute-Force
🇺🇸
TPI-Abuse
2026-09-04 04:34:26
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.104.129.41 (41.129.104.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.104.129.41 (41.129.104.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 00:34:19.734843 2026] [security2:error] [pid 7081:tid 7081] [client 34.104.129.41:31642] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sabbathseminars.net"] [uri "/@fs/app/.env"] [unique_id "appKS-Ina9EDbCnU35I1rAAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 03:48:41
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.104.129.41 (41.129.104.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.104.129.41 (41.129.104.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 23:48:36.064923 2026] [security2:error] [pid 23680:tid 23680] [client 34.104.129.41:32224] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dillydallyvalley.com"] [uri "/@fs/.env"] [unique_id "apo_lHFf7y0YDfalvNKdUAAAAF4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
azminawwar
2026-09-04 02:56:17
(2 hours ago)
[34.104.129.41] triggered by honeypot on port [80], Timestamp [2026-09-04T02:56:17Z]METHOD=GET PATH= ...
show more
[34.104.129.41] triggered by honeypot on port [80], Timestamp [2026-09-04T02:56:17Z]METHOD=GET PATH=/ HTTP=HTTP/1.1 UA="Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like
show less
Port Scan
Hacking
🇺🇸
TPI-Abuse
2026-09-04 02:55:30
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.104.129.41 (41.129.104.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.104.129.41 (41.129.104.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 22:55:22.438251 2026] [security2:error] [pid 18519:tid 18519] [client 34.104.129.41:50940] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.dhsgrad.net"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252froot/.env"] [unique_id "apozGoPpZQWrBoXzM1iMBQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Webhoster
2026-09-04 02:36:32
(3 hours ago)
CrowdSec detected crowdsecurity/http-path-traversal-probing on a monitored service.
Web App Attack
🇫🇷
masterguru
2026-09-04 02:32:30
(3 hours ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-195)
Hacking
Web App Attack
🇫🇷
masterguru
2026-09-04 02:17:09
(3 hours ago)
Restricted File Access Attempt. Matched phrase "/@fs/" at REQUEST_FILENAME. (930130-201)
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 02:03:00
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.104.129.41 (41.129.104.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.104.129.41 (41.129.104.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 22:02:52.401030 2026] [security2:error] [pid 20959:tid 20959] [client 34.104.129.41:43064] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.davidocchino.com"] [uri "/@fs/root/.env"] [unique_id "apomzCAppdscTGyzbNjtPQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
✨
2026-09-04 01:43:12
(3 hours ago)
Domain : bondinterfaceshop.co.uk
Rule : hack
2026-09-04 01:42:35 ***hidden-privacy*** GET /config.ph ...
show more
Domain : bondinterfaceshop.co.uk
Rule : hack
2026-09-04 01:42:35 ***hidden-privacy*** GET /config.php.bak - 443 - 34.104.129.41 HTTP/1.1 Mozilla/5.0 (compatible; Discordbot/2.0; https://discordapp.com) - bondinterfaceshop.co.uk 404 0 2 12904 271 244 - -
show less
Hacking
SQL Injection
Brute-Force
🇺🇸
mc4bbs
2026-09-04 01:24:43
(4 hours ago)
Automated Apache detection on Windows host. 5 suspicious HTTP requests within 300 seconds. Examples: ...
show more
Automated Apache detection on Windows host. 5 suspicious HTTP requests within 300 seconds. Examples: GET /@fs/root/.env?raw?? -> 404 UA=""; GET /@fs/.env?raw?? -> 404 UA=""; GET /@fs/app/.env?raw?? -> 404 UA=""; GET /@fs/src/.env?raw?? -> 404 UA=""; GET /@fs/..%252f..%252f..%252f..%252f..%252fproc/self/environ?raw?? -> 404 UA=""
show less
Web App Attack
Hacking
🇺🇦
URAN Publishing Service
2026-09-04 00:24:29
(5 hours ago)
[04/Sep/2026:03:24:29 +0300] -- 34.104.129.41 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET / ...
show more
[04/Sep/2026:03:24:29 +0300] -- 34.104.129.41 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET /@fs/.env?raw?? HTTP/1.1
show less
Bad Web Bot
Web App Attack
🇸🇪
vaia.cloud
2026-09-03 23:45:02
(5 hours ago)
crowdsecurity/http-probing
Brute-Force
Web App Attack