๐ธ๐ช
KIDOS
2026-08-28 13:55:18
(3 weeks ago)
CrowdSec detected malicious activity
DDoS Attack
๐ธ๐ช
KIDOS
2026-08-28 13:40:10
(3 weeks ago)
IIS malicious activity: dir_traversal_attempt
Web App Attack
๐ฆ๐บ
rubixstudios
2026-08-28 12:45:02
(3 weeks ago)
Excessive HTTP requests consistent with automated attack behaviour detected by Imunify360
DDoS Attack
Brute-Force
Web App Attack
๐ฉ๐ช
BlueWire Hosting
2026-08-28 12:44:05
(3 weeks ago)
Probing websites for vulnerabilities
Web App Attack
๐ช๐ธ
masterguru
2026-08-28 11:12:56
(3 weeks ago)
BAD BOT - Detected and Blocked.. Matched phrase "OAI-SearchBot" at REQUEST_HEADERS:User-Agent. (1100 ...
show more
BAD BOT - Detected and Blocked.. Matched phrase "OAI-SearchBot" at REQUEST_HEADERS:User-Agent. (1100000-122)
show less
Bad Web Bot
๐ฎ๐น
mediarama.com
2026-08-28 10:25:22
(3 weeks ago)
Banned by Fail2Ban
Web App Attack
๐ฉ๐ช
thesimonmanuel
2026-08-28 09:56:12
(3 weeks ago)
34.104.149.20 - - [28/Aug/2026:15:26:11 +0530] "GET /@fs/root/.aws/credentials?raw?? HTTP/1.1" 404 8 ...
show more
34.104.149.20 - - [28/Aug/2026:15:26:11 +0530] "GET /@fs/root/.aws/credentials?raw?? HTTP/1.1" 404 8326 "https://www.[redacted].com/@fs/root/.aws/credentials?raw??" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.318.55 Safari/537.36 Edg/91.0.318.55; compatible; TelegramBot/1.0"
show less
Web App Attack
๐บ๐ธ
WellSpring
2026-08-28 06:57:17
(3 weeks ago)
env leak on 828.today/@fs/home/ubuntu/.env โ WellSpr.ing/NetSentinel civic-AI security layer
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 05:28:51
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.104.149.20 (20.149.104.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.104.149.20 (20.149.104.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 01:28:44.223607 2026] [security2:error] [pid 7054:tid 7054] [client 34.104.149.20:19290] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.d365geek.com"] [uri "/@fs/.env.staging"] [unique_id "apEcjBm8imMLdSci__TSXAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Gwyneth Llewelyn
2026-08-28 05:27:44
(3 weeks ago)
2026/08/28 06:27:42 [error] 380594#380594: *1052708 access forbidden by rule, client: 34.104.149.20, ...
show more
2026/08/28 06:27:42 [error] 380594#380594: *1052708 access forbidden by rule, client: 34.104.149.20, server: alzulej.pt, request: "GET /autodiscover.xml/api/.env HTTP/2.0", host: "alzulej.pt", referrer: "https://autodiscover.alzulej.pt/api/.env"
2026/08/28 06:27:42 [error] 380594#380594: *1052707 access forbidden by rule, client: 34.104.149.20, server: alzulej.pt, request: "GET /autodiscover.xml/v1/.env HTTP/2.0", host: "alzulej.pt", referrer: "https://autodiscover.alzulej.pt/v1/.env"
2026/08/28 06:27:42 [error] 380594#380594: *1052704 access forbidden by rule, client: 34.104.149.20, server: alzulej.pt, request: "GET /autodiscover.xml/src/.env HTTP/2.0", host: "alzulej.pt", referrer: "https://autodiscover.alzulej.pt/src/.env"
show less
Brute-Force
Web App Attack
๐ธ๐ช
vaia.cloud
2026-08-28 05:25:02
(3 weeks ago)
crowdsecurity/http-probing
Brute-Force
Web App Attack
๐ซ๐ท
georgton.tech
2026-08-28 04:29:00
(3 weeks ago)
34.104.149.20 - - [28/Aug/2026:01:28:43 -0300] "GET /@fs/../../.env?raw?? HTTP/1.1" 400 166 "-" "-"
...
show more
34.104.149.20 - - [28/Aug/2026:01:28:43 -0300] "GET /@fs/../../.env?raw?? HTTP/1.1" 400 166 "-" "-"
34.104.149.20 - - [28/Aug/2026:01:28:59 -0300] "GET /@fs/..%2f..%2f..%2f..%2f..%2fproc/self/environ?raw?? HTTP/1.1" 400 166 "-" "-"
34.104.149.20 - - [28/Aug/2026:01:28:59 -0300] "GET /@fs/..%2f..%2f..%2f..%2f..%2fapp/.env?raw?? HTTP/1.1" 400 166 "-" "-"
...
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-08-28 04:17:57
(3 weeks ago)
Excessive multi-domain requests
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-08-28 04:16:13
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.104.149.20 (20.149.104.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.104.149.20 (20.149.104.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 00:16:09.411672 2026] [security2:error] [pid 3455:tid 3455] [client 34.104.149.20:10888] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.onlyincanada-eh.com"] [uri "/@fs/root/.env"] [unique_id "apELiTt4QeYP8G0sQ-PQZgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 03:32:42
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.104.149.20 (20.149.104.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.104.149.20 (20.149.104.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 23:32:36.680886 2026] [security2:error] [pid 1277:tid 1277] [client 34.104.149.20:62852] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.encoreporchfest.info"] [uri "/@fs/src/.env"] [unique_id "apEBVA2Cjk8jpap-6CO2GQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack