🇮🇳
evicky2002
2026-09-09 00:01:20
(13 hours ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
Anonymous
2026-09-08 13:00:08
(1 day ago)
timestamp: 2026-09-08T14:00:07.537
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 11:39:32
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.104.235.111 (111.235.104.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.104.235.111 (111.235.104.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 07:39:28.377051 2026] [security2:error] [pid 6622:tid 6622] [client 34.104.235.111:38160] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.beebesties.com"] [uri "/@fs/root/.env"] [unique_id "ap_z8C1iT48A7oU5vFfOJQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-08 11:03:22
(1 day ago)
34.104.235.111 - - [08/Sep/2026:19:03:21 +0800] "GET /@fs/root/rootkey.csv?raw?? HTTP/1.1" 404 196 " ...
show more
34.104.235.111 - - [08/Sep/2026:19:03:21 +0800] "GET /@fs/root/rootkey.csv?raw?? HTTP/1.1" 404 196 "-" "Mozilla/5.0 (compatible; GrokBot/1.0; +https://x.ai/grokbot)"
34.104.235.111 - - [08/Sep/2026:19:03:21 +0800] "GET /@fs/.env.staging?raw?? HTTP/1.1" 404 196 "-" "Mozilla/5.0 (Linux; Android 13; Pixel 7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.8715.96 Mobile Safari/537.36; compatible; WhatsApp/10.0.2.1"
34.104.235.111 - - [08/Sep/2026:19:03:21 +0800] "GET /@fs/.env.development?raw?? HTTP/1.1" 404 196 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.3051.21 Safari/537.36 Edg/134.0.3051.21; compatible; Bytespider; +https://zhanzhang.toutiao.com/"
34.104.235.111 - - [08/Sep/2026:19:03:21 +0800] "GET /@fs/home/ubuntu/.aws/config?raw?? HTTP/1.1" 404 196 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; GPTBot/1.2; +https://openai.com/gptbot)"
34.104.235.111 - - [08/Sep/2026:19:03:21 +0800] "GET /@fs/root/
...
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 10:48:23
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.104.235.111 (111.235.104.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.104.235.111 (111.235.104.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 06:48:16.081272 2026] [security2:error] [pid 1291:tid 1305] [client 34.104.235.111:26098] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mwcecommerce.com"] [uri "/@fs/.env"] [unique_id "ap_n8GEpWX-3eUDUg298iwAAAUs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-08 09:44:01
(1 day ago)
(mod_security) mod_security triggered on hostname [redacted])
SQL Injection
Anonymous
2026-09-08 09:33:24
(1 day ago)
Multiple web server 400 error codes from same source ip
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 09:00:20
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.104.235.111 (111.235.104.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.104.235.111 (111.235.104.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 05:00:12.438238 2026] [security2:error] [pid 24498:tid 24498] [client 34.104.235.111:57468] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "styxwamworld.com"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252froot/.env"] [unique_id "ap_OnJlp_ZuGLneLpkuQWQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇲🇾
Rizzy
2026-09-08 08:53:28
(1 day ago)
Multiple WAF Violations
Brute-Force
Web App Attack
🇫🇷
masterguru
2026-09-08 07:45:32
(1 day ago)
Restricted File Access Attempt. Matched phrase "/@fs/" at REQUEST_FILENAME. (930130-193)
Hacking
Web App Attack
Anonymous
2026-09-08 06:17:12
(1 day ago)
Bot / seems abusive / Apache connections: 33
DDoS Attack
Web Spam
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 06:16:34
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.104.235.111 (111.235.104.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.104.235.111 (111.235.104.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 02:16:30.430421 2026] [security2:error] [pid 8049:tid 8049] [client 34.104.235.111:19812] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "boat-accessories.net"] [uri "/@fs/app/.env"] [unique_id "ap-oPv4snIAxqBZ85eeVdgAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
paissangroup
2026-09-08 05:57:30
(1 day ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 05:51:21
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.104.235.111 (111.235.104.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.104.235.111 (111.235.104.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 01:51:13.019186 2026] [security2:error] [pid 8136:tid 8136] [client 34.104.235.111:45142] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.cultiplant.com"] [uri "/@fs/app/.env"] [unique_id "ap-iUQJGI0bfFJotmO88EwAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
FD-IX
2026-09-08 05:35:43
(1 day ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack