🇳🇱
Savvii
2026-08-29 17:47:31
(51 minutes ago)
20 attempts against mh-misbehave-ban on ozone
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
FeG Deutschland
2026-08-29 15:52:33
(2 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 12
Exploited Host
Web App Attack
🇫🇷
Lacrimosa99
2026-08-29 15:32:03
(3 hours ago)
34.11.30.255 - - [29/Aug/2026:17:31:59 +0200] "GET / HTTP/1.1" 403 6257 "-" "Mozilla/5.0 (iPhone; CP ...
show more
34.11.30.255 - - [29/Aug/2026:17:31:59 +0200] "GET / HTTP/1.1" 403 6257 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_0 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Mobile/15E148 Safari/604.1"
34.11.30.255 - - [29/Aug/2026:17:32:02 +0200] "GET / HTTP/1.1" 403 930 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36 Edg/126.0.0.0"
34.11.30.255 - - [29/Aug/2026:17:32:02 +0200] "GET /@fs/home/admin/.aws/credentials?raw?? HTTP/1.1" 404 927 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.7205.166 Safari/537.36; compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexity-user"
...
show less
Web Spam
🇩🇪
thesimonmanuel
2026-08-29 14:20:44
(4 hours ago)
34.11.30.255 - - [29/Aug/2026:19:50:44 +0530] "GET /@fs/.env.production?raw?? HTTP/1.1" 404 558 "-" ...
show more
34.11.30.255 - - [29/Aug/2026:19:50:44 +0530] "GET /@fs/.env.production?raw?? HTTP/1.1" 404 558 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14.5; rv:121.1) Gecko/20100101 Firefox/121.1; compatible; Discordbot/2.0; +https://discordapp.com" "-"
show less
Web App Attack
🇪🇸
alferez
2026-08-29 10:52:40
(7 hours ago)
Searching .(env|sql|zip|tar|rar) files
Hacking
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2026-08-29 10:51:57
(7 hours ago)
(mod_security) mod_security (id:949110) triggered by 34.11.30.255 (255.30.11.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:949110) triggered by 34.11.30.255 (255.30.11.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 06:51:50.613470 2026] [security2:error] [pid 16370:tid 16370] [client 34.11.30.255:63894] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "thebealcompany.net.armstrongenvironmental.com"] [uri "/@fs/root/.env"] [unique_id "apK5xtbnL33Q2Ho3GTtcYAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇭
4server
2026-08-29 08:13:11
(10 hours ago)
[SatAug2910:13:04.6531292026][security2:error][pid1038133:tid1038341][client34.11.30.255:0]ModSecuri ...
show more
[SatAug2910:13:04.6531292026][security2:error][pid1038133:tid1038341][client34.11.30.255:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".env\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"610\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"pmprogettazione.ch\"][uri\"/@fs/root/.env\"][unique_id\"apKUkL9GzTZIF8qtWuYzFAAAAIg\"]
show less
Hacking
Web App Attack
🇪🇸
pipeline.es
2026-08-29 08:06:17
(10 hours ago)
Web scanning / probing for vulnerable paths | URL: /@fs/app/serverless.yml?raw?? | Evidence: microsi ...
show more
Web scanning / probing for vulnerable paths | URL: /@fs/app/serverless.yml?raw?? | Evidence: microsites.grupoeuropa.com 34.11.30.255 - - [29/Aug/2026:10:05:58 +0200] \"GET /@fs/app/serverless.yml?raw?? HTTP/1.1\" 404 - \"-\" \"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.8578.125 Safari/537.36 Edg/91.0.8578.125; compatible; OAI-SearchBot/1.4; robots.txt; +https://openai.com/searchbot\" GEOIP_COUNTRY_CODE=US | ASN: GOOGLE-CLOUD-PLATFORM | Country: US
show less
Port Scan
Web App Attack
🇩🇪
ger-stg-sifi1
2026-08-29 08:01:09
(10 hours ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
🇫🇷
dynamix
2026-08-29 07:38:54
(11 hours ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2026-08-29 07:34:42
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.11.30.255 (255.30.11.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.11.30.255 (255.30.11.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 03:34:35.136597 2026] [security2:error] [pid 21433:tid 21453] [client 34.11.30.255:22160] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.cookmanufacturinggroup.com"] [uri "/@fs/.env"] [unique_id "apKLi0j3sRXW_QGdG-UIiQAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-29 05:55:22
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.11.30.255 (255.30.11.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.11.30.255 (255.30.11.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 01:55:14.685086 2026] [security2:error] [pid 18275:tid 18275] [client 34.11.30.255:64860] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.ronaldagrant.com"] [uri "/@fs/.env"] [unique_id "apJ0QmOV-m6FEQjKUQ5F6QAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-08-29 05:51:05
(12 hours ago)
Web attack/malicious scanning detected
Web App Attack
🇺🇸
TPI-Abuse
2026-08-29 05:30:16
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.11.30.255 (255.30.11.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.11.30.255 (255.30.11.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 01:30:08.554048 2026] [security2:error] [pid 12875:tid 12875] [client 34.11.30.255:39754] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "order.thereddoorlounge.com"] [uri "/@fs/src/.env"] [unique_id "apJuYPK378-UqqN2SrxA9gAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-29 05:05:50
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.11.30.255 (255.30.11.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.11.30.255 (255.30.11.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 01:05:46.709041 2026] [security2:error] [pid 13079:tid 13079] [client 34.11.30.255:33212] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.thebronsons.com"] [uri "/@fs/root/.env"] [unique_id "apJoqsk4Nf2239wqbcaV9QAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack