🇳🇱
homeshowdomain.nl
2026-09-04 22:03:23
(3 hours ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-03.
show less
Web App Attack
SSH
Hacking
🇩🇪
updown.io
2026-09-04 17:14:16
(8 hours ago)
{"level":"info","ts":1788542018.9043584,"logger":"http.log.access.log1","msg":"handled request","req ...
show more
{"level":"info","ts":1788542018.9043584,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"34.124.128.221","remote_port":"45166","client_ip":"34.124.128.221","proto":"HTTP/1.1","method":"GET","host":"status.chilltech.ie","uri":"/","headers":{"User-Agent":["Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/148.0.0.0 Safari/537.36"],"Accept":["*/*"],"Accept-Encoding":["gzip"]}},"bytes_read":0,"user_id":"","duration":0.00004781,"size":0,"status":308,"resp_headers":{"Server":["Caddy"],"Connection":["close"],"Location":["https://status.chilltech.ie/"],"Content-Type":[]}}
{"level":"info","ts":1788542025.7491722,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"34.124.128.221","remote_port":"38962","client_ip":"34.124.128.221","proto":"HTTP/1.1","method":"GET","host":"status.chilltech.ie","uri":"/@fs/home/debian/.aws/credentials?raw??","headers":{"Accept":["text/html,application/xhtml+xml,applicat
...
show less
DDoS Attack
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 15:23:08
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.124.128.221 (221.128.124.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.124.128.221 (221.128.124.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 11:23:02.201284 2026] [security2:error] [pid 7649:tid 7649] [client 34.124.128.221:22850] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.willoughbywolf.com"] [uri "/@fs/../../.env"] [unique_id "apriVr4T7zZIKMxgkDNc7wAAACg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 13:47:21
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.124.128.221 (221.128.124.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.124.128.221 (221.128.124.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 09:47:17.941960 2026] [security2:error] [pid 2851:tid 2851] [client 34.124.128.221:54798] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.jimhermelband.com"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252froot/.env"] [unique_id "aprL5QPF61YqKo6gKahuOwAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 13:22:39
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.124.128.221 (221.128.124.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.124.128.221 (221.128.124.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 09:22:35.047888 2026] [security2:error] [pid 17069:tid 17069] [client 34.124.128.221:47926] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.nwsci.net"] [uri "/@fs/.env"] [unique_id "aprGG7Swx7z7WAPGY5UfRQAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇸🇪
vaia.cloud
2026-09-04 13:10:06
(12 hours ago)
crowdsecurity/http-probing
Brute-Force
Web App Attack
Anonymous
2026-09-04 12:55:58
(12 hours ago)
2026/09/04 09:55:57 [error] 1369#1369: *61215 access forbidden by rule, client: 34.124.128.221, serv ...
show more
2026/09/04 09:55:57 [error] 1369#1369: *61215 access forbidden by rule, client: 34.124.128.221, server: n8n.sorotop.com.br, request: "GET /@fs/.env?raw?? HTTP/1.1", host: "n8n.sorotop.com.br"
2026/09/04 09:55:57 [error] 1371#1371: *61217 access forbidden by rule, client: 34.124.128.221, server: n8n.sorotop.com.br, request: "GET /@fs/src/.env?raw?? HTTP/1.1", host: "n8n.sorotop.com.br"
2026/09/04 09:55:57 [error] 1369#1369: *61216 access forbidden by rule, client: 34.124.128.221, server: n8n.sorotop.com.br, request: "GET /@fs/root/.env?raw?? HTTP/1.1", host: "n8n.sorotop.com.br"
...
show less
Port Scan
🇪🇸
alferez
2026-09-04 11:07:22
(14 hours ago)
Searching .(env|sql|zip|tar|rar) files
Hacking
Exploited Host
Web App Attack
🇺🇸
Rocky Mountain Bioengineering Symposium
2026-09-04 10:58:39
(14 hours ago)
[Fri Sep 04 04:58:38.612928 2026] [authz_core:error] [pid 200881:tid 140669330892352] [client 34.124 ...
show more
[Fri Sep 04 04:58:38.612928 2026] [authz_core:error] [pid 200881:tid 140669330892352] [client 34.124.128.221:50238] AH01630: client denied by server configuration: /var/www/horde/.env.swp
[Fri Sep 04 04:58:38.618752 2026] [authz_core:error] [pid 201276:tid 140669767116352] [client 34.124.128.221:50338] AH01630: client denied by server configuration: /var/www/horde/config/.env
[Fri Sep 04 04:58:38.624730 2026] [authz_core:error] [pid 201276:tid 140669205067328] [client 34.124.128.221:50216] AH01630: client denied by server configuration: /var/www/horde/.env.bak
...
show less
Bad Web Bot
🇳🇱
ConsulHosting
2026-09-04 10:05:50
(15 hours ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 10:04:22
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.124.128.221 (221.128.124.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.124.128.221 (221.128.124.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:04:18.049471 2026] [security2:error] [pid 5203:tid 5203] [client 34.124.128.221:1058] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.noisepie.com"] [uri "/@fs/../../.env"] [unique_id "apqXon9GQTW_yfdtGYm9WQAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇷🇴
iulianh
2026-09-04 10:03:32
(15 hours ago)
80,443
Brute-Force
SSH
🇺🇸
TPI-Abuse
2026-09-04 09:39:33
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.124.128.221 (221.128.124.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.124.128.221 (221.128.124.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 05:39:25.924279 2026] [security2:error] [pid 2824996:tid 2825036] [client 34.124.128.221:14000] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.relatedlinks.giere.us"] [uri "/@fs/.env"] [unique_id "apqRzR0fUXAXMoF-M9vZTgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 09:18:14
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.124.128.221 (221.128.124.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.124.128.221 (221.128.124.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 05:18:09.026991 2026] [security2:error] [pid 2418:tid 2418] [client 34.124.128.221:45656] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.oldmaninthepeanut.com"] [uri "/@fs/app/.env"] [unique_id "apqM0W6dbOCDz_992les_QAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 08:50:17
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.124.128.221 (221.128.124.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.124.128.221 (221.128.124.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 04:50:12.521908 2026] [security2:error] [pid 12765:tid 12765] [client 34.124.128.221:4184] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.northfortworthalliance.com"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252froot/.env"] [unique_id "apqGRMy5oSIkxL9qE6GVCAAAAC8"]
show less
Brute-Force
Bad Web Bot
Web App Attack