๐ช๐ธ
librebit
2026-08-28 14:59:08
(10 hours ago)
Bad guys doing bad things, bad crawling
Bad Web Bot
๐บ๐ธ
markiper
2026-08-28 13:04:00
(12 hours ago)
Brute-Force
๐ฆ๐น
penguin-solutions.at
2026-08-28 12:42:00
(12 hours ago)
Excessive 403/404 errors
...
Brute-Force
Web App Attack
๐ช๐ธ
el-brujo
2026-08-28 12:29:21
(13 hours ago)
28/Aug/2026:14:29:20.989175 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client ...
show more
28/Aug/2026:14:29:20.989175 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 34.125.92.34] ModSecurity: Access denied with code 406 (phase 2). Pattern match "etc/passwd" at REQUEST_URI. [file "/etc/httpd/conf.d/mod_security.conf"] [line "124"] [id "500001"] [hostname "ns2.elhacker.net"] [uri "/@fs/etc/passwd"] [unique_id "apF_IDyMbGqa7oZv-fovtAAEgA8"]
...
show less
Hacking
Web App Attack
๐ซ๐ท
masterguru
2026-08-28 10:44:16
(14 hours ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-197)
Hacking
Web App Attack
๐ง๐ช
madeit
2026-08-28 09:07:35
(16 hours ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 08:55:22
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.125.92.34 (34.92.125.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.125.92.34 (34.92.125.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 04:55:15.814771 2026] [security2:error] [pid 27179:tid 27179] [client 34.125.92.34:9650] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.catnameslist.bodybuildbid.com"] [uri "/@fs/root/.env"] [unique_id "apFM86rIfbt5s5B8NQVtQQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-08-28 08:53:25
(16 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-08-28 08:39:32
(16 hours ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.125.92.34 (US/United States/34.92. ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.125.92.34 (US/United States/34.92.125.34.bc.googleusercontent.com): 1 in the last 3600 secs (0-195)
show less
Hacking
๐ท๐ด
clauss
2026-08-28 08:23:26
(17 hours ago)
34.125.92.34 - - [28/Aug/2026:11:23:25 +0300] "GET /@fs/root/.anthropic/config.json?raw?? HTTP/2.0" ...
show more
34.125.92.34 - - [28/Aug/2026:11:23:25 +0300] "GET /@fs/root/.anthropic/config.json?raw?? HTTP/2.0" 404 22088 "-" "Mozilla/5.0 (Windows NT 11.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko; compatible; OAI-SearchBot/1.4; robots.txt; +https://openai.com/searchbot) Chrome/122.0.1800.104 Safari/537.36"
34.125.92.34 - - [28/Aug/2026:11:23:25 +0300] "GET /@fs/root/.config/openai/config.json?raw?? HTTP/2.0" 404 22088 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko; compatible; Twitterbot/1.0) Chrome/131.0.4262.82 Safari/537.36"
...
show less
Web App Attack
๐ณ๐ฑ
JCB
2026-08-28 08:14:00
(17 hours ago)
34.125.92.34 - - [28/Aug/2026:10:37:56 +0300] "GET /@fs/.env.production?raw?? HTTP/1.1" 404 236 "-" ...
show more
34.125.92.34 - - [28/Aug/2026:10:37:56 +0300] "GET /@fs/.env.production?raw?? HTTP/1.1" 404 236 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Discordbot/2.0; +https://discordapp.com)"
34.125.92.34 - - [28/Aug/2026:10:37:56 +0300] "GET /@fs/app/.aws/credentials?raw?? HTTP/1.1" 404 236 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; GrokBot/1.0; +https://x.ai/grokbot"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 07:58:12
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.125.92.34 (34.92.125.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.125.92.34 (34.92.125.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 03:58:05.471564 2026] [security2:error] [pid 30691:tid 30691] [client 34.125.92.34:49290] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thomasanthonyquinn.com"] [uri "/@fs/root/.env"] [unique_id "apE_jRQR82wUSMWu2ONFMAAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 07:07:32
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.125.92.34 (34.92.125.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.125.92.34 (34.92.125.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 03:07:27.172108 2026] [security2:error] [pid 19223:tid 19223] [client 34.125.92.34:42976] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.earlsworkshop.com"] [uri "/@fs/src/.env"] [unique_id "apEzr7h4FL4TTIXK1ch2ZQAAACQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
zynex
2026-08-28 07:06:39
(18 hours ago)
URL Probing: /@fs/src/.env
Web App Attack
๐ธ๐ช
vaia.cloud
2026-08-28 06:40:01
(18 hours ago)
crowdsecurity/http-probing
Brute-Force
Web App Attack