๐บ๐ธ
kosada.com
2026-08-19 02:35:43
(1 hour ago)
Web vulnerability probing: /@fs/proc/self/environ
Web App Attack
๐ซ๐ท
largo-it.net
2026-08-19 01:33:55
(2 hours ago)
Aug 19 03:33:54 vps-9f3cdc33 haproxy[2617427]: 34.126.183.131:61410 [19/Aug/2026:03:33:53.987] www_f ...
show more
Aug 19 03:33:54 vps-9f3cdc33 haproxy[2617427]: 34.126.183.131:61410 [19/Aug/2026:03:33:53.987] www_frontend~ finance_cluster/finance1_test1_https 0/0/10/79/89 404 3252 - - ---- 116/72/10/10/0 0/0 "GET /config.js HTTP/1.1"
Aug 19 03:33:54 vps-9f3cdc33 haproxy[2617427]: 34.126.183.131:61312 [19/Aug/2026:03:33:53.987] www_frontend~ finance_cluster/finance1_test1_https 0/0/10/322/332 404 3252 - - ---- 114/70/31/31/0 0/0 "GET /@fs/proc/self/environ HTTP/1.1"
Aug 19 03:33:54 vps-9f3cdc33 haproxy[2617427]: 34.126.183.131:61328 [19/Aug/2026:03:33:53.982] www_frontend~ finance_cluster/finance1_test1_https 0/0/11/340/351 404 3252 - - ---- 114/70/30/30/0 0/0 "GET /@fs/home/ec2-user/.aws/credentials?raw?? HTTP/1.1"
Aug 19 03:33:54 vps-9f3cdc33 haproxy[2617427]: 34.126.183.131:61416 [19/Aug/2026:03:33:53.995] www_frontend~ finance_cluster/finance1_test1_https 0/0/11/358/369 404 3252 - - ---- 114/70/29/29/0 0/0 "GET /@fs/etc/passwd?raw?? HTTP/1.1"
Aug 19 03:33:54 vps-9f3cdc33 haproxy[2617427]: 34.12
...
show less
Hacking
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-08-19 01:15:29
(2 hours ago)
Restricted File Access Attempt. Matched phrase "proc/1" at REQUEST_FILENAME. (930130-195)
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-19 00:37:46
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.126.183.131 (131.183.126.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.126.183.131 (131.183.126.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 18 20:37:39.976474 2026] [security2:error] [pid 13146:tid 13146] [client 34.126.183.131:26124] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.landjudging.com"] [uri "/.git/HEAD"] [unique_id "aoT606v4ftDq1GTgU4gz4gAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
hghosting
2026-08-19 00:22:59
(3 hours ago)
CrowdSec auto-report: crowdsecurity/http-probing โ 11 events
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-08-18 21:29:37
(6 hours ago)
(mod_security) mod_security (id:210580) triggered by 34.126.183.131 (131.183.126.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210580) triggered by 34.126.183.131 (131.183.126.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 18 17:29:31.510492 2026] [security2:error] [pid 10619:tid 10619] [client 34.126.183.131:37822] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "proc/self/environ" at ARGS:url. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/08_Global_Other.conf"] [line "57"] [id "210580"] [rev "2"] [msg "COMODO WAF: OS File Access Attempt||www.anxietyquest.com|F|2"] [data "Matched Data: proc/self/environ found within ARGS:url: file:/proc/self/environ"] [severity "CRITICAL"] [tag "CWAF"] [tag "Other"] [hostname "www.anxietyquest.com"] [uri "/read"] [unique_id "aoTOu-qaJVNIBMRITI7YqQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-18 21:12:46
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.126.183.131 (131.183.126.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.126.183.131 (131.183.126.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 18 17:12:41.848016 2026] [security2:error] [pid 12466:tid 12474] [client 34.126.183.131:17394] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.antinats.aafm.us"] [uri "/media../.env"] [unique_id "aoTKyTLeGp9HMIVpLoFy-gAAAMY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
ANTI SCANNER
2026-08-18 21:10:59
(6 hours ago)
Scanner : /@fs/proc/self/environ
Web Spam
๐ฌ๐ง
foxxelabs
2026-08-18 20:57:18
(7 hours ago)
Automated report from FoxxeLabs Sentinel. Path probed: /actuator/env | Project: anseo | Reason(s): K ...
show more
Automated report from FoxxeLabs Sentinel. Path probed: /actuator/env | Project: anseo | Reason(s): Known exploit path: /actuator/env; AbuseIPDB score: 100/100 | User-Agent: Mozilla/5.0 (compatible; Google-Extended/1.0; +http://www.google.com/bot.html)
show less
Web App Attack
๐ณ๐ฑ
Savvii
2026-08-18 19:09:34
(8 hours ago)
10 attempts against mh-misc-ban on joost-st
Web App Attack
Anonymous
2026-08-18 19:01:20
(9 hours ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
Anonymous
2026-08-18 17:40:07
(10 hours ago)
CVE-2025-30208 - ViteJS Traversal Exploit - HTTP(Request)
Hacking
๐บ๐ธ
mnsf
2026-08-18 17:05:17
(11 hours ago)
Scanning/Probing (12)
Brute-Force
Web App Attack
๐ณ๐ฟ
Antinson
2026-08-18 16:32:20
(11 hours ago)
Scraping with a high error ratio and request rate
Bad Web Bot
๐ฌ๐ง
consul.to
2026-08-18 16:18:46
(11 hours ago)
Web attack/malicious scanning detected
Web App Attack