๐ณ๐ฑ
homeshowdomain.nl
2026-08-27 21:59:34
(3 days ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-08-26.
show less
Web App Attack
SSH
Hacking
๐ฎ๐ณ
evicky2002
2026-08-27 06:00:33
(4 days ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐ฌ๐ง
openstrike.co.uk
2026-08-27 05:14:01
(4 days ago)
216 attacks on site downloads, PHP URLs, config grabbing URLs (type 2), env grabbing URLs, directory ...
show more
216 attacks on site downloads, PHP URLs, config grabbing URLs (type 2), env grabbing URLs, directory traversals, password grabbing URLs, VC URLs:
GET /dump.sql HTTP/1.1
GET /info.php HTTP/1.1
GET /appspec.yml HTTP/1.1
GET /aws/.env HTTP/1.1
GET /..%252F..%252F..%252F..%252F..%252Fproc/self/environ HTTP/1.1
GET /.vscode/sftp.json HTTP/1.1
GET /.git/config HTTP/1.1
show less
Hacking
Web App Attack
Anonymous
2026-08-26 19:51:38
(4 days ago)
(mod_security) mod_security triggered on hostname [redacted] 34.13.224.135 (135.224.13.34.bc.googleu ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.13.224.135 (135.224.13.34.bc.googleusercontent.com)
show less
SQL Injection
๐ฉ๐ช
DEV-DNS
2026-08-26 19:51:25
(4 days ago)
(php-url-fopen) Failed php-url-fopen trigger from 34.13.224.135 (NL/The Netherlands/Groningen/Gronin ...
show more
(php-url-fopen) Failed php-url-fopen trigger from 34.13.224.135 (NL/The Netherlands/Groningen/Groningen/135.224.13.34.bc.googleusercontent.com/[redacted])
show less
Web App Attack
Anonymous
2026-08-26 18:23:48
(5 days ago)
34.13.224.135 - - [26/Aug/2026:20:23:39 +0200] "GET /assets../../../etc/passwd HTTP/1.1" 400 150 "-" ...
show more
34.13.224.135 - - [26/Aug/2026:20:23:39 +0200] "GET /assets../../../etc/passwd HTTP/1.1" 400 150 "-" "-"
34.13.224.135 - - [26/Aug/2026:20:23:40 +0200] "GET /assets../../../.env HTTP/1.1" 400 150 "-" "-"
34.13.224.135 - - [26/Aug/2026:20:23:48 +0200] "GET /public/plugins/alertlist/../../../../../../../../.env HTTP/1.1" 400 150 "-" "-"
34.13.224.135 - - [26/Aug/2026:20:23:48 +0200] "GET /cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/proc/self/environ HTTP/1.1" 400 150 "-" "-"
34.13.224.135 - - [26/Aug/2026:20:23:48 +0200] "GET /icons/.%2e/.%2e/.%2e/.%2e/.env HTTP/1.1" 400 150 "-" "-"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 18:22:17
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 34.13.224.135 (135.224.13.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.13.224.135 (135.224.13.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 14:22:12.510810 2026] [security2:error] [pid 32165:tid 32165] [client 34.13.224.135:24164] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "styxwamworld.com"] [uri "/@fs/../.env"] [unique_id "ao8u1BPcU7DkwsZ57SLN-gAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
grassau.com
2026-08-26 17:57:00
(5 days ago)
*Port Scan* detected from 34.13.224.135 (NL/The Netherlands/Groningen/Groningen/135.224.13.34.bc.goo ...
show more
*Port Scan* detected from 34.13.224.135 (NL/The Netherlands/Groningen/Groningen/135.224.13.34.bc.googleusercontent.com).
show less
Port Scan
Anonymous
2026-08-26 17:51:12
(5 days ago)
Bot / seems abusive / Apache connections: 21
DDoS Attack
Web Spam
Bad Web Bot
Web App Attack
๐ซ๐ท
COMAITE
2026-08-26 17:10:16
(5 days ago)
Common web attack from 34.13.224.135.
Web App Attack
๐ฌ๐ง
consul.to
2026-08-26 16:56:35
(5 days ago)
Web attack/malicious scanning detected
Web App Attack
๐ซ๐ท
Hippoline
2026-08-26 16:56:16
(5 days ago)
[Wed Aug 26 18:56:11.250781 2026] [authz_core:error] [pid 2163] [client 34.13.224.135:28118] AH01630 ...
show more
[Wed Aug 26 18:56:11.250781 2026] [authz_core:error] [pid 2163] [client 34.13.224.135:28118] AH01630: client denied by server configuration: /var/www/beaufort-online.lu/web/.env.local.php
[Wed Aug 26 18:56:11.258043 2026] [authz_core:error] [pid 1515] [client 34.13.224.135:28064] AH01630: client denied by server configuration: /var/www/beaufort-online.lu/web/.env.php
[Wed Aug 26 18:56:15.180486 2026] [authz_core:error] [pid 2230] [client 34.13.224.135:50512] AH01630: client denied by server configuration: /var/www/beaufort-online.lu/web/phpinfo.php
[Wed Aug 26 18:56:15.320883 2026] [authz_core:error] [pid 2272] [client 34.13.224.135:50418] AH01630: client denied by server configuration: /var/www/beaufort-online.lu/web/app_dev.php
[Wed Aug 26 18:56:15.439666 2026] [authz_core:error] [pid 2032] [client 34.13.224.135:28252] AH01630: client denied by server configuration: /var/www/beaufort-online.lu/web/app_dev.php
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 16:05:32
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 34.13.224.135 (135.224.13.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.13.224.135 (135.224.13.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 12:05:25.339477 2026] [security2:error] [pid 22138:tid 22138] [client 34.13.224.135:18952] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "twinls.com"] [uri "/static../.env"] [unique_id "ao8OxTt2G6f9u_9ASvYHdgAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 15:43:08
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 34.13.224.135 (135.224.13.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.13.224.135 (135.224.13.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 11:43:02.038680 2026] [security2:error] [pid 30687:tid 30687] [client 34.13.224.135:24772] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "podbillspec.com"] [uri "/media../.env"] [unique_id "ao8Jhv-9xYsA4ioImz5hTQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 13:22:58
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 34.13.224.135 (135.224.13.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.13.224.135 (135.224.13.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 09:22:53.595575 2026] [security2:error] [pid 24645:tid 24645] [client 34.13.224.135:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cloudex.click"] [uri "/.env"] [unique_id "ao7orXK3EJGIhF0L2sS6mQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack