Anonymous
2026-09-05 16:15:36
(17 hours ago)
34.131.163.206 - - [05/Sep/2026:11:15:30 -0500] "GET /.env HTTP/1.1" 403 199 "-" "Mozilla/5.0 (X11; ...
show more
34.131.163.206 - - [05/Sep/2026:11:15:30 -0500] "GET /.env HTTP/1.1" 403 199 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" 104.23.216.99
34.131.163.206 - - [05/Sep/2026:11:15:31 -0500] "GET /.env.local HTTP/1.1" 403 199 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" 104.23.216.99
34.131.163.206 - - [05/Sep/2026:11:15:31 -0500] "GET /.env.production HTTP/1.1" 403 199 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" 104.23.216.99
34.131.163.206 - - [05/Sep/2026:11:15:31 -0500] "GET /.env.staging HTTP/1.1" 403 199 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" 104.23.216.99
34.131.163.206 - - [05/Sep/2026:11:15:32 -0500] "GET /.env.development HTTP/1.1" 403 199 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0
...
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 15:20:08
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.131.163.206 (206.163.131.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.131.163.206 (206.163.131.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 11:20:01.168649 2026] [security2:error] [pid 17747:tid 17747] [client 34.131.163.206:58496] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "clip24.net"] [uri "/.git/config"] [unique_id "apwzIWC_JOUSasQ5XXJeYgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇭
zynex
2026-09-05 14:59:09
(18 hours ago)
URL Probing: /server/.env
Web App Attack
🇧🇪
madeit
2026-09-05 14:49:09
(18 hours ago)
Web App Attack
🇪🇸
alferez
2026-09-05 14:18:11
(19 hours ago)
Searching .(env|sql|zip|tar|rar) files
Hacking
Exploited Host
Web App Attack
🇫🇷
masterguru
2026-09-05 14:04:57
(19 hours ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-197)
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 13:50:35
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.131.163.206 (206.163.131.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.131.163.206 (206.163.131.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 09:50:30.628263 2026] [security2:error] [pid 2765427:tid 2765427] [client 34.131.163.206:56530] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "clinegroupmarketplace.com"] [uri "/.git/config"] [unique_id "apweJrLwhomdiC4OndFVggAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
CoreTech srl
2026-09-05 12:53:56
(20 hours ago)
cloudlinux2 fail2ban: 2026-09-05 14:49:09,224 fail2ban.filter [1594]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-09-05 14:49:09,224 fail2ban.filter [1594]: INFO [plesk-modsecurity] Found 34.131.163.206 - 2026-09-05 14:49:09cloudlinux2 fail2ban: 2026-09-05 14:49:10,435 fail2ban.actions [1594]: NOTICE [plesk-modsecurity] Ban 34.131.163.206cloudlinux2 fail2ban: 2026-09-05 14:49:10,456 fail2ban.filter [1594]: INFO [plesk-modsecurity] Found 34.131.163.206 - 2026-09-05 14:49:10cloudlinux2 fail2ban: 2026-09-05 14:49:10,068 fail2ban.filter [1594]: INFO [plesk-modsecurity] Found 34.131.163.206 - 2026-09-05 14:49:10cloudlinux2 fail2ban: 2026-09-05 14:49:10,260 fail2ban.filter [1594]: INFO [plesk-modsecurity] Found 34.131.163.206 - 2026-09-05 14:49:10cloudlinux2 fail2ban: 2026-09-05 14:49:10,437 fail2ban.filter [1594]: INFO [recidive] Found 34.131.163.206 - 2026-09-05 14:49:10cloudlinux2 fail2ban: 2026-09-05 14:49:09,939 fail2ban.filter [1594]: INFO [plesk-modsecurity] Found 34.131.163.206 - 2026-09-05 14:49:09cloudlinux2 fail2ban:
show less
Web App Attack
Anonymous
2026-09-05 07:37:26
(1 day ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
🇺🇸
solantex
2026-09-05 07:34:17
(1 day ago)
Requested a path that does not exist in this application (backup/source artifact or foreign software ...
show more
Requested a path that does not exist in this application (backup/source artifact or foreign software path). Refused at nginx with 444.
show less
Web App Attack
🇧🇪
cmbplf
2026-09-05 02:26:30
(1 day ago)
3.780 requests with url.path *.env
620 requests with url.path *phpinfo.php
115 requests with url. ...
show more
3.780 requests with url.path *.env
620 requests with url.path *phpinfo.php
115 requests with url.path *credentials.json
show less
Brute-Force
Bad Web Bot
🇩🇪
v1nc
2026-09-04 19:53:32
(1 day ago)
34.131.163.206 - - [04/Sep/2026:19:53:31 +0000] "GET /cakephp/.env HTTP/1.1" 301 162 "-" "Mozilla/5. ...
show more
34.131.163.206 - - [04/Sep/2026:19:53:31 +0000] "GET /cakephp/.env HTTP/1.1" 301 162 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Hacking
🇳🇱
Site.eu
2026-09-04 18:48:05
(1 day ago)
Excessive 404/403 errors
Brute-Force
🇳🇱
Savvii
2026-09-04 18:31:11
(1 day ago)
20 attempts against mh-misbehave-ban on orcus
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-04 18:20:48
(1 day ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking