🇧🇪
boxed-it
2026-09-12 08:24:40
(3 days ago)
GET /.env (Tarpitted for 1d15h8m28s, wasted 8.06MB)
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 23:32:19
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.138.92.110 (110.92.138.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.138.92.110 (110.92.138.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 19:32:12.424644 2026] [security2:error] [pid 3554:tid 3563] [client 34.138.92.110:7232] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.24"] [uri "/static../.env"] [unique_id "aqSPfGxsx8PuagxyMv8CmwAAAMY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
sbocquet
2026-09-11 23:10:08
(3 days ago)
Port 443 scanned from 34.138.92.110:8164.
Port Scan
🇳🇱
ipoac.nl
2026-09-11 15:41:22
(3 days ago)
[Fri Sep 11 17:41:20.507452 2026] [core:error] [pid 2719339:tid 2719764] [client 34.138.92.110:42186 ...
show more
[Fri Sep 11 17:41:20.507452 2026] [core:error] [pid 2719339:tid 2719764] [client 34.138.92.110:42186] AH10244: invalid URI path (/assets../../../etc/passwd)
show less
Hacking
🇫🇮
pixiekat
2026-09-11 15:16:39
(3 days ago)
[Fri Sep 11 16:16:34.135941 2026] [authz_core:error] [pid 3689055:tid 3689136] [client 34.138.92.110 ...
show more
[Fri Sep 11 16:16:34.135941 2026] [authz_core:error] [pid 3689055:tid 3689136] [client 34.138.92.110:33676] AH01630: client denied by server configuration: /var/www/html/
[Fri Sep 11 16:16:35.882930 2026] [authz_core:error] [pid 3689056:tid 3689133] [client 34.138.92.110:13002] AH01630: client denied by server configuration: /var/www/html/__aws_leak_probe_12309ef9__
[Fri Sep 11 16:16:36.500141 2026] [authz_core:error] [pid 3689056:tid 3689168] [client 34.138.92.110:13002] AH01630: client denied by server configuration: /var/www/html/static..
[Fri Sep 11 16:16:37.135710 2026] [authz_core:error] [pid 3689056:tid 3689132] [client 34.138.92.110:13002] AH01630: client denied by server configuration: /var/www/html/media..
[Fri Sep 11 16:16:38.179037 2026] [authz_core:error] [pid 3689056:tid 3689155] [client 34.138.92.110:13002] AH01630: client denied by server configuration: /var/www/html/@fs
...
show less
Brute-Force
🇩🇪
Uwe Sarpe
2026-09-11 14:06:37
(3 days ago)
[Fri Sep 11 16:06:33.718472 2026] [access_compat:error] [pid 142073:tid 142073] [client 34.138.92.11 ...
show more
[Fri Sep 11 16:06:33.718472 2026] [access_compat:error] [pid 142073:tid 142073] [client 34.138.92.110:42192] AH01797: client denied by server configuration: /var/www/__aws_leak_probe_685b6a6c__
[Fri Sep 11 16:06:37.162978 2026] [access_compat:error] [pid 119028:tid 119028] [client 34.138.92.110:45358] AH01797: client denied by server configuration: /var/www/media..
[Fri Sep 11 16:06:37.164336 2026] [access_compat:error] [pid 142074:tid 142074] [client 34.138.92.110:45274] AH01797: client denied by server configuration: /var/www/@fs
[Fri Sep 11 16:06:37.186880 2026] [access_compat:error] [pid 142073:tid 142073] [client 34.138.92.110:45294] AH01797: client denied by server configuration: /var/www/.env
[Fri Sep 11 16:06:37.186880 2026] [access_compat:error] [pid 127917:tid 127917] [client 34.138.92.110:45216] AH01797: client denied by server configuration: /var/www/@fs
...
show less
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 13:23:47
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.138.92.110 (110.92.138.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.138.92.110 (110.92.138.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 09:23:40.547132 2026] [security2:error] [pid 959:tid 959] [client 34.138.92.110:54498] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.171"] [uri "/static../.env"] [unique_id "aqQA3JyMercBI5mM490EsgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇿
Antinson
2026-09-11 04:32:56
(4 days ago)
Scraping with a high error ratio and request rate
Bad Web Bot
🇳🇱
Savvii
2026-09-11 03:53:05
(4 days ago)
15 attempts against mh-modsecurity-ban on ice
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 03:11:09
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.138.92.110 (110.92.138.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.138.92.110 (110.92.138.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 10 23:11:01.260968 2026] [security2:error] [pid 1443:tid 1443] [client 34.138.92.110:40354] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.32"] [uri "/static../.env"] [unique_id "aqNxReFXi96z_TmsHZQ-ogAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-11 02:08:38
(4 days ago)
denied traffic to a honeypot network. destination port 8443.
Port Scan
Hacking
🇫🇷
✨
2026-09-11 00:44:20
(4 days ago)
Domain : pleskcontrolpanel
Rule : env
2026-09-11 00:42:06 79.171.39.126 GET /static../.env - 8443 - ...
show more
Domain : pleskcontrolpanel
Rule : env
2026-09-11 00:42:06 79.171.39.126 GET /static../.env - 8443 - 34.138.92.110 Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:78.1) Gecko/20100101 Firefox/78.1; compatible; TelegramBot/1.0 - 404 0 2 74 - -
show less
Hacking
SQL Injection
🇺🇸
RidgeStar
2026-09-10 19:37:57
(4 days ago)
Port Scan
Hacking
🇫🇷
pm33
2026-09-10 19:13:48
(4 days ago)
Unauthorized connections HTTP 403
Web App Attack
🇸🇪
vaia.cloud
2026-09-10 19:00:02
(4 days ago)
crowdsecurity/http-cve-2021-41773
Brute-Force
Web App Attack