🇩🇪
maxpower
2026-09-08 12:35:47
(5 hours ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 34.146.235.229 (JP/Japan/229.235.146.34. ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 34.146.235.229 (JP/Japan/229.235.146.34.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 34.146.235.229 - - [08/Sep/2026:14:35:42 +0200] "GET /@fs/root/.aws/credentials?raw?? HTTP/1.1" 200 12236 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.6690.33 Safari/537.36 Edg/120.0.6690.33; compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexity-user" "-" host=mail.mediaqualitylab.it
show less
Port Scan
🇵🇱
ketovoila.pl
2026-09-08 11:21:56
(6 hours ago)
ketovoila.pl web app secret/repository scan: hits=494; unique_paths=265; sample_paths=/.aws/credenti ...
show more
ketovoila.pl web app secret/repository scan: hits=494; unique_paths=265; sample_paths=/.aws/credentials,/.docker/.env,/.env; UA="Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; GrokBot/1.0; +https://x.ai/grokbot)"; window=2026-09-08T11:21:56Z..2026-09-08T11:24:53Z HTTP methods: GET (494).
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 10:19:01
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.146.235.229 (229.235.146.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.146.235.229 (229.235.146.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 06:18:55.100022 2026] [security2:error] [pid 25277:tid 25346] [client 34.146.235.229:25644] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.arthansl.com"] [uri "/@fs/root/.env"] [unique_id "ap_hD03m3BbB4f648s6tvAAAAEU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 09:20:14
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.146.235.229 (229.235.146.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.146.235.229 (229.235.146.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 05:20:06.227995 2026] [security2:error] [pid 4988:tid 4988] [client 34.146.235.229:15492] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.privateflutelessons.ipostsocialmedia.com"] [uri "/@fs/.env"] [unique_id "ap_TRgwXTw2mUH5UaN3VSQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
masterguru
2026-09-08 08:46:10
(8 hours ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-197)
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 08:30:45
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.146.235.229 (229.235.146.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.146.235.229 (229.235.146.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 04:30:40.206058 2026] [security2:error] [pid 25706:tid 25706] [client 34.146.235.229:54514] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.microscopicpablo.robtown.com"] [uri "/@fs/.env"] [unique_id "ap_HsJONDb_BxHLv2yn6VQAAACo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
dynamix
2026-09-08 08:17:07
(9 hours ago)
Multiple WAF Violations
Web App Attack
Anonymous
2026-09-08 08:11:12
(9 hours ago)
Bot / seems abusive / Apache connections: 40
DDoS Attack
Web Spam
Bad Web Bot
Web App Attack
🇳🇱
Site.eu
2026-09-08 07:21:09
(10 hours ago)
Excessive multi-domain requests
Brute-Force
🇳🇱
Mangelot Hosting
2026-09-08 07:15:50
(10 hours ago)
(modsecurity) srv104 ModSecurity 34.146.235.229 (JP/Japan/229.235.146.34.bc.googleusercontent.com): ...
show more
(modsecurity) srv104 ModSecurity 34.146.235.229 (JP/Japan/229.235.146.34.bc.googleusercontent.com): 30 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 07:11:50
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.146.235.229 (229.235.146.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.146.235.229 (229.235.146.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 03:11:42.973403 2026] [security2:error] [pid 9983:tid 9983] [client 34.146.235.229:52412] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.drumez.com"] [uri "/@fs/app/.env"] [unique_id "ap-1LqY9IbdaTZcH-0StBQAAADo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 06:41:38
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.146.235.229 (229.235.146.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.146.235.229 (229.235.146.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 02:41:31.821716 2026] [security2:error] [pid 5285:tid 5285] [client 34.146.235.229:7196] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.krugmans.com"] [uri "/@fs/app/.env"] [unique_id "ap-uGzvsRO6VcMWmzFOzJQAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 06:25:09
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.146.235.229 (229.235.146.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.146.235.229 (229.235.146.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 02:25:01.228298 2026] [security2:error] [pid 30767:tid 30787] [client 34.146.235.229:30792] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.ep-dh.com"] [uri "/@fs/.env.local"] [unique_id "ap-qPYMiixczI30l3mTmJAAAANI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇭
zynex
2026-09-08 06:09:42
(11 hours ago)
URL Probing: /@fs/src/.env
Web App Attack
🇩🇪
Bedios GmbH
2026-09-08 05:54:20
(11 hours ago)
Login credentials theft attempt
Hacking