🇳🇱
Alt255
2026-09-11 15:49:15
(3 days ago)
34.146.238.84 - - \[08/Sep/2026:21:31:49 +0200\] "GET /@fs/.env.local\?raw\?\? HTTP/1.1" 301 4665 "- ...
show more
34.146.238.84 - - \[08/Sep/2026:21:31:49 +0200\] "GET /@fs/.env.local\?raw\?\? HTTP/1.1" 301 4665 "-" "Mozilla/5.0 \(iPhone\; CPU iPhone OS 17_0 like Mac OS X\) AppleWebKit/537.36 \(KHTML, like Gecko\; compatible\; Claude-User/1.0\; +https://www.anthropic.com/claude-user\) Chrome/109.0.1734.135 Mobile Safari/537.36"
34.146.238.84 - - \[08/Sep/2026:21:31:49 +0200\] "GET /@fs/app/.env\?raw\?\? HTTP/1.1" 301 4661 "-" "Mozilla/5.0 \(Macintosh\; Intel Mac OS X 10_15_7\) AppleWebKit/537.36 \(KHTML, like Gecko\) Chrome/131.0.8631.193 Safari/537.36 Edg/131.0.8631.193\; compatible\; Slackbot-LinkExpanding/1.0\; +https://api.slack.com/robots"
34.146.238.84 - - \[08/Sep/2026:21:31:49 +0200\] "GET /@fs/src/.env\?raw\?\? HTTP/1.1" 301 4661 "-" "Mozilla/5.0 \(Macintosh\; Intel Mac OS X 13_6_7\) AppleWebKit/605.1.15 \(KHTML, like Gecko\; compatible\; GrokBot/1.0\; +https://x.ai/grokbot\) Version/19.2 Safar
...
show less
Bad Web Bot
Web App Attack
🇳🇱
homeshowdomain.nl
2026-09-09 22:02:59
(5 days ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-08.
show less
Web App Attack
SSH
Hacking
🇫🇷
Octopuce
2026-09-09 10:58:41
(5 days ago)
Aggressive web search of vulnerable pages: /.env /.env.local /app/.env /apps/.env /api/.env ...
Web App Attack
🇳🇱
e.fierstra
2026-09-09 09:58:00
(5 days ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇧🇪
cmbplf
2026-09-08 23:40:15
(6 days ago)
158 requests with url.path */@fs/*
Brute-Force
Bad Web Bot
🇮🇪
AutosOnShow
2026-09-08 20:19:04
(6 days ago)
blocked for webapp attack | path requested: /.env | seen at 2026-09-08 20:18:44.553 |
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 19:34:22
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 34.146.238.84 (84.238.146.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.146.238.84 (84.238.146.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 15:34:16.411494 2026] [security2:error] [pid 7307:tid 7307] [client 34.146.238.84:19624] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.digbie.com"] [uri "/@fs/root/.env"] [unique_id "aqBjOOcqLHPWsbOd15llWAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
cwytech
2026-09-08 19:27:19
(6 days ago)
Fleet-wide ban from the Ghostfleet 👻. Triggered by scenario: crowdsecurity/http-probing.
Bad Web Bot
Web App Attack
🇳🇱
Site.eu
2026-09-08 19:20:00
(6 days ago)
Excessive multi-domain requests
Brute-Force
🇩🇪
Marc
2026-09-08 19:11:40
(6 days ago)
34.146.238.84 - - [08/Sep/2026:21:11:40 +0200] "GET /@fs/src/.env?raw?? HTTP/1.1" 404 2042 "-" "Mozi ...
show more
34.146.238.84 - - [08/Sep/2026:21:11:40 +0200] "GET /@fs/src/.env?raw?? HTTP/1.1" 404 2042 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:133.5) Gecko/20100101 Firefox/133.5; compatible; meta-externalagent/1.1; +https://developers.facebook.com/docs/sharing/webmasters/crawler" 34.146.238.84 - - [08/Sep/2026:21:11:40 +0200] "GET /@fs/root/.env?raw?? HTTP/1.1" 404 2042 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Bytespider; +https://zhanzhang.toutiao.com/)" 34.146.238.84 - - [08/Sep/2026:21:11:40 +0200] "GET /@fs/app/.env?raw?? HTTP/1.1" 404 2042 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14_6_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.1937.247 Safari/537.36 Edg/120.0.1937.247; compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot"
show less
Brute-Force
🇩🇪
LRob
2026-09-08 18:31:28
(6 days ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /@fs/.env (+11 more) | 2026-09-08 18:31 UTC
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 18:26:53
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 34.146.238.84 (84.238.146.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.146.238.84 (84.238.146.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 14:26:45.461171 2026] [security2:error] [pid 4032019:tid 4032019] [client 34.146.238.84:21400] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.bogans.net"] [uri "/@fs/../.env"] [unique_id "aqBTZactdYc2_NG6sos3AAAAADE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇷🇴
iulianh
2026-09-08 17:30:15
(6 days ago)
80,443
Brute-Force
SSH
🇺🇸
TPI-Abuse
2026-09-08 17:23:05
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 34.146.238.84 (84.238.146.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.146.238.84 (84.238.146.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 13:22:57.881261 2026] [security2:error] [pid 30349:tid 30349] [client 34.146.238.84:23682] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.jdubindustries.jonathanwilson.me"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252fapp/.env"] [unique_id "aqBEceT7jB0H1wKmoHdRjwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇭🇺
Adorjan Daczo
2026-09-08 17:11:53
(6 days ago)
Probe for vulnerabilities. Path attempted: /@fs/.env.local
Web App Attack