🇫🇷
phoenix1jl96
2026-09-05 13:30:13
(8 hours ago)
2026/09/05 15:30:12 [error] 3857369#3857369: *119999 open() "/home/user-data/www/default/mailer/.env ...
show more
2026/09/05 15:30:12 [error] 3857369#3857369: *119999 open() "/home/user-data/www/default/mailer/.env" failed (2: No such file or directory), client: 34.148.39.211, server: box.ledemon.us, request: "GET /mailer/.env HTTP/1.1", host: "d216-cloud-backup.direct.quickconnect.to"
2026/09/05 15:30:12 [error] 3857369#3857369: *119999 open() "/usr/local/lib/roundcubemail/.env" failed (2: No such file or directory), client: 34.148.39.211, server: box.ledemon.us, request: "GET /mail/.env HTTP/1.1", host: "d216-cloud-backup.direct.quickconnect.to"
...
show less
DNS Compromise
DNS Poisoning
DDoS Attack
Ping of Death
Web Spam
Email Spam
Blog Spam
Port Scan
Hacking
Brute-Force
Bad Web Bot
SSH
Web App Attack
🇺🇸
abuse-opdc
2026-09-04 20:06:16
(1 day ago)
Malicious HTTP requests matching injection/exploit signatures.
Web App Attack
Brute-Force
🇮🇹
ivanbiagi7
2026-09-04 08:22:08
(1 day ago)
Wazuh detected repeated HTTP client errors consistent with automated web probing. Wazuh rule=31151.
Web App Attack
🇧🇾
lns.bz
2026-09-04 06:09:29
(1 day ago)
.env scanning [BY]
Web App Attack
🇩🇪
Dominik Lysiak
2026-09-04 03:05:38
(1 day ago)
34.148.39.211 - - [04/Sep/2026:05:05:37 +0200] "GET /.git/config HTTP/1.1" 404 271 "-" "Mozilla/5.0 ...
show more
34.148.39.211 - - [04/Sep/2026:05:05:37 +0200] "GET /.git/config HTTP/1.1" 404 271 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.148.39.211 - - [04/Sep/2026:05:05:38 +0200] "GET /.env HTTP/1.1" 404 271 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.148.39.211 - - [04/Sep/2026:05:05:38 +0200] "GET /.env.local HTTP/1.1" 404 271 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Web App Attack
🇳🇱
homeshowdomain.nl
2026-09-03 21:59:45
(1 day ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-02.
show less
Web App Attack
SSH
Hacking
Anonymous
2026-09-03 14:11:21
(2 days ago)
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: US, Attack patterns: Word ...
show more
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: US, Attack patterns: WordPress scanning, Backup file probing, Cloud secrets probing
show less
Bad Web Bot
Web App Attack
🇦🇺
KevinNeale
2026-09-03 05:40:37
(2 days ago)
Fail2Ban recidive block for repeated malicious authentication attempts.
Brute-Force
Web App Attack
🇮🇹
ivanbiagi7
2026-09-02 19:38:53
(3 days ago)
Wazuh detected repeated HTTP client errors consistent with automated web probing. Wazuh rule=31151.
Web App Attack
🇸🇪
vaia.cloud
2026-09-02 17:50:01
(3 days ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
🇳🇱
tmiland
2026-09-02 16:36:35
(3 days ago)
(nginx_404) Dot directory Honeypot Trap 34.148.39.211 (US/United States/211.39.148.34.bc.googleuserc ...
show more
(nginx_404) Dot directory Honeypot Trap 34.148.39.211 (US/United States/211.39.148.34.bc.googleusercontent.com): 2 in the last 3600 secs; IP: 34.148.39.211; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 34.148.39.211 - - [02/Sep/2026:18:36:32 +0200] "GET /.git/config HTTP/1.1" 404 2992 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" 34.148.39.211 - - [02/Sep/2026:18:36:33 +0200] "GET /.env HTTP/1.1" 404 2992 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
show less
Brute-Force
Anonymous
2026-09-02 16:36:12
(3 days ago)
Bot / seems abusive / Apache connections: 50
DDoS Attack
Web Spam
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-02 15:45:06
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.148.39.211 (211.39.148.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.148.39.211 (211.39.148.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 11:44:59.155722 2026] [security2:error] [pid 23502:tid 23502] [client 34.148.39.211:39450] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "abundancecompany.com"] [uri "/.git/config"] [unique_id "aphEe7b8DD_YGHXuBFcnLQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
Baking333
2026-09-02 15:26:10
(3 days ago)
[redacted] 34.148.39.211 - - [02/Sep/2026:16:26:07 +0100] "GET /.git/config HTTP/1.1" 302 1564 0/436 ...
show more
[redacted] 34.148.39.211 - - [02/Sep/2026:16:26:07 +0100] "GET /.git/config HTTP/1.1" 302 1564 0/43617 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" [redacted] 34.148.39.211 - - [02/Sep/2026:16:26:08 +0100] "GET /.env HTTP/1.1" 302 1564 0/68124 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-02 14:15:39
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.148.39.211 (211.39.148.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.148.39.211 (211.39.148.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 10:15:31.586877 2026] [security2:error] [pid 31307:tid 31313] [client 34.148.39.211:42402] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "absurdotron.com"] [uri "/.git/config"] [unique_id "apgvg8TPTdezdfSzwzFTpgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack