{"level":"info","ts":1781512451.2514458,"logger":"http.log.access.log1","msg":"handled request","req ...
show more{"level":"info","ts":1781512451.2514458,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"34.150.230.94","remote_port":"58310","client_ip":"34.150.230.94","proto":"HTTP/1.1","method":"GET","host":"up2.weweb.win","uri":"/.env.qa","headers":{"Connection":["close"],"User-Agent":["Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_6) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/11.1.2 Safari/605.1.15"],"Accept-Charset":["utf-8"],"Accept-Encoding":["gzip"]},"tls":{"resumed":false,"version":772,"cipher_suite":4865,"proto":"","server_name":"up2.weweb.win","ech":false}},"bytes_read":0,"user_id":"","duration":0.000553846,"size":0,"status":429,"resp_headers":{"Server":["Caddy"],"Alt-Svc":["h3=\":443\"; ma=2592000"],"Retry-After":["1"]}}
{"level":"info","ts":1781512451.2570105,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"34.150.230.94","remote_port":"58306","client_ip":"34.150.230.94","proto":"HTTP/1.1","method":"GET","host":"up2.wewe
...
show less
Aggressive web search of vulnerable pages: /.env.local /src/.env /backend/api/.env /src/api/.env /fr ...
show moreAggressive web search of vulnerable pages: /.env.local /src/.env /backend/api/.env /src/api/.env /frontend/.env ...
show less
http-probing - IP: 34.150.230.94 - time="2026-06-15T00:47:04+02:00" level=info msg="(555f66b4f6a745 ...
show morehttp-probing - IP: 34.150.230.94 - time="2026-06-15T00:47:04+02:00" level=info msg="(555f66b4f6a74558bc11e3f93469658es8App0Mcc0TKEeje/crowdsec) crowdsecurity/http-probing by ip 34.150.230.94 (US/396982) : 4h ban on Ip 34.150.230.94" module=db
show less
[SunJun1404:14:12.9900912026][security2:error][pid2004023:tid2004069][client34.150.230.94:0]ModSecur ...
show more[SunJun1404:14:12.9900912026][security2:error][pid2004023:tid2004069][client34.150.230.94:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"[a-z0-9]~\$\"atREQUEST_FILENAME.[file\"/etc/apache2/conf.d/modsec_rules/10_asl_rules.conf\"][line\"1158\"][id\"390581\"][rev\"1\"][msg\"Atomicorp.comWAFRules:AttackBlocked-DataLeakage-attempttoaccessbackupfile\(disablethisruleifyourequireaccesstofilesthatendwithatilde\)\"][severity\"CRITICAL\"][hostname\"schneider-tools.ch.136-243-54-122.cpanel.site\"][uri\"/.env~\"][unique_id\"ai4OdCAeCkOshFcnS-dxrgAAAEI\"]
show less
Port Scan
Brute-Force
Web App Attack
Showing 1 to
15
of 17 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ