๐ง๐ช
boxed-it
2026-09-17 19:42:36
(2 weeks ago)
GET /.env (Tarpitted for 1d15h8m28s, wasted 8.06MB)
Web App Attack
๐ง๐ช
boxed-it
2026-09-17 14:09:37
(2 weeks ago)
GET /@fs/../.env?raw?? (Tarpitted for 1d15h8m27s, wasted 8.06MB)
Web App Attack
๐บ๐ธ
ShadowWhisperer
2026-09-16 02:08:12
(2 weeks ago)
HTTPS GET /.env.local UA: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; C
Web App Attack
๐ซ๐ฎ
Erpelstolz
2026-09-15 20:37:06
(2 weeks ago)
external host: 34.16.204.222 - - [15/Sep/2026:22:37:06 +0200] "GET /assets../../../etc/passwd HTTP/1 ...
show more
external host: 34.16.204.222 - - [15/Sep/2026:22:37:06 +0200] "GET /assets../../../etc/passwd HTTP/1.1" 400 5433 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; TelegramBot/1.0)" CF-Ray:- CF-IP:-
show less
Web App Attack
๐ธ๐ช
KIDOS
2026-09-15 19:16:54
(2 weeks ago)
malicious activity
Web App Attack
๐ฎ๐น
[email protected]
2026-09-15 16:49:14
(2 weeks ago)
34.16.204.222 - - [15/Sep/2026:18:44:45 +0200] "GET /@fs/root/.aws/credentials?raw?? HTTP/1.1" 404 2 ...
show more
34.16.204.222 - - [15/Sep/2026:18:44:45 +0200] "GET /@fs/root/.aws/credentials?raw?? HTTP/1.1" 404 2006 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 15_0) AppleWebKit/605.1.15 (KHTML, like Gecko; compatible; Claude-SearchBot/1.0; +https://www.anthropic.com/claude-searchbot) Version/17.2 Safari/605.1.15"
show less
Web App Attack
Hacking
๐บ๐ธ
JCB
2026-09-15 16:01:00
(2 weeks ago)
34.16.204.222 - - [15/Sep/2026:02:28:14 +0300] "GET /serverless.yml.save HTTP/1.1" 404 236 "-" "Mozi ...
show more
34.16.204.222 - - [15/Sep/2026:02:28:14 +0300] "GET /serverless.yml.save HTTP/1.1" 404 236 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; LinkedInBot/1.0; +http://www.linkedin.com"
34.16.204.222 - - [15/Sep/2026:02:28:14 +0300] "GET /serverless.yml.backup HTTP/1.1" 404 236 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot)"
...
show less
Web App Attack
๐ง๐พ
lns.bz
2026-09-15 08:41:07
(2 weeks ago)
.env scanning [BY]
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 06:04:50
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.16.204.222 (222.204.16.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.16.204.222 (222.204.16.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 02:04:45.429671 2026] [security2:error] [pid 13883:tid 13910] [client 34.16.204.222:43602] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.134"] [uri "/static../.env"] [unique_id "aqjf_er-8J2YoN-_cEQfYQAAAEs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-15 02:54:06
(2 weeks ago)
Port Scan
Port Scan
๐ธ๐ช
nekopavel
2026-09-15 02:05:44
(2 weeks ago)
34.16.204.222 - - [15/Sep/2026:04:05:42 +0200]"GET /.env HTTP/1.1" 404 804"-" 78.69.8.25 "Mozilla/5. ...
show more
34.16.204.222 - - [15/Sep/2026:04:05:42 +0200]"GET /.env HTTP/1.1" 404 804"-" 78.69.8.25 "Mozilla/5.0 (compatible; Google-Extended/1.0; +http://www.google.com/bot.html)""0.000" "-""Las Vegas" "US"
34.16.204.222 - - [15/Sep/2026:04:05:42 +0200]"GET /.env.local HTTP/1.1" 444 0"-" 78.69.8.25 "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; OAI-SearchBot/1.4; robots.txt; +https://openai.com/searchbot)""0.000" "-""Las Vegas" "US"
34.16.204.222 - - [15/Sep/2026:04:05:42 +0200]"GET /@fs/../.env?raw?? HTTP/1.1" 444 0"-" 78.69.8.25 "Mozilla/5.0 (Macintosh; Intel Mac OS X 14_6_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.8080.28 Safari/537.36; compatible; OAI-SearchBot/1.3; +https://openai.com/searchbot""0.000" "-""Las Vegas" "US"
...
show less
Hacking
Bad Web Bot
Web App Attack
Anonymous
2026-09-15 01:59:39
(2 weeks ago)
Aggressive web scan
Web App Attack
Anonymous
2026-09-15 00:40:41
(2 weeks ago)
| A web attack returned code 200 (success).
Web App Attack
Hacking
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-09-14 18:06:55
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.16.204.222 (222.204.16.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.16.204.222 (222.204.16.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 14:06:48.087935 2026] [security2:error] [pid 20796:tid 20796] [client 34.16.204.222:39062] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.60"] [uri "/static../.env"] [unique_id "aqg3uIUKoabdllJKmcHKOAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack