Anonymous
2026-08-29 09:35:43
(4 minutes ago)
34.16.233.49 - - [29/Aug/2026:11:35:39 +0200] "GET / HTTP/1.1" 403 12583 "-" "Mozilla/5.0 (Macintosh ...
show more
34.16.233.49 - - [29/Aug/2026:11:35:39 +0200] "GET / HTTP/1.1" 403 12583 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Safari/537.36"
34.16.233.49 - - [29/Aug/2026:11:35:43 +0200] "GET / HTTP/1.1" 403 12583 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Safari/537.36"
34.16.233.49 - - [29/Aug/2026:11:35:43 +0200] "GET /@fs/root/.env?raw?? HTTP/1.1" 403 12583 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_0 like Mac OS X) AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexity-user) Chrome/118.0.4592.152 Mobile Safari/537.36"
34.16.233.49 - - [29/Aug/2026:11:35:43 +0200] "GET /@fs/..%252f..%252f..%252f..%252f..%252froot/.env?raw?? HTTP/1.1" 403 153 "-" "Mozilla/5.0 (X11; Linux x86_64; rv:78.2) Gecko/20100101 Firefox/78.2; compatible; Google-Extended/1.0; +http://www.google.com/bot.html"
34.16.233.49 - - [29/Aug/2026:11:35:43 +0200] "G
...
show less
Bad Web Bot
Web App Attack
π«π·
dynamix
2026-08-29 08:59:40
(40 minutes ago)
Multiple WAF Violations
Web App Attack
πΊπ¦
URAN Publishing Service
2026-08-29 08:56:57
(43 minutes ago)
[29/Aug/2026:11:56:57 +0300] -- 34.16.233.49 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET /@ ...
show more
[29/Aug/2026:11:56:57 +0300] -- 34.16.233.49 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET /@fs/root/.env?raw?? HTTP/1.1
show less
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-29 08:33:17
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.16.233.49 (49.233.16.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.16.233.49 (49.233.16.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 04:33:10.378245 2026] [security2:error] [pid 2604:tid 2604] [client 34.16.233.49:23656] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.star-discgolf.com"] [uri "/@fs/.env"] [unique_id "apKZRnthxwkZSw7x_XEo8QAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-29 07:58:22
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.16.233.49 (49.233.16.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.16.233.49 (49.233.16.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 03:58:16.923492 2026] [security2:error] [pid 14684:tid 14684] [client 34.16.233.49:35140] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.abeandmason.com"] [uri "/@fs/.env"] [unique_id "apKRGFxD86xkIRxA5lsHiQAAACo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
masterguru
2026-08-29 07:48:10
(1 hour ago)
Restricted File Access Attempt. Matched phrase "/@fs/" at REQUEST_FILENAME. (930130-193)
Hacking
Web App Attack
π«π·
masterguru
2026-08-29 07:32:00
(2 hours ago)
Restricted File Access Attempt. Matched phrase "/@fs/" at REQUEST_FILENAME. (930130-197)
Hacking
Web App Attack
πΊπΈ
WellSpring
2026-08-29 07:24:52
(2 hours ago)
env leak on 908.today/@fs/home/ubuntu/.env β WellSpr.ing/NetSentinel civic-AI security layer
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-29 07:09:44
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.16.233.49 (49.233.16.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.16.233.49 (49.233.16.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 03:09:40.141209 2026] [security2:error] [pid 9809:tid 9809] [client 34.16.233.49:31170] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.nolaanime.com"] [uri "/@fs/root/.env"] [unique_id "apKFtAQeLFnbdCS5xTrwZgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
ghostwarriors
2026-08-29 06:50:04
(2 hours ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-29 06:11:28
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.16.233.49 (49.233.16.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.16.233.49 (49.233.16.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 02:11:24.370293 2026] [security2:error] [pid 20302:tid 20302] [client 34.16.233.49:44032] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.mikebenson.com"] [uri "/@fs/root/.env"] [unique_id "apJ4DPW5x78dfo9CXx6PrQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
Roderic
2026-08-29 05:59:25
(3 hours ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted])
Bad Web Bot
πΈπ¬
Cloudkul Cloudkul
2026-08-29 05:54:26
(3 hours ago)
Attempted Brute Force on our application
Brute-Force
Web App Attack
πΊπΈ
snappic
2026-08-29 05:47:50
(3 hours ago)
Scanning for config [GET /config.json.js] [Mozilla/5.0 (Linux; Android 14; Pixel 8) AppleWebKit/537. ...
show more
Scanning for config [GET /config.json.js] [Mozilla/5.0 (Linux; Android 14; Pixel 8) AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexity-user) Chrome/131.0.3878.25 Mobile Safari/537.36]
show less
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-29 04:01:11
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.16.233.49 (49.233.16.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.16.233.49 (49.233.16.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 00:01:05.426454 2026] [security2:error] [pid 23869:tid 23869] [client 34.16.233.49:35450] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.plazahacienda.com"] [uri "/@fs/app/.env"] [unique_id "apJZgc56kypH74-TGes0WwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack