🇩🇪
findlab
2026-09-04 18:00:02
(1 hour ago)
Backdrop CMS module - malicious activity detected
Bad Web Bot
Web App Attack
🇮🇹
ciccio diddo
2026-09-04 16:45:39
(3 hours ago)
High Burst multiple 40X port:Tcp/80,443
Brute-Force
Web App Attack
🇳🇱
ConsulHosting
2026-09-04 15:35:30
(4 hours ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack
🇨🇿
sajmon0011
2026-09-04 15:23:19
(4 hours ago)
34.168.64.159 - - [04/Sep/2026:17:23:18 +0200] "GET /@fs/app/.env?raw?? HTTP/1.1" 404 196 "-" "Mozil ...
show more
34.168.64.159 - - [04/Sep/2026:17:23:18 +0200] "GET /@fs/app/.env?raw?? HTTP/1.1" 404 196 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko; compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot) Chrome/147.0.7439.246 Safari/537.36"
...
show less
Web App Attack
🇸🇪
vaia.cloud
2026-09-04 14:30:04
(5 hours ago)
crowdsecurity/http-path-traversal-probing
Brute-Force
Web App Attack
🇩🇪
Petros Stefanakis
2026-09-04 14:14:19
(5 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 34.168.64.159 (US/United States/159.64. ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.168.64.159 (US/United States/159.64.168.34.bc.googleusercontent.com)
show less
SQL Injection
🇩🇪
maxpower
2026-09-04 13:45:12
(6 hours ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 34.168.64.159 (US/United States/159.64.1 ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 34.168.64.159 (US/United States/159.64.168.34.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 34.168.64.159 - - [04/Sep/2026:15:45:11 +0200] "GET /@fs/root/.aws/credentials.bak?raw?? HTTP/1.1" 200 12087 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko; compatible; GrokBot/1.0; +https://x.ai/grokbot) Chrome/120.0.5898.16 Safari/537.36" "-" host=gestionale.mediaqualitylab.com
show less
Port Scan
🇺🇸
TPI-Abuse
2026-09-04 12:22:19
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.168.64.159 (159.64.168.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.168.64.159 (159.64.168.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 08:22:12.429650 2026] [security2:error] [pid 24265:tid 24265] [client 34.168.64.159:30120] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.starthreadingsalon.com"] [uri "/@fs/root/.env"] [unique_id "apq39E6wLNeFatZ7PaSY4QAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 10:26:23
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.168.64.159 (159.64.168.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.168.64.159 (159.64.168.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:26:14.772692 2026] [security2:error] [pid 23003:tid 23051] [client 34.168.64.159:37490] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lagifthouse.com"] [uri "/@fs/.env.staging"] [unique_id "apqcxiex7aGucYgIv8Y7QQAAAEo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 09:41:28
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.168.64.159 (159.64.168.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.168.64.159 (159.64.168.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 05:41:20.758359 2026] [security2:error] [pid 18034:tid 18034] [client 34.168.64.159:30510] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mskimberleesspace.com"] [uri "/@fs/root/.env"] [unique_id "apqSQOQAiqOnOkzsLdxEiwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 08:56:32
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.168.64.159 (159.64.168.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.168.64.159 (159.64.168.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 04:56:26.306110 2026] [security2:error] [pid 22610:tid 22610] [client 34.168.64.159:35878] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.rcjav.com.lordhari.com"] [uri "/@fs/app/.env"] [unique_id "apqHugvMzh-awevCff5QiwAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Vegascosmetics
2026-09-04 07:51:35
(12 hours ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after sensitive config/credentials exposure ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after sensitive config/credentials exposure probe. Evidence: AttackPattern: /\.env (Match: /.env)
show less
Hacking
Brute-Force
Web App Attack
🇬🇧
Bytemark
2026-09-04 07:13:09
(12 hours ago)
34.168.64.159 - - [04/Sep/2026:08:13:08 +0100] "GET /@fs/etc/apache2/apache2.conf?raw?? HTTP/1.1" 30 ...
show more
34.168.64.159 - - [04/Sep/2026:08:13:08 +0100] "GET /@fs/etc/apache2/apache2.conf?raw?? HTTP/1.1" 301 905 "https://distancelearningcentre.org.uk/@fs/etc/apache2/apache2.conf?raw??" "Mozilla/5.0 (compatible; Applebot/0.1; +http://www.apple.com/go/applebot)"
show less
Brute-Force
Web App Attack
🇳🇱
Site.eu
2026-09-04 06:59:12
(12 hours ago)
Excessive multi-domain requests
Brute-Force
🇩🇪
tentwentyfour
2026-09-04 06:56:09
(13 hours ago)
Blocked for probing for sensitive web application components
Brute-Force
Web App Attack