๐ฉ๐ช
FeG Deutschland
2026-06-10 12:30:41
(5 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐ฉ๐ช
DEV-DNS
2026-06-10 07:05:51
(10 hours ago)
(mod_security) mod_security triggered on hostname [redacted])
SQL Injection
๐ฉ๐ช
updown.io
2026-06-10 05:44:21
(12 hours ago)
{"level":"info","ts":1781070260.6040206,"logger":"http.log.access.log1","msg":"handled request","req ...
show more
{"level":"info","ts":1781070260.6040206,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"34.176.99.126","remote_port":"58806","client_ip":"34.176.99.126","proto":"HTTP/1.1","method":"GET","host":"nmlkjihupdate.update.yxwvutsrqpovutsrqponmlkjihgc7402a95-6fc9-4756-b4e6-fa6c7eeb29c6.random.159.89.98.98.nip.io","uri":"/.env.testing","headers":{"Accept-Encoding":["gzip"],"Connection":["close"],"User-Agent":["Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/69.0.3497.92 Safari/537.36"],"Accept-Charset":["utf-8"]}},"bytes_read":0,"user_id":"","duration":0.000077288,"size":0,"status":308,"resp_headers":{"Server":["Caddy"],"Connection":["close"],"Location":["https://nmlkjihupdate.update.yxwvutsrqpovutsrqponmlkjihgc7402a95-6fc9-4756-b4e6-fa6c7eeb29c6.random.159.89.98.98.nip.io/.env.testing"],"Content-Type":[]}}
{"level":"info","ts":1781070260.6150863,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"34
...
show less
DDoS Attack
Web App Attack
๐ฉ๐ช
webanyone
2026-06-09 23:00:27
(19 hours ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
๐ง๐ช
cmbplf
2026-06-09 21:51:02
(20 hours ago)
637 requests with url.path *.env
Brute-Force
Bad Web Bot
๐ฉ๐ช
todix
2026-06-09 09:38:23
(1 day ago)
Web App Attack Exploid from 34.176.99.126
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 06:59:11
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.176.99.126 (126.99.176.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.176.99.126 (126.99.176.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 02:59:05.515195 2026] [security2:error] [pid 16923:tid 16923] [client 34.176.99.126:35290] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.jennlaurenphotography.com"] [uri "/api/.env.production"] [unique_id "aie5uTTdhYoxGYsn-pFxjgAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 06:20:38
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.176.99.126 (126.99.176.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.176.99.126 (126.99.176.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 02:20:32.477652 2026] [security2:error] [pid 14479:tid 14479] [client 34.176.99.126:44198] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.cultureshockmedia.com"] [uri "/.env.development"] [unique_id "aiewsK9NnG8NEa-vFyAeSQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
๐จ๐ญ Hosting
2026-06-09 05:10:16
(1 day ago)
Automated WAF report: 125-150 blocked requests from this IP detected by our WAF.
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 00:25:36
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.176.99.126 (126.99.176.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.176.99.126 (126.99.176.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 20:25:29.686989 2026] [security2:error] [pid 23783:tid 23805] [client 34.176.99.126:37272] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "onenessrecords.com"] [uri "/.env.backup"] [unique_id "aiddebI1v61Wt9NDp9MW1QAAANQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-06-08 23:32:14
(1 day ago)
Excessive multi-domain requests
Brute-Force
๐ฉ๐ช
FeG Deutschland
2026-06-08 23:24:16
(1 day ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐ฉ๐ช
HoneyPotFRI
2026-06-08 23:15:23
(1 day ago)
34.176.99.126 - - [09/Jun/2026:01:15:07 +0200] "GET /.env.prod HTTP/1.1" 404 125 "-" "Mozilla/5.0 (W ...
show more
34.176.99.126 - - [09/Jun/2026:01:15:07 +0200] "GET /.env.prod HTTP/1.1" 404 125 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:6.0a2) Gecko/20110622 Firefox/6.0a2"
34.176.99.126 [redacted] (396982-GO
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-08 22:58:21
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.176.99.126 (126.99.176.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.176.99.126 (126.99.176.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 18:58:12.839329 2026] [security2:error] [pid 29731:tid 29731] [client 34.176.99.126:42596] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.utahproaudio.com"] [uri "/.env.production"] [unique_id "aidJBP3wMxpnN2iSw6sL3AAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-06-08 22:02:30
(1 day ago)
Auto-ban: >3000 req/min op 2026-06-08
Web App Attack
SSH
Hacking