🇫🇷
masterguru
2026-08-28 13:34:13
(5 days ago)
(modsec_5015) ModSec 5015: Suspicious User-Agent from 34.180.118.251 (JP/Japan/251.118.180.34.bc.goo ...
show more
(modsec_5015) ModSec 5015: Suspicious User-Agent from 34.180.118.251 (JP/Japan/251.118.180.34.bc.googleusercontent.com): 1 in the last 3600 secs (0-195)
show less
Hacking
🇺🇸
Charlesiv
2026-08-28 12:07:51
(5 days ago)
Triggered Cloudflare WAF (firewallCustom) from JP.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Prot ...
show more
Triggered Cloudflare WAF (firewallCustom) from JP.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Protocol: HTTP/1.1 (GET method)
Endpoint: /@fs/..%252f..%252f..%252f..%252f..%252froot/.env
Query: ?raw??
Timestamp: 2026-08-28T12:07:12Z
Ray ID: a32331bdcf5de399
UA: Mozilla/5.0 (Windows NT 11.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko; compatible; GrokBot/1.0; +https://x.ai/grokbot) Chrome/114.0.4230.31 Safari/537.36 Edg/114.0.4230.31
show less
Bad Web Bot
🇪🇸
alferez
2026-08-28 10:43:11
(5 days ago)
Searching .(env|sql|zip|tar|rar) files
Hacking
Exploited Host
Web App Attack
🇺🇸
WellSpring
2026-08-28 09:09:34
(5 days ago)
env leak on 940.today/@fs/home/ubuntu/.env — WellSpr.ing/NetSentinel civic-AI security layer
Web App Attack
🇫🇷
Baking333
2026-08-28 08:41:12
(5 days ago)
[redacted] 34.180.118.251 - - [28/Aug/2026:09:41:11 +0100] "GET /@fs/home/debian/.aws/credentials?ra ...
show more
[redacted] 34.180.118.251 - - [28/Aug/2026:09:41:11 +0100] "GET /@fs/home/debian/.aws/credentials?raw?? HTTP/1.1" 302 6768 0/82630 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14_6_1) AppleWebKit/537.36 (KHTML, like Gecko; compatible; GrokBot/1.0; +https://[redacted]/grokbot) Chrome/85.0.8599.181 Safari/537.36" [redacted] 34.180.118.251 - - [28/Aug/2026:09:41:11 +0100] "GET /@fs/var/www/.aws/credentials?raw?? HTTP/1.1" 302 6768 0/167576 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; PerplexityBot/1.0; +https://[redacted]/perplexitybot)"
show less
Bad Web Bot
Web App Attack
🇫🇷
Octopuce
2026-08-28 07:20:02
(5 days ago)
Aggressive web search of vulnerable pages: /v2/.env /assets../.env /config/.env /laravel/.env /uploa ...
show more
Aggressive web search of vulnerable pages: /v2/.env /assets../.env /config/.env /laravel/.env /uploads../.env ...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-08-28 06:51:52
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 34.180.118.251 (251.118.180.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.180.118.251 (251.118.180.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 02:51:46.014506 2026] [security2:error] [pid 31964:tid 31964] [client 34.180.118.251:57336] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.isjustanasshole.com"] [uri "/@fs/root/.env"] [unique_id "apEwArMqQbiSx0WxeXR_vAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Savvii
2026-08-28 06:32:43
(5 days ago)
20 attempts against mh-misbehave-ban on joost-st
Brute-Force
Bad Web Bot
Web App Attack
🇦🇺
A.i.D.A.N.N
2026-08-28 06:09:07
(5 days ago)
A.i.D.A.N.N: Anomaly Detected - Signature match Web Service - Web application attack detected
Web App Attack
🇺🇸
TPI-Abuse
2026-08-28 06:02:35
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 34.180.118.251 (251.118.180.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.180.118.251 (251.118.180.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 02:02:31.154227 2026] [security2:error] [pid 3637:tid 3637] [client 34.180.118.251:34936] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.smart1services.com"] [uri "/@fs/.env"] [unique_id "apEkdzTSOXTBF8CzLdOwPgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-28 05:39:48
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 34.180.118.251 (251.118.180.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.180.118.251 (251.118.180.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 01:39:43.260436 2026] [security2:error] [pid 25223:tid 25223] [client 34.180.118.251:41468] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.rockymtnfire.com"] [uri "/@fs/.env"] [unique_id "apEfH1lnf-irRUrfgWH9hQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-28 05:12:27
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 34.180.118.251 (251.118.180.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.180.118.251 (251.118.180.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 01:12:21.271025 2026] [security2:error] [pid 19454:tid 19454] [client 34.180.118.251:42904] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.davidharrisgriffith.com"] [uri "/@fs/.env"] [unique_id "apEYtZB0Mq5wbHkoOM_LKQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-28 04:45:53
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 34.180.118.251 (251.118.180.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.180.118.251 (251.118.180.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 00:45:39.947022 2026] [security2:error] [pid 26209:tid 26209] [client 34.180.118.251:49384] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.boblog111.com"] [uri "/@fs/root/.env"] [unique_id "apESc8Awm3gQW3CQS2rPvAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Site.eu
2026-08-28 04:25:35
(5 days ago)
Excessive multi-domain requests
Brute-Force
🇩🇪
Bedios GmbH
2026-08-28 04:14:55
(5 days ago)
Login credentials theft attempt
Hacking