🇮🇳
evicky2002
2026-09-09 00:01:20
(58 minutes ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
🇺🇸
TPI-Abuse
2026-09-08 13:16:42
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.186.7.228 (228.7.186.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.186.7.228 (228.7.186.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 09:16:38.022859 2026] [security2:error] [pid 21536:tid 21536] [client 34.186.7.228:1682] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.bhartman.com"] [uri "/@fs/.env"] [unique_id "aqAKtgT33UndjfbLUlfwqAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 13:00:20
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.186.7.228 (228.7.186.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.186.7.228 (228.7.186.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 09:00:15.688335 2026] [security2:error] [pid 32514:tid 32514] [client 34.186.7.228:33674] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.paintriver.com"] [uri "/@fs/root/.env"] [unique_id "aqAG3_MVXUf7okqV2Hl-uAAAADQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
WellSpring
2026-09-08 12:57:08
(12 hours ago)
env leak on 562.today/@fs/usr/src/app/.env — WellSpr.ing/NetSentinel civic-AI security layer
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 12:37:43
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.186.7.228 (228.7.186.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.186.7.228 (228.7.186.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 08:37:36.606080 2026] [security2:error] [pid 25553:tid 25553] [client 34.186.7.228:10054] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.lundtrading.com"] [uri "/@fs/.env"] [unique_id "aqABkPbsMKHWghQDolaF3gAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 12:02:37
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.186.7.228 (228.7.186.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.186.7.228 (228.7.186.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 08:02:31.696674 2026] [security2:error] [pid 6769:tid 6769] [client 34.186.7.228:48152] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.greed.ee"] [uri "/@fs/.env"] [unique_id "ap_5V8404BKHVo3BgqKbVgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-08 10:40:12
(14 hours ago)
Bot / seems abusive / Apache connections: 106
DDoS Attack
Web Spam
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 09:23:19
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.186.7.228 (228.7.186.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.186.7.228 (228.7.186.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 05:23:13.144937 2026] [security2:error] [pid 18413:tid 18413] [client 34.186.7.228:17082] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.bhsp.org"] [uri "/@fs/.env"] [unique_id "ap_UAfWdAHyuwTATaN8lzwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
snappic
2026-09-08 09:06:20
(15 hours ago)
Scanning for config [GET /config.json.js] [Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compat ...
show more
Scanning for config [GET /config.json.js] [Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-SearchBot/1.0; +https://www.anthropic.com/claude-searchbot)]
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 08:51:06
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.186.7.228 (228.7.186.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.186.7.228 (228.7.186.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 04:50:58.422593 2026] [security2:error] [pid 23001:tid 23001] [client 34.186.7.228:33786] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.khtcpl.com"] [uri "/@fs/src/.env"] [unique_id "ap_MciFPeEbM7KjeUUmucAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
netclix.gr
2026-09-08 08:38:37
(16 hours ago)
(security_scan) Sensitive File Scan Blocked 34.186.7.228 (US/United States/228.7.186.34.bc.googleuse ...
show more
(security_scan) Sensitive File Scan Blocked 34.186.7.228 (US/United States/228.7.186.34.bc.googleusercontent.com): 1 in the last 4600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 34.186.7.228 - - [08/Sep/2026:11:37:00 +0300] "GET /@fs/../../.env?raw?? HTTP/1.1" 400 150 "-" "-"
show less
Port Scan
🇳🇱
e.fierstra
2026-09-08 07:47:18
(17 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇩🇪
updown.io
2026-09-08 07:31:53
(17 hours ago)
{"level":"info","ts":1788852683.0481915,"logger":"http.log.access.log0","msg":"handled request","req ...
show more
{"level":"info","ts":1788852683.0481915,"logger":"http.log.access.log0","msg":"handled request","request":{"remote_ip":"34.186.7.228","remote_port":"63416","client_ip":"34.186.7.228","proto":"HTTP/1.1","method":"GET","host":"m5gh.status.updown.io","uri":"/","headers":{"Accept":["*/*"],"Accept-Encoding":["gzip"],"User-Agent":["Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:127.0) Gecko/20100101 Firefox/127.0"]}},"bytes_read":0,"user_id":"","duration":0.000069231,"size":0,"status":308,"resp_headers":{"Content-Type":[],"Server":["Caddy"],"Connection":["close"],"Location":["https://m5gh.status.updown.io/"]}}
{"level":"info","ts":1788852687.8528135,"logger":"http.log.access.log0","msg":"handled request","request":{"remote_ip":"34.186.7.228","remote_port":"10776","client_ip":"34.186.7.228","proto":"HTTP/1.1","method":"GET","host":"m5gh.status.updown.io","uri":"/@fs/.env.local?raw??","headers":{"User-Agent":["Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; LinkedInBot/1.0; +http:
...
show less
DDoS Attack
Web App Attack
🇮🇩
Burayot
2026-09-08 07:15:45
(17 hours ago)
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 34.186.7.228 (US/United States/228.7 ...
show more
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 34.186.7.228 (US/United States/228.7.186.34.bc.googleusercontent.com): 1 in the last 3600 secs
show less
Web App Attack
🇵🇱
Budyn
2026-09-08 06:55:18
(18 hours ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: i.budyn.ovh | URI: /.env?raw?? | UA: Mozilla/5.0 (Linux; Android 13; Pixel 7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.8546.191 Mobile Safari/537.36; compatible; Twitterbot/1.0 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack