๐ณ๐ฑ
Site.eu
2026-08-30 23:06:38
(1 day ago)
Excessive multi-domain requests
Brute-Force
๐ณ๐ฑ
homeshowdomain.nl
2026-08-29 21:59:53
(2 days ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-08-28.
show less
Web App Attack
SSH
Hacking
๐ณ๐ฑ
Site.eu
2026-08-29 14:36:40
(2 days ago)
Excessive multi-domain requests
Brute-Force
Anonymous
2026-08-28 13:13:59
(3 days ago)
34.187.104.193 - - [28/Aug/2026:08:12:29 -0500] "GET /.env.development HTTP/1.1" 403 199 "https://nr ...
show more
34.187.104.193 - - [28/Aug/2026:08:12:29 -0500] "GET /.env.development HTTP/1.1" 403 199 "https://nrgco.com/.env.development" "Mozilla/5.0 (compatible; Claude-User/1.0; +https://www.anthropic.com/claude-user)" 172.70.46.89
34.187.104.193 - - [28/Aug/2026:08:12:29 -0500] "GET /.env.example HTTP/1.1" 403 199 "https://nrgco.com/.env.example" "Mozilla/5.0 (compatible; TelegramBot/1.0)" 104.23.170.194
34.187.104.193 - - [28/Aug/2026:08:12:29 -0500] "GET /.env.staging HTTP/1.1" 403 199 "https://nrgco.com/.env.staging" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14_5) AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; +https://www.anthropic.com/claude-user) Chrome/91.0.6339.72 Safari/537.36" 104.23.172.57
34.187.104.193 - - [28/Aug/2026:08:12:29 -0500] "GET /.env.production HTTP/1.1" 403 199 "https://nrgco.com/.env.production" "Mozilla/5.0 (Windows NT 10.0; rv:128.12) Gecko/20100101 Firefox/128.12; compatible; facebookexternalhit/1.1; +http://www.facebook.com/externalhit_uatext.p
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
rubixstudios
2026-08-28 13:09:02
(3 days ago)
Excessive HTTP requests consistent with automated attack behaviour detected by Imunify360
DDoS Attack
Brute-Force
Web App Attack
๐ฌ๐ง
consul.to
2026-08-28 13:01:04
(3 days ago)
Web attack/malicious scanning detected
Web App Attack
๐ฌ๐ง
thetomtaylor.co.uk
2026-08-28 12:08:00
(3 days ago)
Fail2Ban - [WAF]ModSecurity OWASP CRS rule violation on nginx-modsecurity ... [ice01,ice02,wa02]
Hacking
SQL Injection
Web App Attack
๐ซ๐ฎ
mnazibo
2026-08-28 10:45:19
(3 days ago)
Date: Aug 28 13:12:13 2026 EAT | Reported IP: 34.187.104.193 mod_security | id: 920440 930100 930110 ...
show more
Date: Aug 28 13:12:13 2026 EAT | Reported IP: 34.187.104.193 mod_security | id: 920440 930100 930110 930130 949110 930140 920500 | NL/usernameab.my_domain/- | Connections: 1 | Blocked: Permanent Block: [LF_MODSEC] | Logs: ; URL file extension is restricted by policy; URL file extension is restricted by policy; Path Traversal Attack (/../) or (/.../); Path Traversal Attack (/../) or (/.../); Path Traversal Attack (/../) or (/.../); Path Traversal Attack (/../) or (/.../); Path Traversal Attack (/../) or (/.../); Restricted File Access Attempt; Restricted File Access Attempt; Restricted File Access Attempt; Restricted File Access Attempt; Restricted File Access Attempt; Restricted File Access Attempt; Restricted File Access Attempt; Restricted File Access Attempt; Restricted File Access Attempt; Restricted File Access Attempt; Restricted File Access Attempt; Restricted File Access Attempt; Restricted File Access Attempt; Restricted File A
show less
SQL Injection
Brute-Force
Bad Web Bot
๐ฆ๐บ
neilwal
2026-08-28 09:23:54
(3 days ago)
Web Probe (443): teamhummingbird.neilwallace.au:443 34.187.104.193 - - [28/Aug/2026:19:23:53 +1000] ...
show more
Web Probe (443): teamhummingbird.neilwallace.au:443 34.187.104.193 - - [28/Aug/2026:19:23:53 +1000] "GET /@fs/root/.env?raw?? HTTP/1.1" 401 1062 "-" "Mozilla/5.0 (Windows NT 11.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/130.0.1952.84 Safari/537.36; compatible; OAI-SearchBot/1.3; +https://openai.com/searchbot"
teamhummingbird.neilwallace.au:443 34.187.104.193 - - [28/Aug/2026:19:23:53 +1000] "GET /@fs/..%252f..%252f..%252f..%252f..%252fapp/.env?raw?? HTTP/1.1" 401 1062 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; Applebot/0.1; +http://www.apple.com/go/applebot"
teamhummingbird.neilwallace.au:443 34.187.104.193 - - [28/Aug/2026:19:23:53 +1000] "GET /@fs/../.env?raw?? HTTP/1.1" 401 1062 "-" "Mozilla/5.0 (Linux; Android 12; Pixel 6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.1929.1 Mobile Safari/537.36; compatible; ChatGPT-User/1.0; +https://openai.com/bot"
show less
Web App Attack
Anonymous
2026-08-28 09:19:08
(3 days ago)
Web scanner: GET /@fs/../.env?raw??
Web App Attack
Hacking
๐ณ๐ฑ
Mangelot Hosting
2026-08-28 07:38:44
(3 days ago)
(modsecurity) srv102 ModSecurity 34.187.104.193 (NL/The Netherlands/193.104.187.34.bc.googleusercont ...
show more
(modsecurity) srv102 ModSecurity 34.187.104.193 (NL/The Netherlands/193.104.187.34.bc.googleusercontent.com): 30 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
Anonymous
2026-08-28 07:13:18
(3 days ago)
[da.kdns.gr] httpd-config-scan: sites=www.galanistherm.gr; logs=/var/log/httpd/domains/galanistherm. ...
show more
[da.kdns.gr] httpd-config-scan: sites=www.galanistherm.gr; logs=/var/log/httpd/domains/galanistherm.gr.log; samples=/@fs/app/.env?raw?? | /@fs/..%252f..%252f..%252f..%252f..%252fproc/self/environ?raw?? | /@fs/root/.env?raw??
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 06:57:43
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.187.104.193 (193.104.187.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.187.104.193 (193.104.187.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 02:57:39.009592 2026] [security2:error] [pid 12783:tid 12783] [client 34.187.104.193:38036] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.blalock.us"] [uri "/@fs/root/.env"] [unique_id "apExYwdSGWLxrFmLmcmPewAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-28 06:42:16
(3 days ago)
Bot / seems abusive / Apache connections: 45
DDoS Attack
Web Spam
Bad Web Bot
Web App Attack
๐ซ๐ท
phoenix1jl96
2026-08-28 06:25:10
(3 days ago)
2026/08/28 08:25:09 [error] 993341#993341: *364891 open() "/usr/local/lib/roundcubemail/.env" failed ...
show more
2026/08/28 08:25:09 [error] 993341#993341: *364891 open() "/usr/local/lib/roundcubemail/.env" failed (2: No such file or directory), client: 34.187.104.193, server: box.ledemon.us, request: "GET /mail/.env HTTP/1.1", host: "ledemon.us"
2026/08/28 08:25:09 [error] 993341#993341: *364920 open() "/home/user-data/www/default/cgi-bin/test" failed (2: No such file or directory), client: 34.187.104.193, server: box.ledemon.us, request: "GET /cgi-bin/test?cmd=%3B+echo+GSCAN_CMDI+%23 HTTP/1.1", host: "ledemon.us"
...
show less
DNS Compromise
DNS Poisoning
DDoS Attack
Ping of Death
Web Spam
Email Spam
Blog Spam
Port Scan
Hacking
Brute-Force
Bad Web Bot
SSH
Web App Attack