🇫🇷
masterguru
2026-09-14 17:01:46
(10 hours ago)
OS File Access Attempt. Matched phrase "proc/self/environ" at ARGS:0. (930120-131)
Hacking
🇫🇷
guillaume illien
2026-09-14 16:28:25
(10 hours ago)
34.187.157.191 - - [14/Sep/2026:16:28:22 +0000] "GET /api/uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e% ...
show more
34.187.157.191 - - [14/Sep/2026:16:28:22 +0000] "GET /api/uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2fproc/self/environ HTTP/1.1" 400 166 "-" "-"
34.187.157.191 - - [14/Sep/2026:16:28:22 +0000] "GET /public/plugins/alertlist/../../../../../../../../proc/self/environ HTTP/1.1" 400 166 "-" "-"
34.187.157.191 - - [14/Sep/2026:16:28:22 +0000] "GET /uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f.env HTTP/1.1" 400 166 "-" "-"
34.187.157.191 - - [14/Sep/2026:16:28:22 +0000] "GET /api/uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f.env HTTP/1.1" 400 166 "-" "-"
34.187.157.191 - - [14/Sep/2026:16:28:22 +0000] "GET /icons/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/proc/self/environ HTTP/1.1" 400 166 "-" "-"
34.187.157.191 - - [14/Sep/2026:16:28:25 +0000] "GET /public/plugins/grafana-clock-panel/../../../../../../../../proc/self/environ HTTP/1.1" 400 166 "-" "-"
34.187.157.191 - - [14/Sep/2026:16:28:25 +0000] "GET /public/plugins/text/../../../../../../../../proc/self/environ HTTP/1.1" 400 166 "-" "-"
...
show less
Hacking
Brute-Force
Web App Attack
SSH
Anonymous
2026-09-14 12:01:57
(15 hours ago)
Attempted known web exploits
Brute-Force
Web App Attack
🇮🇹
VHosting
2026-09-14 10:00:05
(17 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇮🇳
evicky2002
2026-09-14 06:00:01
(21 hours ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
🇳🇱
oisecnet
2026-09-13 21:02:35
(1 day ago)
Automated report: Unauthorized vulnerability scanning detected on 2026-09-13. 842 requests from this ...
show more
Automated report: Unauthorized vulnerability scanning detected on 2026-09-13. 842 requests from this IP.
show less
Port Scan
Hacking
Web App Attack
🇫🇷
guillaume illien
2026-09-13 18:13:24
(1 day ago)
34.187.157.191 - - [13/Sep/2026:18:13:22 +0000] "GET /public/plugins/grafana-clock-panel/../../../.. ...
show more
34.187.157.191 - - [13/Sep/2026:18:13:22 +0000] "GET /public/plugins/grafana-clock-panel/../../../../../../../../proc/self/environ HTTP/1.1" 400 166 "-" "-"
34.187.157.191 - - [13/Sep/2026:18:13:22 +0000] "GET /public/plugins/text/../../../../../../../../proc/self/environ HTTP/1.1" 400 166 "-" "-"
34.187.157.191 - - [13/Sep/2026:18:13:23 +0000] "GET /..%2f.env HTTP/1.1" 400 166 "-" "-"
34.187.157.191 - - [13/Sep/2026:18:13:23 +0000] "GET /public/plugins/alertlist/../../../../../../../../proc/self/environ HTTP/1.1" 400 166 "-" "-"
34.187.157.191 - - [13/Sep/2026:18:13:23 +0000] "GET /%2e%2e/.env HTTP/1.1" 400 166 "-" "-"
34.187.157.191 - - [13/Sep/2026:18:13:23 +0000] "GET /api/uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2fproc/self/environ HTTP/1.1" 400 166 "-" "-"
34.187.157.191 - - [13/Sep/2026:18:13:23 +0000] "GET /..%2f..%2f.env HTTP/1.1" 400 166 "-" "-"
...
show less
Hacking
Brute-Force
Web App Attack
SSH
🇬🇧
noise.agency
2026-09-13 14:22:24
(1 day ago)
34.187.157.191 (US/United States/191.157.187.34.bc.googleusercontent.com), more than 10 Apache 403 h ...
show more
34.187.157.191 (US/United States/191.157.187.34.bc.googleusercontent.com), more than 10 Apache 403 hits
show less
Hacking
🇩🇪
raph
2026-09-13 14:05:30
(1 day ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-13 13:37:34
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.187.157.191 (191.157.187.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.187.157.191 (191.157.187.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 09:37:28.075512 2026] [security2:error] [pid 19084:tid 19084] [client 34.187.157.191:37802] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "zmgmt.net"] [uri "/.git/config"] [unique_id "aqanGNRVwv6htSMFAY79XgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
BlueWire Hosting
2026-09-13 13:10:45
(1 day ago)
High-confidence malicious configuration/VCS probe
Web App Attack
🇮🇹
mgarofano80
2026-09-13 12:49:29
(1 day ago)
Brute-Force
Web App Attack
🇫🇷
masterguru
2026-09-13 12:45:07
(1 day ago)
Restricted File Access Attempt. Matched phrase "proc/self" at REQUEST_FILENAME. (930130-195)
Hacking
Web App Attack
Anonymous
2026-09-13 12:40:27
(1 day ago)
34.187.157.191 - - [13/Sep/2026:07:40:27 -0500] "GET /.env?raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 Ap ...
show more
34.187.157.191 - - [13/Sep/2026:07:40:27 -0500] "GET /.env?raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ChatGPT-User/1.0; +https://openai.com/bot)" 34.187.157.191
34.187.157.191 - - [13/Sep/2026:07:40:27 -0500] "GET /.env?import&raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; KimiBot/1.0; +https://kimi.ai/)" 34.187.157.191
34.187.157.191 - - [13/Sep/2026:07:40:27 -0500] "GET /.env.local?raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" 34.187.157.191
34.187.157.191 - - [13/Sep/2026:07:40:27 -0500] "GET /.env?import&url&inline HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; YouBot/1.0; +https://you.com/bot)" 34.187.157.191
34.187.157.191 - - [13/Sep/2026:07:40:27 -0500] "GET /.env.local?import&raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot)" 34.187.157.191
34.187.157.191 - - [13/Sep/2026:07:40:27 -0500] "GET /.env.product
...
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-13 12:34:07
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.187.157.191 (191.157.187.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 34.187.157.191 (191.157.187.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 08:34:03.808720 2026] [security2:error] [pid 5741:tid 5741] [client 34.187.157.191:44082] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||softwarezz.net|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "softwarezz.net"] [uri "/rclone.conf"] [unique_id "aqaYO2jB2XJlTvJ9qprFpwAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack