🇫🇷
Omar Martínez
2026-09-09 20:34:19
(58 minutes ago)
[Wed Sep 09 14:33:58.659031 2026] [core:error] [pid 3478912:tid 139864586573376] [client 34.21.166.1 ...
show more
[Wed Sep 09 14:33:58.659031 2026] [core:error] [pid 3478912:tid 139864586573376] [client 34.21.166.181:28212] AH10244: invalid URI path (/@fs/../../.env?raw??)
[Wed Sep 09 14:34:17.032973 2026] [core:error] [pid 3558565:tid 139864553002560] [client 34.21.166.181:48678] AH10244: invalid URI path (/@fs/../../../../../proc/self/environ?raw??)
...
show less
Phishing
Email Spam
Blog Spam
🇩🇪
BlueWire Hosting
2026-09-09 19:23:42
(2 hours ago)
Probing websites for vulnerabilities
Web App Attack
🇨🇭
zynex
2026-09-09 19:17:20
(2 hours ago)
URL Probing: /@fs/src/.env
Web App Attack
Anonymous
2026-09-09 18:08:12
(3 hours ago)
Bot / seems abusive / Apache connections: 64
DDoS Attack
Web Spam
Bad Web Bot
Web App Attack
🇩🇪
Skyrider
2026-09-09 17:42:26
(3 hours ago)
Nginx: HTTP 4xx probe/scan attempts. Automated fail2ban report.
Bad Web Bot
Web App Attack
🇳🇱
BlueWire Hosting
2026-09-09 16:18:38
(5 hours ago)
High-confidence malicious configuration/VCS probe
Web App Attack
🇬🇧
consul.to
2026-09-09 15:43:41
(5 hours ago)
Web attack/malicious scanning detected
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 15:35:14
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.21.166.181 (181.166.21.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.21.166.181 (181.166.21.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 11:35:08.729632 2026] [security2:error] [pid 7200:tid 7200] [client 34.21.166.181:15592] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "drbbenefits.com"] [uri "/@fs/../../.env"] [unique_id "aqF8rCzgAKOe5jFqhOhLIAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇷🇴
iulianh
2026-09-09 14:11:47
(7 hours ago)
80,443
Brute-Force
SSH
🇺🇸
TPI-Abuse
2026-09-09 12:40:13
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.21.166.181 (181.166.21.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.21.166.181 (181.166.21.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 08:40:09.072503 2026] [security2:error] [pid 5942:tid 5942] [client 34.21.166.181:60400] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.machineryenchantress.com"] [uri "/@fs/root/.env"] [unique_id "aqFTqRzhWbgpME-5xABM9QAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
lavnet.net
2026-09-09 12:28:25
(9 hours ago)
34.21.166.181 - - [09/Sep/2026:12:28:25 +0000] "GET /@fs/root/rootkey.csv?raw?? HTTP/1.1" 404 2925 " ...
show more
34.21.166.181 - - [09/Sep/2026:12:28:25 +0000] "GET /@fs/root/rootkey.csv?raw?? HTTP/1.1" 404 2925 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexity-user)"
34.21.166.181 - - [09/Sep/2026:12:28:25 +0000] "GET /@fs/..%252f..%252f..%252f..%252f..%252froot/.env?raw?? HTTP/1.1" 404 2925 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Bytespider; +https://zhanzhang.toutiao.com/)"
34.21.166.181 - - [09/Sep/2026:12:28:25 +0000] "GET /@fs/root/.env?raw?? HTTP/1.1" 404 2925 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Amzn-SearchBot/1.0; +https://developer.amazon.com/support/amazonbot)"
34.21.166.181 - - [09/Sep/2026:12:28:25 +0000] "GET /@fs/.env?raw?? HTTP/1.1" 404 2924 "-" "Mozilla/5.0 (Windows NT 11.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko; compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot) Chrome/118.0.2553.185 Safari/537.36"
34.21.166.181 - - [09
...
show less
Brute-Force
🇺🇸
TPI-Abuse
2026-09-09 12:24:20
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.21.166.181 (181.166.21.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.21.166.181 (181.166.21.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 08:24:16.184282 2026] [security2:error] [pid 26472:tid 26472] [client 34.21.166.181:63342] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.sophcomp.com"] [uri "/@fs/app/.env"] [unique_id "aqFP8OMO25CDuKHJUSsZaQAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Vegascosmetics
2026-09-09 12:21:03
(9 hours ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after sensitive config/credentials exposure ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after sensitive config/credentials exposure probe. Evidence: AttackPattern: /\.env (Match: /.env)
show less
Hacking
Brute-Force
Web App Attack
🇩🇪
ghostwarriors
2026-09-09 12:20:06
(9 hours ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
🇫🇷
masterguru
2026-09-09 12:15:36
(9 hours ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.21.166.181 (SG/Singapore/181.166.2 ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.21.166.181 (SG/Singapore/181.166.21.34.bc.googleusercontent.com): 1 in the last 3600 secs (0-195)
show less
Hacking