🇩🇪
ghostwarriors
2026-09-07 21:20:11
(15 hours ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
🇩🇪
yitzhaq
2026-09-07 21:09:26
(15 hours ago)
34.22.54.139 - - [07/Sep/2026:23:09:21 +0200] "GET /.env.local HTTP/1.1" 404 516 "-" "Mozilla/5.0 (W ...
show more
34.22.54.139 - - [07/Sep/2026:23:09:21 +0200] "GET /.env.local HTTP/1.1" 404 516 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.22.54.139 - - [07/Sep/2026:23:09:22 +0200] "GET /.env.production HTTP/1.1" 404 516 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.22.54.139 - - [07/Sep/2026:23:09:22 +0200] "GET /.env.staging HTTP/1.1" 404 516 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.22.54.139 - - [07/Sep/2026:23:09:22 +0200] "GET /.env.development HTTP/1.1" 404 516 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.22.54.139 - - [07/Sep/2026:23:09:22 +0200] "GET /.env.test HTTP/1.1" 404 516 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/5
show less
Web App Attack
Hacking
🇫🇷
Zundapper
2026-09-07 20:23:12
(16 hours ago)
34.22.54.139 - - [07/Sep/2026:22:23:01 +0200] "GET /config/.env HTTP/1.1" 404 548 "-" "Mozilla/5.0 ( ...
show more
34.22.54.139 - - [07/Sep/2026:22:23:01 +0200] "GET /config/.env HTTP/1.1" 404 548 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.22.54.139 - - [07/Sep/2026:22:23:10 +0200] "GET /vendor/.env HTTP/1.1" 404 548 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.22.54.139 - - [07/Sep/2026:22:23:10 +0200] "GET /vendor/.env HTTP/1.1" 404 548 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.22.54.139 - - [07/Sep/2026:22:23:12 +0200] "GET /bin/.env HTTP/1.1" 404 548 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Web App Attack
Port Scan
🇩🇪
Hazzard
2026-09-07 19:18:01
(17 hours ago)
(mod_security) mod_security triggered on hostname [redacted]): (CF_ENABLE)
SQL Injection
🇺🇸
Rocky Mountain Bioengineering Symposium
2026-09-07 17:59:13
(18 hours ago)
[Mon Sep 07 11:59:10.720341 2026] [authz_core:error] [pid 89514:tid 139763864561216] [client 34.22.5 ...
show more
[Mon Sep 07 11:59:10.720341 2026] [authz_core:error] [pid 89514:tid 139763864561216] [client 34.22.54.139:33930] AH01630: client denied by server configuration: /var/www/horde/.env.bak
[Mon Sep 07 11:59:12.779731 2026] [authz_core:error] [pid 89514:tid 139763956815424] [client 34.22.54.139:33930] AH01630: client denied by server configuration: /var/www/horde/.env.dist
[Mon Sep 07 11:59:12.849605 2026] [authz_core:error] [pid 89514:tid 139763789026880] [client 34.22.54.139:33930] AH01630: client denied by server configuration: /var/www/horde/.env.swp
...
show less
Bad Web Bot
🇩🇪
Petros Stefanakis
2026-09-07 17:16:00
(19 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 34.22.54.139 (US/United States/139.54.2 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.22.54.139 (US/United States/139.54.22.34.bc.googleusercontent.com)
show less
SQL Injection
🇺🇸
TPI-Abuse
2026-09-07 14:58:33
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.22.54.139 (139.54.22.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.22.54.139 (139.54.22.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 10:58:29.481146 2026] [security2:error] [pid 32075:tid 32075] [client 34.22.54.139:55754] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.computer-advisors.com"] [uri "/.git/config"] [unique_id "ap7RFfrR49ebh8FZNugEwgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇭
4server
2026-09-07 13:18:32
(23 hours ago)
[MonSep0715:18:29.4437082026][security2:error][pid1261956:tid1262318][client34.22.54.139:0]ModSecuri ...
show more
[MonSep0715:18:29.4437082026][security2:error][pid1261956:tid1262318][client34.22.54.139:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".git\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"610\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"mail.comarcosa.com.81-17-25-250.cpanel.site\"][uri\"/.git/config\"][unique_id\"ap65pY30PZ0zu6FDXYNNgwAAAVQ\"]
show less
Hacking
Web App Attack
🇷🇴
iulianh
2026-09-07 13:10:51
(23 hours ago)
80,443
Brute-Force
SSH
🇺🇸
dot.mg
2026-09-07 13:03:03
(23 hours ago)
Bad behaviour
Web Spam
🇺🇸
TPI-Abuse
2026-09-07 12:26:47
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.22.54.139 (139.54.22.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.22.54.139 (139.54.22.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 08:26:39.458646 2026] [security2:error] [pid 19713:tid 19753] [client 34.22.54.139:51710] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.colinkyffinmusic.com"] [uri "/.git/config"] [unique_id "ap6tf2eAISeWoIQ_UMZXkQAAAYk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 11:49:56
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.22.54.139 (139.54.22.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.22.54.139 (139.54.22.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 07:49:48.416557 2026] [security2:error] [pid 10070:tid 10070] [client 34.22.54.139:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.coiledtubingdrilling.com"] [uri "/.git/config"] [unique_id "ap6k3PYtJryhNAc6hBqC3wAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
Apache
2026-09-07 09:18:46
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.22.54.139 (US/United States/139.54.22.34.bc. ...
show more
(mod_security) mod_security (id:210492) triggered by 34.22.54.139 (US/United States/139.54.22.34.bc.googleusercontent.com): 5 in the last 300 secs (CF_ENABLE)
show less
Brute-Force
Web App Attack
🇫🇷
Zundapper
2026-09-07 08:23:47
(1 day ago)
34.22.54.139 - - [07/Sep/2026:10:23:22 +0200] "GET /config/.env HTTP/1.1" 404 548 "-" "Mozilla/5.0 ( ...
show more
34.22.54.139 - - [07/Sep/2026:10:23:22 +0200] "GET /config/.env HTTP/1.1" 404 548 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.22.54.139 - - [07/Sep/2026:10:23:35 +0200] "GET /vendor/.env HTTP/1.1" 404 548 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.22.54.139 - - [07/Sep/2026:10:23:37 +0200] "GET /bin/.env HTTP/1.1" 404 548 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.22.54.139 - - [07/Sep/2026:10:23:44 +0200] "GET /temp/.env HTTP/1.1" 404 548 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.22.54.139 - - [07/Sep/2026:10:23:47 +0200] "GET /logs/.env HTTP/1.1" 404 548 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Web App Attack
Port Scan
🇺🇸
TPI-Abuse
2026-09-07 06:29:39
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.22.54.139 (139.54.22.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.22.54.139 (139.54.22.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 02:29:33.971271 2026] [security2:error] [pid 2624:tid 2624] [client 34.22.54.139:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.cloudbursttechnologies.com"] [uri "/.git/config"] [unique_id "ap5ZzRzKCG04d9s_qNuMlwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack