🇫🇷
david.houstin
2026-09-07 07:12:32
(32 minutes ago)
34.28.81.87 - - [07/Sep/2026:09:11:49 +0200] "GET /@fs/..%2f..%2f..%2f..%2f..%2froot/.env?raw?? HTTP ...
show more
34.28.81.87 - - [07/Sep/2026:09:11:49 +0200] "GET /@fs/..%2f..%2f..%2f..%2f..%2froot/.env?raw?? HTTP/1.1" 404 1799 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Bytespider; +https://zhanzhang.toutiao.com/)"
34.28.81.87 - - [07/Sep/2026:09:11:49 +0200] "GET /@fs/..%2f..%2f..%2f..%2f..%2fapp/.env?raw?? HTTP/1.1" 404 1799 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; OAI-SearchBot/1.3; +https://openai.com/searchbot"
34.28.81.87 - - [07/Sep/2026:09:11:50 +0200] "GET /@fs/var/www/html/wp-config.php?raw?? HTTP/1.1" 404 5918 "https://www.chinesetools.eu/@fs/var/www/html/wp-config.php?raw??" "Mozilla/5.0 (compatible; OAI-SearchBot/1.4; robots.txt; +https://openai.com/searchbot)" 14728 -
34.28.81.87 - - [07/Sep/2026:09:12:30 +0200] "GET /api/config HTTP/1.1" 404 38126 "https://www.chinesetools.eu/api/config" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:133.14) Gecko/20100101 Firefox/133.14; compatible; LinkedInBot/1.0; +http://www.linkedin.com" 29426
...
show less
Web App Attack
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-07 06:55:40
(49 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.28.81.87 (87.81.28.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.28.81.87 (87.81.28.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 02:55:36.147061 2026] [security2:error] [pid 7686:tid 7686] [client 34.28.81.87:64600] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.santagreetingcards.com"] [uri "/@fs/.env.development"] [unique_id "ap5f6E8KysymklL4MzmMmQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇪
cmbplf
2026-09-07 06:36:27
(1 hour ago)
768 requests with url.path *.aws/*
235 requests with url.path *.ssh/*
Brute-Force
Bad Web Bot
Anonymous
2026-09-07 06:29:35
(1 hour ago)
(mod_security) mod_security triggered on hostname [redacted] 34.28.81.87 (US/United States/87.81.28. ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.28.81.87 (US/United States/87.81.28.34.bc.googleusercontent.com)
show less
SQL Injection
Anonymous
2026-09-07 06:21:19
(1 hour ago)
Multiple web server 400 error codes from same source ip
Web App Attack
Anonymous
2026-09-07 06:21:13
(1 hour ago)
Bot / seems abusive / Apache connections: 20
DDoS Attack
Web Spam
Bad Web Bot
Web App Attack
Anonymous
2026-09-07 06:20:28
(1 hour ago)
Aggressive web scan
Web App Attack
🇪🇸
elcruzado.es
2026-09-07 06:09:38
(1 hour ago)
(mod_security) mod_security triggered on hostname [redacted] 34.28.81.87 (US/United States/87.81.28. ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.28.81.87 (US/United States/87.81.28.34.bc.googleusercontent.com)
show less
SQL Injection
🇫🇮
mnazibo
2026-09-07 06:00:10
(1 hour ago)
Date: 07/Sep/2026 08:59:09 | Reported IP: 34.28.81.87 mod_security | id: 930100 930110 930130 930140 ...
show more
Date: 07/Sep/2026 08:59:09 | Reported IP: 34.28.81.87 mod_security | id: 930100 930110 930130 930140 | US/group.my_domain/- | Connections: 194 | Blocked: Permanent Block: [LF_MODSEC] | URIs: /admin/.env; /.anthropic/config.json; /api/.env; /app-config.json; /app/.env; /application_default_credentials.json; /application.env; /assets../.env; /.aws/config; /.aws/credentials; /aws.env; /.azure/credentials; /azure-credentials.json; /backend/.env; /.bash_history; /.bash_profile; /.claude/settings.json; /.codex/config.toml; /.config/anthropic/credentials/default.json; /config/database.yml; /config/.env; /config.json; /config.php; /config.php.bak; /config/secrets.yml; /core/.env; /credentials.json; /.cursor/mcp.json; /docker-compose.yaml; /docker-compose.yml; /.docker/config.json; /.docker/.env; /docker/.env; /Dockerfile; /.env~; /.env.anthropic; /.env.backup; /.env.bak; /.env.development; /.env.example; /.env.local; /.env.old; /.env.openai; /.
show less
SQL Injection
Brute-Force
Bad Web Bot
🇬🇧
Aetherweb Ark
2026-09-07 05:31:11
(2 hours ago)
(mod_security) mod_security (id:949110) triggered by 34.28.81.87 (US/United States/87.81.28.34.bc.go ...
show more
(mod_security) mod_security (id:949110) triggered by 34.28.81.87 (US/United States/87.81.28.34.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 05:07:21
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.28.81.87 (87.81.28.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.28.81.87 (87.81.28.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 01:07:14.867690 2026] [security2:error] [pid 8779:tid 8779] [client 34.28.81.87:44622] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.paragontechusa.com"] [uri "/@fs/.env"] [unique_id "ap5GgraCcvC0cjxGll-lEAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 04:50:30
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.28.81.87 (87.81.28.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.28.81.87 (87.81.28.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 00:50:26.140316 2026] [security2:error] [pid 4030:tid 4030] [client 34.28.81.87:53556] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.intrinsicreef.com"] [uri "/@fs/.env"] [unique_id "ap5Cki7LFjKPz-adHN9begAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-07 04:42:49
(3 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
🇸🇬
mypatricks
2026-09-07 04:35:32
(3 hours ago)
34.28.81.87 | Port: 12677 | DNS: 87.81.28.34.bc.googleusercontent.com 2026-09-07T12:35:30+08:00 Asia ...
show more
34.28.81.87 | Port: 12677 | DNS: 87.81.28.34.bc.googleusercontent.com 2026-09-07T12:35:30+08:00 Asia/Singapore | Fake GoogleBot Detected | UA: Mozilla/5.0 (compatible; Google-Extended/1.0; +http://www.google.com/bot.html) HTTP/1.1 443 GET | URL: /@fs/root/.aws/credentials?raw?? | Ref: - | Country: US/United States/-08:00 a37301d3ea64aff5-ORD/Chicago, IL, United States 1 hits/0 secs Robots 2
show less
Brute-Force
Web App Attack
Blog Spam
Web Spam
Exploited Host
🇺🇸
TPI-Abuse
2026-09-07 03:54:25
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.28.81.87 (87.81.28.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.28.81.87 (87.81.28.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 23:54:21.698082 2026] [security2:error] [pid 1184803:tid 1184803] [client 34.28.81.87:24578] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.icoinedthewordironesty.com"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252froot/.env"] [unique_id "ap41bflIbxeocOavUKgHCAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack