🇷🇺
olegio
2026-08-29 21:00:22
(21 minutes ago)
34.34.152.232 - - [29/Aug/2026:21:00:21 +0000] "GET /@fs/app/.env?raw?? HTTP/2.0" 403 146 "-" "Mozil ...
show more
34.34.152.232 - - [29/Aug/2026:21:00:21 +0000] "GET /@fs/app/.env?raw?? HTTP/2.0" 403 146 "-" "Mozilla/5.0 (compatible; Amzn-SearchBot/1.0; +https://developer.amazon.com/support/amazonbot)"
34.34.152.232 - - [29/Aug/2026:21:00:21 +0000] "GET /@fs/root/.env?raw?? HTTP/2.0" 403 146 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; facebookexternalhit/1.1; +http://www.facebook.com/externalhit_uatext.php)"
...
show less
Brute-Force
Web App Attack
🇨🇭
zynex
2026-08-29 19:40:03
(1 hour ago)
URL Probing: /@fs/app/.env
Web App Attack
🇲🇾
Rizzy
2026-08-29 18:04:57
(3 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack
Anonymous
2026-08-29 17:12:01
(4 hours ago)
34.34.152.232 - - [29/Aug/2026:14:12:01 -0300] "GET /@fs/..%252f..%252f..%252f..%252f..%252froot/.en ...
show more
34.34.152.232 - - [29/Aug/2026:14:12:01 -0300] "GET /@fs/..%252f..%252f..%252f..%252f..%252froot/.env?raw?? HTTP/1.1" 403 180 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_0 like Mac OS X) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.5225.35 Mobile Safari/537.36; compatible; Applebot/0.1; +http://www.apple.com/go/applebot"
34.34.152.232 - - [29/Aug/2026:14:12:01 -0300] "GET /@fs/root/.env?raw?? HTTP/1.1" 403 118 "-" "Mozilla/5.0 (compatible; ChatGPT-User/1.0; +https://openai.com/bot)"
34.34.152.232 - - [29/Aug/2026:14:12:01 -0300] "GET /@fs/.env?raw?? HTTP/1.1" 403 118 "-" "Mozilla/5.0 (Windows NT 10.0; rv:121.8) Gecko/20100101 Firefox/121.8; compatible; OAI-SearchBot/1.4; robots.txt; +https://openai.com/searchbot"
34.34.152.232 - - [29/Aug/2026:14:12:01 -0300] "GET /@fs/..%252f..%252f..%252f..%252f..%252fapp/.env?raw?? HTTP/1.1" 403 180 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_4 like Mac OS X) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.7093.134 Mobile Safari/537.36; comp
...
show less
Port Scan
🇫🇷
Kraften
2026-08-29 14:56:30
(6 hours ago)
Trying script web attack
...
Web App Attack
Anonymous
2026-08-29 14:31:40
(6 hours ago)
Automated report from fail2ban.
Detected: automated probing for vulnerable/administrative endpoints ...
show more
Automated report from fail2ban.
Detected: automated probing for vulnerable/administrative endpoints (e.g. wp-login.php, phpMyAdmin) consistent with bot scanning.
Jail: nginx-botsearch
Failed attempts recorded: 2
Report time: 2026-08-29 14:31:40 UTC
This IP has been automatically and permanently blocked at our network perimeter.
Evidence (most recent matched log lines, redacted):
$f2bV_matches
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-08-29 13:57:13
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.34.152.232 (232.152.34.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.34.152.232 (232.152.34.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 09:57:08.842272 2026] [security2:error] [pid 14549:tid 14549] [client 34.34.152.232:36078] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.tianabes.com"] [uri "/@fs/.env"] [unique_id "apLlNOjLOERn-OZGt_xIGgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-29 13:19:19
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.34.152.232 (232.152.34.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.34.152.232 (232.152.34.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 09:19:12.622583 2026] [security2:error] [pid 30853:tid 30853] [client 34.34.152.232:3348] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.usefulendeavors.org"] [uri "/@fs/root/.env"] [unique_id "apLcUEUVOwZTh5wfK1EcBAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-29 12:55:28
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.34.152.232 (232.152.34.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.34.152.232 (232.152.34.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 08:55:20.499179 2026] [security2:error] [pid 2349:tid 2349] [client 34.34.152.232:42710] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.arctic-sea.com"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252fapp/.env"] [unique_id "apLWuLWvUspAWMDkRznDwQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
creechy
2026-08-29 12:46:53
(8 hours ago)
34.34.152.232 - - [29/Aug/2026:05:46:46 -0700] "GET /@fs/.env?raw?? HTTP/1.1" 404 764
...
Hacking
Bad Web Bot
🇺🇦
URAN Publishing Service
2026-08-29 12:27:03
(8 hours ago)
[29/Aug/2026:15:27:03 +0300] -- 34.34.152.232 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET / ...
show more
[29/Aug/2026:15:27:03 +0300] -- 34.34.152.232 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET /@fs/../.env?raw?? HTTP/1.1
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-29 12:16:55
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.34.152.232 (232.152.34.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.34.152.232 (232.152.34.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 08:16:48.565735 2026] [security2:error] [pid 5405:tid 5405] [client 34.34.152.232:5154] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.austintrauma.com"] [uri "/@fs/.env"] [unique_id "apLNsCV1MGNYu117JEdYJAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇿🇦
conure.sh
2026-08-29 12:00:55
(9 hours ago)
csagent: score 20.0: secrets grab x2; 1 domain(s) in 5s
Web App Attack
🇺🇸
TPI-Abuse
2026-08-29 11:39:27
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.34.152.232 (232.152.34.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.34.152.232 (232.152.34.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 07:39:21.016229 2026] [security2:error] [pid 10035:tid 10043] [client 34.34.152.232:46060] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.securitymediaservices.com"] [uri "/@fs/.env"] [unique_id "apLE6SGq06eqtA3PEJqO4gAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
XICTRON
2026-08-29 11:35:09
(9 hours ago)
ModSecurity rule violation detected by Fail2Ban
Web App Attack