🇺🇸
TPI-Abuse
2026-09-08 12:47:59
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.38.189.5 (5.189.38.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.38.189.5 (5.189.38.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 08:47:54.487991 2026] [security2:error] [pid 17240:tid 17240] [client 34.38.189.5:46040] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.checkmyvaluegilroy.kunzteam.com"] [uri "/@fs/src/.env"] [unique_id "aqAD-tkmrGsS_8SqIp-buQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Site.eu
2026-09-08 12:07:57
(2 hours ago)
Excessive multi-domain requests
Brute-Force
🇺🇸
TPI-Abuse
2026-09-08 11:52:35
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.38.189.5 (5.189.38.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.38.189.5 (5.189.38.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 07:52:28.621736 2026] [security2:error] [pid 20109:tid 20109] [client 34.38.189.5:34226] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.edsantos.biz"] [uri "/@fs/root/.env"] [unique_id "ap_2_GH701gHFwECEXBEQAAAACc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-08 11:52:29
(2 hours ago)
34.38.189.5 - - [08/Sep/2026:13:52:28 +0200] "GET /@fs/root/.env?raw?? HTTP/1.1" 403 124 "-" "Mozill ...
show more
34.38.189.5 - - [08/Sep/2026:13:52:28 +0200] "GET /@fs/root/.env?raw?? HTTP/1.1" 403 124 "-" "Mozilla/5.0 (compatible; Amzn-SearchBot/1.0; +https://developer.amazon.com/support/amazonbot)"
34.38.189.5 - - [08/Sep/2026:13:52:28 +0200] "GET /@fs/etc/passwd?raw?? HTTP/1.1" 403 124 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 15_0) AppleWebKit/605.1.15 (KHTML, like Gecko; compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot) Version/18.0 Safari/605.1.15"
34.38.189.5 - - [08/Sep/2026:13:52:28 +0200] "GET /@fs/app/.env?raw?? HTTP/1.1" 403 183 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko; compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot) Chrome/128.0.9060.19 Safari/537.36"
34.38.189.5 - - [08/Sep/2026:13:52:28 +0200] "GET /@fs/.env?raw?? HTTP/1.1" 403 183 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.1722.148 Safari/537.36; compatible; Perplexity-User/1.0; +https://perplexit
...
show less
Bad Web Bot
Web App Attack
🇳🇱
e.fierstra
2026-09-08 11:31:42
(2 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇦🇺
rubixstudios
2026-09-08 11:26:02
(2 hours ago)
Excessive HTTP requests consistent with automated attack behaviour detected by Imunify360
DDoS Attack
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 11:24:16
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.38.189.5 (5.189.38.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.38.189.5 (5.189.38.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 07:24:09.042619 2026] [security2:error] [pid 19419:tid 19419] [client 34.38.189.5:33988] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.suswastima.com"] [uri "/@fs/root/.env"] [unique_id "ap_wWUPSxKF8VX-uF3_jNAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 10:58:38
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.38.189.5 (5.189.38.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.38.189.5 (5.189.38.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 06:58:33.963179 2026] [security2:error] [pid 32078:tid 32078] [client 34.38.189.5:21892] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.vittariafashion.vittariadesign.com"] [uri "/@fs/.env"] [unique_id "ap_qWcu55ZxvEgnIox-oSwAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 10:37:55
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.38.189.5 (5.189.38.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.38.189.5 (5.189.38.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 06:37:50.849640 2026] [security2:error] [pid 28958:tid 28958] [client 34.38.189.5:10144] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.addisonkinkade.com"] [uri "/@fs/app/.env"] [unique_id "ap_lfipNMw9q3JAv0Brv1gAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-08 10:14:27
(3 hours ago)
34.38.189.5 - - [08/Sep/2026:05:12:46 -0500] "GET /.env.development HTTP/1.1" 301 280 "https://storm ...
show more
34.38.189.5 - - [08/Sep/2026:05:12:46 -0500] "GET /.env.development HTTP/1.1" 301 280 "https://stormtank.com/.env.development" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; +https://www.anthropic.com/claude-user)" 104.23.229.118
34.38.189.5 - - [08/Sep/2026:05:12:46 -0500] "GET /.env.backup HTTP/1.1" 301 275 "https://stormtank.com/.env.backup" "Mozilla/5.0 (Windows NT 10.0; rv:149.1) Gecko/20100101 Firefox/149.1; compatible; Twitterbot/1.0" 172.71.127.21
34.38.189.5 - - [08/Sep/2026:05:12:46 -0500] "GET /.env.example HTTP/1.1" 301 276 "https://stormtank.com/.env.example" "Mozilla/5.0 (compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexity-user)" 172.71.232.14
34.38.189.5 - - [08/Sep/2026:05:12:46 -0500] "GET /.env.staging HTTP/1.1" 301 276 "https://stormtank.com/.env.staging" "Mozilla/5.0 (X11; Linux x86_64; rv:128.15) Gecko/20100101 Firefox/128.15; compatible; GrokBot/1.0; +https://x.ai/grokbot" 104.23.225.88
34.38.189.5 - - [08/Sep/2026:
...
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 09:56:18
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.38.189.5 (5.189.38.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.38.189.5 (5.189.38.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 05:56:10.009136 2026] [security2:error] [pid 16118:tid 16118] [client 34.38.189.5:23056] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.lynellejonsson.com"] [uri "/@fs/root/.env"] [unique_id "ap_buoU72EzgW_e-54a04wAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
ruusvuu
2026-09-08 09:24:26
(4 hours ago)
Automated abuse report: 25 attack/probe requests from Google LLC / BE.
Targeted paths: /@fs/..%252f. ...
show more
Automated abuse report: 25 attack/probe requests from Google LLC / BE.
Targeted paths: /@fs/..%252f..%252f..%252f..%252f..%252fproc/self/environ, /@fs/proc/self/environ, /@fs/etc/passwd, /@fs/var/run/secrets/kubernetes.io/serviceaccount/token, /@fs/home/node/.config/gcloud/application_default_credentials.json.
Sample log lines:
[pixboard] 2026-09-08T02:24:25: PXV 2026-09-08T09:24:25.898Z 34.38.189.5 GET /@fs/proc/self/cmdline?raw?? 404 - Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko; compat…
[pixboard] 2026-09-08T02:24:25: PXV 2026-09-08T09:24:25.901Z 34.38.189.5 GET /@fs/root/.config/gcloud/application_default_credentials.json?raw?? 404 - Mozilla/5.0 (X11; Ubuntu; Linux x86_64) AppleWeb…
[pixboard] 2026-09-08T02:24:25: PXV 2026-09-08T09:24:25.904Z 34.38.189.5 GET /@fs/root/.config/gcloud/credentials.db?raw?? 404 - Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; GrokBo…
Detected by an automated web-server log monitor.
show less
Web App Attack
🇨🇦
swk
2026-09-08 09:07:37
(5 hours ago)
34.38.189.5 - - [08/Sep/2026:09:07:31 +0000] "GET / HTTP/1.1" 301 162 "-" "Mozilla/5.0 (Windows NT 1 ...
show more
34.38.189.5 - - [08/Sep/2026:09:07:31 +0000] "GET / HTTP/1.1" 301 162 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/148.0.0.0 Safari/537.36 Edg/148.0.0.0"
34.38.189.5 - - [08/Sep/2026:09:07:32 +0000] "GET / HTTP/1.1" 200 2596 "-" "Mozilla/5.0 (Linux; Android 13; SM-G935R6; Build/TP1A.180718.91) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.6261.127 Mobile Safari/537.36"
34.38.189.5 - - [08/Sep/2026:09:07:32 +0000] "GET / HTTP/1.1" 200 2596 "http://mail.ailuyou.vip/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/148.0.0.0 Safari/537.36 Edg/148.0.0.0"
34.38.189.5 - - [08/Sep/2026:09:07:36 +0000] "GET /@fs/.env?raw?? HTTP/1.1" 404 479 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Slackbot-LinkExpanding/1.0; +https://api.slack.com/robots)"
34.38.189.5 - - [08/Sep/2026:09:07:36 +0000] "GET /@fs/src/.env?raw?? HTTP/1.1" 404 479 "-" "Mozilla/5.0 (Windows NT 11.0; Win64; x64) A
...
show less
Hacking
Web App Attack
🇩🇪
FeG Deutschland
2026-09-08 08:39:32
(5 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 12
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 08:36:38
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.38.189.5 (5.189.38.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.38.189.5 (5.189.38.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 04:36:33.915411 2026] [security2:error] [pid 1714852:tid 1715271] [client 34.38.189.5:53824] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.records.emehache.com"] [uri "/@fs/app/.env"] [unique_id "ap_JEROHGUIw6XcWdwojGgAAAVQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack