🇳🇱
homeshowdomain.nl
2026-09-07 22:03:03
(2 days ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-06.
show less
Web App Attack
SSH
Hacking
🇺🇸
TPI-Abuse
2026-09-07 03:15:39
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.38.51.232 (232.51.38.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.38.51.232 (232.51.38.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 23:15:34.688163 2026] [security2:error] [pid 1976:tid 1976] [client 34.38.51.232:57566] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "intermixx.com"] [uri "/@fs/app/.env"] [unique_id "ap4sVno16b0X7sXTN7uLJAAAACo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-07 02:03:58
(3 days ago)
34.38.51.232 - - [07/Sep/2026:04:03:55 +0200] "GET /serverless.yml HTTP/1.1" 403 124 "-" "Mozilla/5. ...
show more
34.38.51.232 - - [07/Sep/2026:04:03:55 +0200] "GET /serverless.yml HTTP/1.1" 403 124 "-" "Mozilla/5.0 (compatible; YouBot/1.0; +https://you.com/bot)"
34.38.51.232 - - [07/Sep/2026:04:03:56 +0200] "GET /serverless.yaml HTTP/1.1" 403 124 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot)"
34.38.51.232 - - [07/Sep/2026:04:03:56 +0200] "GET /config/env/aws_credentials.env HTTP/1.1" 403 124 "-" "Mozilla/5.0 (compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot)"
34.38.51.232 - - [07/Sep/2026:04:03:56 +0200] "GET /z9x8c7v6b5-debug-trigger-matrixventures.co.zm HTTP/1.1" 403 124 "-" "Mozilla/5.0 (compatible; PanguBot/1.0; +https://www.huaweicloud.com/)"
34.38.51.232 - - [07/Sep/2026:04:03:56 +0200] "GET /secrets.env HTTP/1.1" 403 124 "-" "CCBot/2.0 (https://commoncrawl.org/faq/)"
34.38.51.232 - - [07/Sep/2026:04:03:56 +0200] "GET /.idea/WebServers.xml HTTP/1.1" 404 119619 "-" "Mozilla/5.0 (compatibl
...
show less
Bad Web Bot
Web App Attack
🇫🇷
david.houstin
2026-09-07 02:01:30
(3 days ago)
34.38.51.232 - - [07/Sep/2026:04:01:27 +0200] "GET /uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f.env ...
show more
34.38.51.232 - - [07/Sep/2026:04:01:27 +0200] "GET /uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f.env HTTP/2.0" 404 264 "-" "Mozilla/5.0 (compatible; KimiBot/1.0; +https://kimi.ai/)"
34.38.51.232 - - [07/Sep/2026:04:01:27 +0200] "GET /admin%2F.env HTTP/2.0" 404 264 "-" "Mozilla/5.0 (compatible; Google-Extended; +http://www.google.com/bot.html)"
34.38.51.232 - - [07/Sep/2026:04:01:27 +0200] "GET /dashboard%2F.env HTTP/2.0" 404 264 "-" "Mozilla/5.0 (compatible; YiBot/1.0; +https://01.ai/)"
34.38.51.232 - - [07/Sep/2026:04:01:27 +0200] "GET /api%2F.env HTTP/2.0" 404 264 "-" "Mozilla/5.0 (compatible; Bravebot/1.0; +https://brave.com/search/)"
34.38.51.232 - - [07/Sep/2026:04:01:27 +0200] "GET /settings%2F.env HTTP/2.0" 404 264 "-" "Mozilla/5.0 (compatible; Hunyuan/1.0; +https://hunyuan.tencent.com/)"
34.38.51.232 - - [07/Sep/2026:04:01:29 +0200] "GET /api/uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2fvar/run/secrets/kubernetes.io/serviceaccount/token HTTP/2.0" 404 264 "-" "Mozilla/5.
...
show less
Web App Attack
Bad Web Bot
🇺🇸
dot.mg
2026-09-07 01:38:02
(3 days ago)
Bad behaviour
Web Spam
🇫🇷
COMAITE
2026-09-07 01:01:44
(3 days ago)
Suspicious URL access.
Web App Attack
🇬🇧
Aetherweb Ark
2026-09-07 00:39:44
(3 days ago)
(mod_security) mod_security (id:949110) triggered by 34.38.51.232 (BE/Belgium/232.51.38.34.bc.google ...
show more
(mod_security) mod_security (id:949110) triggered by 34.38.51.232 (BE/Belgium/232.51.38.34.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 00:29:52
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 34.38.51.232 (232.51.38.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.38.51.232 (232.51.38.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 20:29:46.042187 2026] [security2:error] [pid 18409:tid 18409] [client 34.38.51.232:52088] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||dancingbearprinting.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "dancingbearprinting.com"] [uri "/rclone.conf"] [unique_id "ap4Fenl-jJ_NvptzVHvEjgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇪🇸
pepitogrillo
2026-09-07 00:16:12
(3 days ago)
34.38.51.232 - - [07/Sep/2026:00:16:11 +0000] "GET /public/plugins/text/../../../../../../../../proc ...
show more
34.38.51.232 - - [07/Sep/2026:00:16:11 +0000] "GET /public/plugins/text/../../../../../../../../proc/self/environ HTTP/1.1" 400 514 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
...
show less
DNS Compromise
DNS Poisoning
Fraud Orders
DDoS Attack
Ping of Death
Phishing
Fraud VoIP
Open Proxy
Web Spam
Email Spam
Port Scan
Hacking
SQL Injection
Bad Web Bot
Exploited Host
Web App Attack
IoT Targeted
🇺🇸
TPI-Abuse
2026-09-06 23:52:48
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 34.38.51.232 (232.51.38.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.38.51.232 (232.51.38.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 19:52:42.041301 2026] [security2:error] [pid 1298769:tid 1298854] [client 34.38.51.232:35266] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||sattraffic.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "sattraffic.com"] [uri "/z9x8c7v6b5-debug-trigger-sattraffic.com"] [unique_id "ap38yuzpUE8uChzG_TzAowAAAJQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇪
cmbplf
2026-09-06 23:35:51
(3 days ago)
113 requests with url.path *.oci/*
109 requests with url.path *.ssh/*
Brute-Force
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-06 21:59:47
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.38.51.232 (232.51.38.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.38.51.232 (232.51.38.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 17:59:42.884325 2026] [security2:error] [pid 12638:tid 12683] [client 34.38.51.232:53706] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.gotogps.com"] [uri "/css../.env"] [unique_id "ap3iTrjQqUbSTz_WDKFOeAAAAZY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
dynamix
2026-09-06 20:48:21
(4 days ago)
Multiple WAF Violations
Web App Attack
🇳🇱
Savvii
2026-09-06 19:07:39
(4 days ago)
20 attempts against mh-misbehave-ban on ozone
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Savvii
2026-09-06 18:26:27
(4 days ago)
20 attempts against mh_ha-misbehave-ban on ceres
Brute-Force
Bad Web Bot
Web App Attack