๐บ๐ธ
mw
2026-10-02 00:20:18
(21 hours ago)
GET /api/system/fileView?file=/app/.env HTTP/1.1
Web App Attack
๐ซ๐ฎ
Christopher Hughes
2026-10-01 17:19:34
(1 day ago)
34.45.209.138 - - [01/Oct/2026:18:19:34 +0100] "GET /.env.test HTTP/2.0" 401 410 "-" "Mozilla/5.0 (c ...
show more
34.45.209.138 - - [01/Oct/2026:18:19:34 +0100] "GET /.env.test HTTP/2.0" 401 410 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
...
show less
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-10-01 16:31:58
(1 day ago)
Try to access /.env.bak
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 16:16:53
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.45.209.138 (138.209.45.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.45.209.138 (138.209.45.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 12:16:49.616089 2026] [security2:error] [pid 24782:tid 24782] [client 34.45.209.138:37804] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.waleed-alshalan.com"] [uri "/static../.env"] [unique_id "ar6HcQ7QzxCtkjjd5Hv8FwAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
poundawebsiteltd
2026-10-01 15:19:54
(1 day ago)
Malicious activity in general-malicious. Evidence: (apache_probe) Failed Access (403/404) 34.45.209. ...
show more
Malicious activity in general-malicious. Evidence: (apache_probe) Failed Access (403/404) 34.45.209.138 (US/United States/[REDACTED_DOMAIN]): 20 in the last 3600 secs | UA: (apache_probe) Failed Access (403/404) 34.45.209.138 (US/United States/138.209.45.34.bc.googleusercontent.com): 20 in the last 3600 secs
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 15:09:34
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.45.209.138 (138.209.45.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.45.209.138 (138.209.45.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 11:09:30.000865 2026] [security2:error] [pid 10999:tid 10999] [client 34.45.209.138:56784] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||wakims.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "wakims.com"] [uri "/z9x8c7v6b5-debug-trigger-wakims.com"] [unique_id "ar53qYc1nztvw0oQ2EraNgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-01 13:45:18
(1 day ago)
Observed scanned 255 known-sensitive endpoint(s), e.g.: /, /%2eenv, /.//.env, /.aws/config, /.aws/cr ...
show more
Observed scanned 255 known-sensitive endpoint(s), e.g.: /, /%2eenv, /.//.env, /.aws/config, /.aws/credentials, /.bashrc
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
middelkoopcc
2026-10-01 12:03:10
(1 day ago)
2026-10-01 14:01:50 GET /js../.env [301] && 2026-10-01 14:01:50 GET /config.json [301] && 2026-10-01 ...
show more
2026-10-01 14:01:50 GET /js../.env [301] && 2026-10-01 14:01:50 GET /config.json [301] && 2026-10-01 14:01:50 GET /__/firebase/init.json [301] && 127 more within 20 minutes
show less
Web App Attack
๐บ๐ธ
Charlesiv
2026-10-01 12:01:18
(1 day ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Prot ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Protocol: HTTP/2 (POST method)
Endpoint: /exec-py
Timestamp: 2026-10-01T11:38:26Z
Ray ID: a43b2e58eabde223
UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36; compatible; OAI-SearchBot/1.4; +https://openai.com/searchbot
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-01 11:40:45
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.45.209.138 (138.209.45.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.45.209.138 (138.209.45.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 07:40:38.855402 2026] [security2:error] [pid 25772:tid 25772] [client 34.45.209.138:46550] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ic1.biz"] [uri "/static//.env"] [unique_id "ar5GtmlR131UvaTEs1b5xAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alboweb B.V.
2026-10-01 11:11:02
(1 day ago)
Bad web bot activity detected by Fail2Ban in plesk-apache-badbot jail
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-01 11:06:54
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.45.209.138 (138.209.45.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.45.209.138 (138.209.45.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 07:06:47.309928 2026] [security2:error] [pid 11945:tid 11945] [client 34.45.209.138:45498] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||walterjhoodco.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "walterjhoodco.com"] [uri "/z9x8c7v6b5-debug-trigger-walterjhoodco.com"] [unique_id "ar4-x3EHgTe7OSbCTAYQnQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-01 11:04:40
(1 day ago)
Aggressive web scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 10:39:09
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.45.209.138 (138.209.45.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.45.209.138 (138.209.45.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 06:39:06.931801 2026] [security2:error] [pid 28848:tid 28848] [client 34.45.209.138:46670] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.wallawallafirearmstraining.com|F|2"] [data ".wallawallafirearmstraining.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.wallawallafirearmstraining.com"] [uri "/z9x8c7v6b5-debug-trigger-www.wallawallafirearmstraining.com"] [unique_id "ar44StfFGYjfWzaH6Ge-AAAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-01 10:37:34
(1 day ago)
Blocked by fail2ban on a public web server.
Web App Attack