Anonymous
2026-09-12 15:04:29
(1 hour ago)
Aggressive web scan
Web App Attack
🇳🇱
ipoac.nl
2026-09-12 10:01:47
(6 hours ago)
ipoac.nl:443 34.6.196.122 - - [12/Sep/2026:12:01:43 +0200] 203.26.133.19:443 "GET /media../.env HTTP ...
show more
ipoac.nl:443 34.6.196.122 - - [12/Sep/2026:12:01:43 +0200] 203.26.133.19:443 "GET /media../.env HTTP/1.1" 403 1928 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ClaudeBot/1.0; +claudebot*anthropic.com"
show less
Bad Web Bot
🇸🇪
sweplox.se
2026-09-12 06:14:37
(10 hours ago)
Ip 34.6.196.122 performed 'crowdsecurity/http-path-traversal-probing' (4 events over 449.989861ms) a ...
show more
Ip 34.6.196.122 performed 'crowdsecurity/http-path-traversal-probing' (4 events over 449.989861ms) at 2026-09-12 06:14:36.936424599 +0000 UTC
show less
Web App Attack
🇷🇸
Smel
2026-09-12 04:00:03
(12 hours ago)
MH/MP Probe, Scan, Hack -
Port Scan
Hacking
🇺🇸
TPI-Abuse
2026-09-12 01:23:58
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.6.196.122 (122.196.6.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.6.196.122 (122.196.6.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 21:23:50.375189 2026] [security2:error] [pid 27337:tid 27337] [client 34.6.196.122:51014] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.4"] [uri "/static../.env"] [unique_id "aqSppgnrCaXzfC2FKr-7awAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 00:19:56
(16 hours ago)
(mod_security) mod_security (id:949110) triggered by 34.6.196.122 (122.196.6.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:949110) triggered by 34.6.196.122 (122.196.6.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 20:19:52.511500 2026] [security2:error] [pid 31822:tid 31822] [client 34.6.196.122:8814] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 15)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "192.64.150.240"] [uri "/static../.env"] [unique_id "aqSaqBZrXmu5YuuAfWzPqAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-12 00:00:16
(16 hours ago)
Path traversal attempt
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 23:07:42
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.6.196.122 (122.196.6.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.6.196.122 (122.196.6.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 19:07:35.933912 2026] [security2:error] [pid 12119:tid 12119] [client 34.6.196.122:54516] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.151.37"] [uri "/static../.env"] [unique_id "aqSJt5hRHG8xRxaFL2NskwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Tsumugi Kotobuki
2026-09-11 19:51:30
(20 hours ago)
Port Scan on Honeypot | Ports: 8443/HTTPS-alt | Proto: TCP(1) | Flags: all SYN | TTL: 58 | Len: 60B ...
show more
Port Scan on Honeypot | Ports: 8443/HTTPS-alt | Proto: TCP(1) | Flags: all SYN | TTL: 58 | Len: 60B | Win: 42600(1) | rDNS: 122.196.6.34.bc.googleusercontent.com | F2B/ufw-honeypot@2026-09-11T19:51:29Z
show less
Port Scan
Hacking
Anonymous
2026-09-11 16:39:06
(23 hours ago)
Port Scan
Port Scan
🇬🇧
robmwood
2026-09-11 13:57:00
(1 day ago)
Multiple GETs probing for various file vulnerabilities like "GET /.ssh/id_dsa HTTP/1.1"
Brute-Force
Bad Web Bot
Web App Attack
🇧🇪
voormedia
2026-09-11 13:41:21
(1 day ago)
Accessed trap at '/.env'
Web App Attack
🇳🇱
Savvii
2026-09-11 10:20:16
(1 day ago)
10 attempts against mh_ha-misc-ban on pf221111
Brute-Force
Web App Attack
Anonymous
2026-09-11 05:12:52
(1 day ago)
[panel.backorder.gr] httpd-config-scan: sites=global; logs=/var/log/nginx/access.log; samples=/stati ...
show more
[panel.backorder.gr] httpd-config-scan: sites=global; logs=/var/log/nginx/access.log; samples=/static../.env | /media../.env | /@fs/proc/self/environ
show less
Hacking
Web App Attack
🇩🇪
strzonnek
2026-09-11 03:06:41
(1 day ago)
attack on webform
Brute-Force
Web App Attack