🇫🇮
geot
2026-08-29 20:45:23
(8 hours ago)
GET /.well-known/jwks.json HTTP/1.1
Hacking
Web App Attack
🇦🇺
rubixstudios
2026-08-28 14:00:04
(1 day ago)
Excessive HTTP requests consistent with automated attack behaviour detected by Imunify360
DDoS Attack
Brute-Force
Web App Attack
🇩🇪
Zydzy
2026-08-28 13:58:07
(1 day ago)
Automated attack detected. Server: 95.140.154.181. Jail: nginx-exploit.
Web App Attack
🇺🇸
TPI-Abuse
2026-08-28 13:31:13
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.62.6.90 (90.6.62.34.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:210492) triggered by 34.62.6.90 (90.6.62.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 09:31:05.468034 2026] [security2:error] [pid 17674:tid 17674] [client 34.62.6.90:45624] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.souldata.com"] [uri "/@fs/app/.env"] [unique_id "apGNmWlgPODto6Jb9rma0wAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-28 13:07:55
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.62.6.90 (90.6.62.34.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:210492) triggered by 34.62.6.90 (90.6.62.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 09:07:49.629301 2026] [security2:error] [pid 743681:tid 744360] [client 34.62.6.90:14564] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "besfixedwireless.com.exede-sales.com"] [uri "/@fs/app/.env"] [unique_id "apGIJazKk__5QR0Jy-_BmwAAAFQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
raph
2026-08-28 12:32:19
(1 day ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack
🇳🇱
debestelapp
2026-08-28 12:25:07
(1 day ago)
Web App Attack
🇺🇸
TPI-Abuse
2026-08-28 12:04:52
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.62.6.90 (90.6.62.34.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:210492) triggered by 34.62.6.90 (90.6.62.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 08:04:45.104985 2026] [security2:error] [pid 22233:tid 22233] [client 34.62.6.90:42180] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "enjoy2dance.com"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252fapp/.env"] [unique_id "apF5XQBAhdYKnKaUlhigSQAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-28 11:49:15
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.62.6.90 (90.6.62.34.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:210492) triggered by 34.62.6.90 (90.6.62.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 07:49:09.130087 2026] [security2:error] [pid 19696:tid 19696] [client 34.62.6.90:62992] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.boaredraven.com"] [uri "/@fs/.env"] [unique_id "apF1tbgNm6pOMuFs3mxzCAAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-28 11:31:12
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.62.6.90 (90.6.62.34.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:210492) triggered by 34.62.6.90 (90.6.62.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 07:31:08.296901 2026] [security2:error] [pid 7654:tid 7654] [client 34.62.6.90:17452] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.tireking.co"] [uri "/@fs/.env"] [unique_id "apFxfMQU--Boa8wSKSeE-QAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇭🇺
DumaNet
2026-08-28 11:30:00
(1 day ago)
Web app attack attempts, scanning for vulnerability.
Date: 2026 Aug 28. 10:41:12
Source IP: 34.62. ...
show more
Web app attack attempts, scanning for vulnerability.
Date: 2026 Aug 28. 10:41:12
Source IP: 34.62.6.90
Portion of the log(s):
34.62.6.90 - [28/Aug/2026:10:41:12 +0200] "GET /@fs/.env.development?raw?? HTTP/1.1" 404 555 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.4546.149 Safari/537.36; compatible; GrokBot/1.0; +https://x.ai/grokbot"
34.62.6.90 - [28/Aug/2026:10:41:12 +0200] "GET /@fs/.env.production?raw?? HTTP/1.1" 404 153 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; Amzn-SearchBot/1.0; +https://developer.amazon.com/support/amazonbot"
34.62.6.90 - [28/Aug/2026:10:41:12 +0200] "GET /@fs/..%252f..%252f..%252f..%252f..%252froot/.env?raw?? HTTP/1.1" 404 153 "-" "Mozilla/5.0 (compatible; Slackbot-LinkExpanding/1.0; +https://api.slack.com/robots)"
34.62.6.90 - [28/Aug/2026:10:41:12 +0200] "GET /@fs/.env.local?raw?? HTTP/1.1" 404 153 "-" "Mozilla/5.0 (Windows NT 10.0; rv:132.0) Gecko/20100101 Firefox/132.0; compatible; Discor
show less
Web App Attack
🇬🇧
consul.to
2026-08-28 11:00:42
(1 day ago)
Web attack/malicious scanning detected
Web App Attack
🇪🇸
alferez
2026-08-28 10:43:11
(1 day ago)
Searching .(env|sql|zip|tar|rar) files
Hacking
Exploited Host
Web App Attack
🇫🇷
masterguru
2026-08-28 10:10:57
(1 day ago)
BAD BOT - Detected and Blocked.. Matched phrase "bytespider" at REQUEST_HEADERS:User-Agent. (1100000 ...
show more
BAD BOT - Detected and Blocked.. Matched phrase "bytespider" at REQUEST_HEADERS:User-Agent. (1100000-196)
show less
Bad Web Bot
🇩🇪
Stefan Dreher
2026-08-28 10:05:02
(1 day ago)
34.62.6.90 - - [28/Aug/2026:12:05:01 +0200] "GET /@fs/root/.env?raw?? HTTP/1.1" 404 125 "-" "Mozilla ...
show more
34.62.6.90 - - [28/Aug/2026:12:05:01 +0200] "GET /@fs/root/.env?raw?? HTTP/1.1" 404 125 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexity-user)"
34.62.6.90 - - [28/Aug/2026:12:05:01 +0200] "GET /@fs/etc/passwd?raw?? HTTP/1.1" 404 187 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_0 like Mac OS X) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/118.0.5895.207 Mobile Safari/537.36; compatible; Discordbot/2.0; +https://discordapp.com"
34.62.6.90 - - [28/Aug/2026:12:05:01 +0200] "GET /@fs/../.env?raw?? HTTP/1.1" 404 125 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ChatGPT-User/1.0; +https://openai.com/bot)"
34.62.6.90 - - [28/Aug/2026:12:05:01 +0200] "GET /@fs/.env?raw?? HTTP/1.1" 404 187 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko; compatible; Google-Extended/1.0; +http://www.google.com/bot.html) Chrome/118.0.4268.6 Safari/537.36"
34.62.6.90 - - [28/Aug/2026:12:05:01 +0200] "GE
show less
Hacking
Brute-Force