🇬🇧
Andrew
2026-09-12 23:51:43
(3 minutes ago)
34.74.51.226 - - [13/Sep/2026:00:51:42 +0100] "GET /.env.production HTTP/1.1" 404 20281 "-" "Mozilla ...
show more
34.74.51.226 - - [13/Sep/2026:00:51:42 +0100] "GET /.env.production HTTP/1.1" 404 20281 "-" "Mozilla/5.0 (compatible; Bravebot/1.0; +https://brave.com/search/)"
34.74.51.226 - - [13/Sep/2026:00:51:42 +0100] "GET /.git/HEAD HTTP/1.1" 404 20275 "-" "Mozilla/5.0 (compatible; Google-Extended; +http://www.google.com/bot.html)"
34.74.51.226 - - [13/Sep/2026:00:51:42 +0100] "GET /.git/config HTTP/1.1" 404 20277 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ChatGPT-User/1.0; +https://openai.com/bot)"
34.74.51.226 - - [13/Sep/2026:00:51:42 +0100] "GET /.gitconfig HTTP/1.1" 404 18360 "-" "Mozilla/5.0 (compatible; ChatGLM-Spider/1.0; +https://zhipuai.cn/)"
34.74.51.226 - - [13/Sep/2026:00:51:42 +0100] "GET /.github/workflows/deploy.yml HTTP/1.1" 404 18378 "-" "Mozilla/5.0 (compatible; Bravebot/1.0; +https://brave.com/search/)"
34.74.51.226 - - [13/Sep/2026:00:51:42 +0100] "GET /.env HTTP/1.1" 404 18354 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15
...
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 23:46:10
(8 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.74.51.226 (226.51.74.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.74.51.226 (226.51.74.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 19:46:04.231049 2026] [security2:error] [pid 26872:tid 26872] [client 34.74.51.226:36598] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ltrinc.com"] [uri "/%2E%2E/%2E%2E/%2E%2E/%2E%2E/.env"] [unique_id "aqXkPIRVU0q8nOfkP_NpVAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
regishoussin
2026-09-12 23:05:29
(49 minutes ago)
Automated web scanning detected by Wazuh (rule 100241): repeated 400/404 errors from mass probing of ...
show more
Automated web scanning detected by Wazuh (rule 100241): repeated 400/404 errors from mass probing of admin/backdoor paths (e.g. wp-login.php, known CMS shell filenames) on an Apache web server, on 2026-09-12 23:05 UTC.
show less
Bad Web Bot
Web App Attack
Anonymous
2026-09-12 22:56:12
(58 minutes ago)
Bot / seems abusive / Apache connections: 36
DDoS Attack
Web Spam
Bad Web Bot
Web App Attack
🇫🇷
LRob
2026-09-12 22:55:10
(59 minutes ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.ssh/id_rsa | 2026-09-12 22:55 UTC
show less
Hacking
Web App Attack
🇫🇷
LRNP
2026-09-12 22:38:06
(1 hour ago)
_:443 34.74.51.226 - - [12/Sep/2026:22:38:05 +0000] "GET /.aws/config HTTP/1.1" 404 118 "-" "DuckAss ...
show more
_:443 34.74.51.226 - - [12/Sep/2026:22:38:05 +0000] "GET /.aws/config HTTP/1.1" 404 118 "-" "DuckAssistBot/1.1 (https://duckduckgo.com/duckassistbot)"
_:443 34.74.51.226 - - [12/Sep/2026:22:38:05 +0000] "GET /.env.local HTTP/1.1" 404 118 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; [email protected] )"
_:443 34.74.51.226 - - [12/Sep/2026:22:38:05 +0000] "GET /user/login HTTP/1.1" 404 181 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36"
_:443 34.74.51.226 - - [12/Sep/2026:22:38:05 +0000] "GET /signin HTTP/1.1" 404 181 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36"
_:443 34.74.51.226 - - [12/Sep/2026:22:38:05 +0000] "GET /auth HTTP/1.1" 404 181 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36"
_:443 34.74.51.226 - - [12/Se
...
show less
Bad Web Bot
Web App Attack
🇩🇪
on-com
2026-09-12 22:13:28
(1 hour ago)
URL scan
Brute-Force
Web App Attack
🇺🇸
interbiznw.com
2026-09-12 22:05:52
(1 hour ago)
fail2ban-ban
Hacking
Brute-Force
Exploited Host
Web App Attack
Anonymous
2026-09-12 21:47:51
(2 hours ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 21:37:10
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.74.51.226 (226.51.74.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.74.51.226 (226.51.74.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 17:37:05.349151 2026] [security2:error] [pid 9763:tid 9763] [client 34.74.51.226:41710] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lovestuff.net"] [uri "/media../.env"] [unique_id "aqXGAXeGIYNZzfyD2jsCkgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 21:18:38
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.74.51.226 (226.51.74.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.74.51.226 (226.51.74.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 17:18:33.673588 2026] [security2:error] [pid 25081:tid 25081] [client 34.74.51.226:38006] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||lovelybeyondwords.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "lovelybeyondwords.com"] [uri "/z9x8c7v6b5-debug-trigger-lovelybeyondwords.com"] [unique_id "aqXBqWhbcX_hkyqvJtb0RAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
IndigoRidge
2026-09-12 21:16:19
(2 hours ago)
34.74.51.226 - - [12/Sep/2026:17:16:17 -0400] "GET /.env?raw HTTP/1.1" 404 45259 "https://lovelivegr ...
show more
34.74.51.226 - - [12/Sep/2026:17:16:17 -0400] "GET /.env?raw HTTP/1.1" 404 45259 "https://lovelivegreenville.com/.env?raw" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexitybot)"
34.74.51.226 - - [12/Sep/2026:17:16:18 -0400] "GET /.env?import&url&inline HTTP/1.1" 404 45283 "https://lovelivegreenville.com/.env?import&url&inline" "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)"
34.74.51.226 - - [12/Sep/2026:17:16:18 -0400] "GET /.env?import&raw HTTP/1.1" 404 45271 "https://lovelivegreenville.com/.env?import&raw" "Mozilla/5.0 (compatible; GrokBot/1.0; +https://x.ai/)"
...
show less
Web App Attack
🇧🇪
cmbplf
2026-09-12 21:08:37
(2 hours ago)
21.560 requests in 1 hour (2mos3w6d)
Brute-Force
Bad Web Bot
🇺🇸
mnsf
2026-09-12 21:05:27
(2 hours ago)
Scanning/Probing (24)
Request Overload (121)
Brute-Force
Web App Attack
🇫🇷
Octopuce
2026-09-12 20:53:16
(3 hours ago)
Aggressive web search of vulnerable pages: /userfiles?path=../../.env /userfiles?path=../../../.env ...
show more
Aggressive web search of vulnerable pages: /userfiles?path=../../.env /userfiles?path=../../../.env /userfiles?path=../../../../.env /userfiles ...
show less
Web App Attack