🇮🇹
[email protected]
2026-08-28 22:06:19
(2 weeks ago)
34.78.156.43 - - [28/Aug/2026:02:25:36 +0200] "GET /.env HTTP/1.1" 404 2010 "-" "Mozilla/5.0 AppleWe ...
show more
34.78.156.43 - - [28/Aug/2026:02:25:36 +0200] "GET /.env HTTP/1.1" 404 2010 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; GPTBot/1.2; +https://openai.com/gptbot"
show less
Web App Attack
Hacking
🇫🇷
masterguru
2026-08-28 12:06:34
(2 weeks ago)
Restricted File Access Attempt. Matched phrase "/@fs/" at REQUEST_FILENAME. (930130-201)
Hacking
Web App Attack
🇺🇸
WellSpring
2026-08-28 11:55:18
(2 weeks ago)
env leak on strangertable.org/@fs/home/ubuntu/.env — WellSpr.ing/NetSentinel civic-AI security layer
Web App Attack
🇭🇺
DumaNet
2026-08-28 11:32:00
(2 weeks ago)
Web app attack attempts, scanning for vulnerability.
Date: 2026 Aug 28. 10:59:39
Source IP: 34.78. ...
show more
Web app attack attempts, scanning for vulnerability.
Date: 2026 Aug 28. 10:59:39
Source IP: 34.78.156.43
Portion of the log(s):
34.78.156.43 - [28/Aug/2026:10:59:39 +0200] "GET /@fs/home/admin/.aws/credentials?raw?? HTTP/1.1" 404 153 "-" "Mozilla/5.0 (compatible; LinkedInBot/1.0; +http://www.linkedin.com)"
34.78.156.43 - [28/Aug/2026:10:59:39 +0200] "GET /@fs/var/www/html/.aws/credentials?raw?? HTTP/1.1" 404 153 "-" "Mozilla/5.0 (compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot)"
34.78.156.43 - [28/Aug/2026:10:59:39 +0200] "GET /@fs/home/www-data/.aws/credentials?raw?? HTTP/1.1" 404 153 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:105.12) Gecko/20100101 Firefox/105.12; compatible; TelegramBot/1.0"
34.78.156.43 - [28/Aug/2026:10:59:39 +0200] "GET /@fs/home/ec2-user/.aws/credentials?raw?? HTTP/1.1" 404 555 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko; compatible; Google-Extended/1.0; +http://www.google.com/bot.html) Chrome/118.0.435
show less
Web App Attack
🇩🇪
maxpower
2026-08-28 11:19:11
(2 weeks ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 34.78.156.43 (BE/Belgium/43.156.78.34.bc ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 34.78.156.43 (BE/Belgium/43.156.78.34.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 34.78.156.43 - - [28/Aug/2026:13:19:08 +0200] "GET /@fs/home/node/.aws/credentials?raw?? HTTP/2.0" 200 4747 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_4 like Mac OS X) AppleWebKit/537.36 (KHTML, like Gecko; compatible; Twitterbot/1.0) Chrome/109.0.2736.34 Mobile Safari/537.36" "34.78.156.43" host=www.vortici.it
show less
Port Scan
🇳🇱
e.fierstra
2026-08-28 10:40:10
(2 weeks ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇦🇺
rubixstudios
2026-08-28 10:22:02
(2 weeks ago)
Excessive HTTP requests consistent with automated attack behaviour detected by Imunify360
DDoS Attack
Brute-Force
Web App Attack
🇫🇷
[email protected]
2026-08-28 10:08:13
(2 weeks ago)
PrestaShop Security Module: AbuseIPDB high confidence score AND local web-app-attack detected (Abuse ...
show more
PrestaShop Security Module: AbuseIPDB high confidence score AND local web-app-attack detected (AbuseIPDB score: 100% (cached))
show less
Web App Attack
🇺🇸
Player Unknown
2026-08-28 09:25:52
(2 weeks ago)
34.78.156.43 - - [28/Aug/2026:02:25:43 -0700] "GET /@fs/../../.env?raw?? HTTP/1.1" 400 6606 "-" "-"
...
show more
34.78.156.43 - - [28/Aug/2026:02:25:43 -0700] "GET /@fs/../../.env?raw?? HTTP/1.1" 400 6606 "-" "-"
34.78.156.43 - - [28/Aug/2026:02:25:51 -0700] "GET /@fs/../../../../../root/.env?raw?? HTTP/1.1" 400 6606 "-" "-"
34.78.156.43 - - [28/Aug/2026:02:25:51 -0700] "GET /@fs/..%2f..%2f..%2f..%2f..%2fapp/.env?raw?? HTTP/1.1" 400 6606 "-" "-"
34.78.156.43 - - [28/Aug/2026:02:25:51 -0700] "GET /@fs/..%2f..%2f..%2f..%2f..%2fproc/self/environ?raw?? HTTP/1.1" 400 6606 "-" "-"
34.78.156.43 - - [28/Aug/2026:02:25:51 -0700] "GET /@fs/../../../../../app/.env?raw?? HTTP/1.1" 400 6606 "-" "-"
...
show less
Brute-Force
SSH
🇫🇷
masterguru
2026-08-28 08:11:25
(2 weeks ago)
Restricted File Access Attempt. Matched phrase "/@fs/" at REQUEST_FILENAME. (930130-193)
Hacking
Web App Attack
🇿🇦
conure.sh
2026-08-28 07:13:06
(2 weeks ago)
csagent: score 20.5: secrets grab x2, 404 noise floor x2; 1 domain(s) in 3s
Web App Attack
🇩🇪
maxpower
2026-08-28 06:43:45
(2 weeks ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 34.78.156.43 (BE/Belgium/43.156.78.34.bc ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 34.78.156.43 (BE/Belgium/43.156.78.34.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 34.78.156.43 - - [28/Aug/2026:08:43:41 +0200] "GET /@fs/root/.aws/credentials.bak?raw?? HTTP/2.0" 403 207 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko; compatible; Twitterbot/1.0) Chrome/136.0.6090.128 Safari/537.36" "34.78.156.43" host=lisoladeidesideri.it
show less
Port Scan
🇺🇸
TPI-Abuse
2026-08-28 06:20:31
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.78.156.43 (43.156.78.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.78.156.43 (43.156.78.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 02:20:25.312319 2026] [security2:error] [pid 32344:tid 32344] [client 34.78.156.43:28184] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.marketingtailoredtoyou.com"] [uri "/@fs/.env"] [unique_id "apEoqS55pVN-GhQDrwioJAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-28 06:02:35
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.78.156.43 (43.156.78.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.78.156.43 (43.156.78.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 02:02:30.559822 2026] [security2:error] [pid 5225:tid 5225] [client 34.78.156.43:18452] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.wildpete.com"] [uri "/@fs/root/.env"] [unique_id "apEkdu4hjsK81QvWmXIs6wAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-28 05:15:27
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.78.156.43 (43.156.78.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.78.156.43 (43.156.78.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 01:15:01.175612 2026] [security2:error] [pid 12154:tid 12154] [client 34.78.156.43:25822] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.mkdesignndetailing.com"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252fapp/.env"] [unique_id "apEZVShmQYeWSz-Tr6OeGgAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack