Anonymous
2026-09-09 06:40:11
(4 minutes ago)
Automated report (2026-09-09T14:40:11+08:00). Caught probing for env file. Traversal attack detected ...
show more
Automated report (2026-09-09T14:40:11+08:00). Caught probing for env file. Traversal attack detected.
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 05:45:49
(59 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.81.118.37 (37.118.81.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.81.118.37 (37.118.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 01:45:43.226223 2026] [security2:error] [pid 29481:tid 29481] [client 34.81.118.37:50270] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.drbolen.com"] [uri "/@fs/.env"] [unique_id "aqDyh4wwWVQlUmJJ2y7FJAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-09 05:28:27
(1 hour ago)
34.81.118.37 - sliver85.eu - [09/Sep/2026:07:28:23 +0200] "GET / HTTP/1.1" 444 "Mozilla/5.0 (X11; Li ...
show more
34.81.118.37 - sliver85.eu - [09/Sep/2026:07:28:23 +0200] "GET / HTTP/1.1" 444 "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Safari/537.36"
34.81.118.37 - sliver85.eu - [09/Sep/2026:07:28:24 +0200] "GET / HTTP/1.1" 444 "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36"
34.81.118.37 - sliver85.eu - [09/Sep/2026:07:28:25 +0200] "GET / HTTP/1.1" 444 "Mozilla/5.0 (iPhone; CPU iPhone OS 17_0 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Mobile/15E148 Safari/604.1"
34.81.118.37 - sliver85.eu - [09/Sep/2026:07:28:26 +0200] "GET / HTTP/1.1" 444 "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
...
show less
Brute-Force
Web App Attack
🇧🇪
cmbplf
2026-09-09 04:36:29
(2 hours ago)
242 requests with url.path *.ssh/*
106 requests with url.path *config.php
Brute-Force
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-09 04:30:26
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.81.118.37 (37.118.81.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.81.118.37 (37.118.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 00:30:20.323683 2026] [security2:error] [pid 1954:tid 1954] [client 34.81.118.37:19210] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mldlnn.com"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252fapp/.env"] [unique_id "aqDg3PPHljukFwaBc65obgAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 04:04:55
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.81.118.37 (37.118.81.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.81.118.37 (37.118.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 00:04:52.092178 2026] [security2:error] [pid 21654:tid 21654] [client 34.81.118.37:14920] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.greybrucepork.ca"] [uri "/@fs/.env.production"] [unique_id "aqDa5P27sd9loQHDiTbPNwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-09 03:54:49
(2 hours ago)
Aggressive web scan
Web App Attack
🇫🇷
Octopuce
2026-09-09 03:50:17
(2 hours ago)
Aggressive web search of vulnerable pages: /img../.env /_nuxt/../.env /uploads../.env /v1/.env /v2/. ...
show more
Aggressive web search of vulnerable pages: /img../.env /_nuxt/../.env /uploads../.env /v1/.env /v2/.env ...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 03:46:56
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.81.118.37 (37.118.81.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.81.118.37 (37.118.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 23:46:49.215268 2026] [security2:error] [pid 1271:tid 1271] [client 34.81.118.37:34684] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "twilighthackers.com"] [uri "/@fs/app/.env"] [unique_id "aqDWqYsPGZs2iZ_DRzonkwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
grassau.com
2026-09-09 03:02:47
(3 hours ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 34.81.118.37 (TW/Tai ...
show more
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 34.81.118.37 (TW/Taiwan/Taipei City/Taipei/37.118.81.34.bc.googleusercontent.com)
show less
Bad Web Bot
🇩🇪
FD-IX
2026-09-09 03:01:30
(3 hours ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
🇩🇪
4server
2026-09-09 02:34:34
(4 hours ago)
[WedSep0904:34:30.2087602026][security2:error][pid2413557:tid2413586][client34.81.118.37:0]ModSecuri ...
show more
[WedSep0904:34:30.2087602026][security2:error][pid2413557:tid2413586][client34.81.118.37:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"/etc/passwd\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_rules/10_asl_rules.conf\"][line\"141\"][id\"347009\"][rev\"1\"][msg\"Atomicorp.comWAFRules:ProtectedFileaccessdenied\"][severity\"CRITICAL\"][hostname\"webdisk.gustotondo.ch\"][uri\"/@fs/etc/passwd\"][unique_id\"aqDFtma0allBLTgmBj8yIgAAAVM\"]
show less
Port Scan
Brute-Force
Web App Attack
🇫🇷
dynamix
2026-09-09 02:34:03
(4 hours ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 02:06:07
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.81.118.37 (37.118.81.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.81.118.37 (37.118.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 22:06:03.263556 2026] [security2:error] [pid 27644:tid 27644] [client 34.81.118.37:32020] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.dreamingofatlantis.com"] [uri "/@fs/../.env"] [unique_id "aqC_C690TZWzw4ZHJZd2vQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
snhosting
2026-09-09 01:56:24
(4 hours ago)
34.81.118.37 - - [09/Sep/2026:03:56:14 +0200] "GET /@fs/..%252f..%252f..%252f..%252f..%252fapp/.env? ...
show more
34.81.118.37 - - [09/Sep/2026:03:56:14 +0200] "GET /@fs/..%252f..%252f..%252f..%252f..%252fapp/.env?raw?? HTTP/1.1" 200 1618 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; OAI-SearchBot/1.3; +https://openai.com/searchbot)"
34.81.118.37 - - [09/Sep/2026:03:56:14 +0200] "GET /@fs/..%252f..%252f..%252f..%252f..%252froot/.env?raw?? HTTP/1.1" 200 1628 "-" "Mozilla/5.0 (Linux; Android 12; Pixel 6) AppleWebKit/537.36 (KHTML, like Gecko; compatible; Twitterbot/1.0) Chrome/147.0.1223.168 Mobile Safari/537.36"
34.81.118.37 - - [09/Sep/2026:03:56:14 +0200] "GET /@fs/app/.env?raw?? HTTP/1.1" 200 1628 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexity-user)"
34.81.118.37 - - [09/Sep/2026:03:56:14 +0200] "GET /@fs/.env?raw?? HTTP/1.1" 200 1628 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; GrokBot/1.0; +https://x.ai/grokbot"
34.81.118.37 - - [09/Sep/2026:03:56:14 +0200] "GET /@fs/../.en
...
show less
DNS Compromise
DNS Poisoning
Phishing
Email Spam
Brute-Force
Web App Attack
SSH