🇩🇪
LRob
2026-08-28 14:27:07
(1 day ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /@fs/..%252f..%252f..%252f..%252f..%252froot/.env (+10 more) | 2026-08-28 14:27 UTC
show less
Hacking
Web App Attack
🇸🇪
vaia.cloud
2026-08-28 13:30:06
(1 day ago)
crowdsecurity/http-probing
Brute-Force
Web App Attack
🇩🇪
todix
2026-08-28 12:44:03
(1 day ago)
Web App Attack Exploid from 34.81.24.5
Web App Attack
🇿🇦
conure.sh
2026-08-28 12:15:03
(1 day ago)
csagent: score 21.5: 404 noise floor x6, secrets grab x2; 1 domain(s) in 8s
Web App Attack
Anonymous
2026-08-28 11:47:24
(1 day ago)
Banned by Fail2Ban on server
Web App Attack
🇩🇪
yitzhaq
2026-08-28 08:39:54
(1 day ago)
34.81.24.5 - - [28/Aug/2026:10:39:49 +0200] "GET /@fs/root/.aws/credentials.backup?raw?? HTTP/1.1" 4 ...
show more
34.81.24.5 - - [28/Aug/2026:10:39:49 +0200] "GET /@fs/root/.aws/credentials.backup?raw?? HTTP/1.1" 404 42099 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_0 like Mac OS X) AppleWebKit/537.36 (KHTML, like Gecko; compatible; Amzn-SearchBot/1.0; +https://developer.amazon.com/support/amazonbot) Chrome/122.0.5907.124 Mobile Safari/537.36"
34.81.24.5 - - [28/Aug/2026:10:39:49 +0200] "GET /@fs/home/debian/.aws/credentials?raw?? HTTP/1.1" 404 42099 "-" "Mozilla/5.0 (Linux; Android 15; SM-S918B) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.8602.170 Mobile Safari/537.36; compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexity-user"
34.81.24.5 - - [28/Aug/2026:10:39:49 +0200] "GET /@fs/proc/self/environ?raw?? HTTP/1.1" 404 42481 "-" "Mozilla/5.0 (X11; Linux x86_64; rv:150.5) Gecko/20100101 Firefox/150.5; compatible; Twitterbot/1.0"
34.81.24.5 - - [28/Aug/2026:10:39:49 +0200] "GET /@fs/.env.local?raw?? HTTP/1.1" 404 42480 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14_5) AppleWebKit
show less
Web App Attack
Hacking
🇫🇷
masterguru
2026-08-28 08:28:49
(1 day ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.81.24.5 (TW/Taiwan/5.24.81.34.bc.g ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.81.24.5 (TW/Taiwan/5.24.81.34.bc.googleusercontent.com): 1 in the last 3600 secs (0-195)
show less
Hacking
🇩🇪
Guardian
2026-08-28 08:13:07
(1 day ago)
Multi abuses [2]: Unauthorized connection attempt / Port scanning (x21), Unauthorized attempt to ret ...
show more
Multi abuses [2]: Unauthorized connection attempt / Port scanning (x21), Unauthorized attempt to retrieve configuration file (x11)
34.81.24.5 [28/Aug/2026:10:12:56 +0200] "GET / HTTP/1.1"
34.81.24.5 [28/Aug/2026:10:12:56 +0200] "GET / HTTP/1.1"
34.81.24.5 [28/Aug/2026:10:13:06 +0200] "GET /@fs/root/.aws/config?raw?? HTTP/1.1"
34.81.24.5 [28/Aug/2026:10:13:06 +0200] "GET /@fs/.env.production?raw?? HTTP/1.1"
34.81.24.5 [28/Aug/2026:10:13:06 +0200] "GET /@fs/root/.aws/credentials.bak?raw?? HTTP/1.1"
34.81.24.5 [28/Aug/2026:10:13:06 +0200] "GET /.env?raw?? HTTP/1.1"
34.81.24.5 [28/Aug/2026:10:13:06 +0200] "GET /@fs/root/.env?raw?? HTTP/1.1"
34.81.24.5 [28/Aug/2026:10:13:06 +0200] "GET /@fs/root/rootkey.csv?raw?? HTTP/1.1"
34.81.24.5 [28/Aug/2026:10:13:06 +0200] "GET /@fs/etc/passwd?raw?? HTTP/1.1"
34.81.24.5 [28/Aug/2026:10:13:06 +0200] "GET /@fs/home/ubuntu/.aws/config?raw?? HTTP/1.1"
34.81.24.5 [28/Aug/2026:10:13:06 +0200] "GET /@fs/.env.staging?raw?? HTTP/1.1"
34.81.24.5 [28/Aug/2026:10:13:06 +0200] "GET /@fs
show less
Port Scan
Web App Attack
🇺🇸
TPI-Abuse
2026-08-28 07:49:41
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.81.24.5 (5.24.81.34.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:210492) triggered by 34.81.24.5 (5.24.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 03:49:35.850007 2026] [security2:error] [pid 21484:tid 21484] [client 34.81.24.5:53104] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.dunningtons.com"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252froot/.env"] [unique_id "apE9j0Lg7JZik1NGy_c2DwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
debestelapp
2026-08-28 07:20:06
(1 day ago)
Web App Attack
🇺🇸
TPI-Abuse
2026-08-28 07:16:23
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.81.24.5 (5.24.81.34.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:210492) triggered by 34.81.24.5 (5.24.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 03:16:16.568149 2026] [security2:error] [pid 10682:tid 10682] [client 34.81.24.5:61806] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.lindafoley.com"] [uri "/@fs/.env"] [unique_id "apE1wHsH2A0mAAjwwccuugAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
Octopuce
2026-08-28 06:38:02
(1 day ago)
Aggressive web search of vulnerable pages: /assets../.env /v1/.env /frontend/.env /admin/.env /confi ...
show more
Aggressive web search of vulnerable pages: /assets../.env /v1/.env /frontend/.env /admin/.env /config/.env ...
show less
Web App Attack
🇫🇷
masterguru
2026-08-28 06:35:06
(1 day ago)
Restricted File Access Attempt. Matched phrase "/@fs/" at REQUEST_FILENAME. (930130-193)
Hacking
Web App Attack
🇪🇸
alferez
2026-08-28 06:32:48
(1 day ago)
Searching .(env|sql|zip|tar|rar) files
Hacking
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2026-08-28 06:19:17
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.81.24.5 (5.24.81.34.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:210492) triggered by 34.81.24.5 (5.24.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 02:19:11.483787 2026] [security2:error] [pid 2141:tid 2154] [client 34.81.24.5:13704] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.magusincognito.com"] [uri "/@fs/.env.development"] [unique_id "apEoX0XSqLDKp5rwffC7agAAAYg"]
show less
Brute-Force
Bad Web Bot
Web App Attack