🇧🇪
cmbplf
2026-09-08 22:39:44
(5 minutes ago)
305 requests with url.path *.aws/*
Brute-Force
Bad Web Bot
🇩🇪
Séfora Srl
2026-09-08 20:13:37
(2 hours ago)
crowdsecurity/http-probing detected by CrowdSec
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 19:42:35
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.84.177.82 (82.177.84.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.84.177.82 (82.177.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 15:42:28.290408 2026] [security2:error] [pid 23235:tid 23340] [client 34.84.177.82:36718] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.icecc.com.aafm.us"] [uri "/@fs/.env"] [unique_id "aqBlJK0o0Fccgv_JBe-TtwAAAhQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
debestelapp
2026-09-08 19:15:12
(3 hours ago)
Web App Attack
🇩🇪
maxpower
2026-09-08 18:56:57
(3 hours ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 34.84.177.82 (JP/Japan/82.177.84.34.bc.g ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 34.84.177.82 (JP/Japan/82.177.84.34.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 34.84.177.82 - - [08/Sep/2026:20:56:54 +0200] "GET /@fs/home/www-data/.aws/credentials?raw?? HTTP/2.0" 200 4843 "-" "Mozilla/5.0 (compatible; ClaudeBot/1.0; [email protected] )" "34.84.177.82" host=abruzzotour.it
show less
Port Scan
🇺🇸
TPI-Abuse
2026-09-08 18:35:53
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.84.177.82 (82.177.84.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.84.177.82 (82.177.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 14:35:49.311020 2026] [security2:error] [pid 28009:tid 28009] [client 34.84.177.82:13782] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.i-med.com"] [uri "/@fs/app/.env"] [unique_id "aqBVhVVvl1kIb4eY4ma6OgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-08 18:26:41
(4 hours ago)
34.84.177.82 - - [08/Sep/2026:13:26:40 -0500] "GET /.env.bak HTTP/1.1" 403 199 "-" "Mozilla/5.0 (com ...
show more
34.84.177.82 - - [08/Sep/2026:13:26:40 -0500] "GET /.env.bak HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; Twitterbot/1.0)" 34.84.177.82
34.84.177.82 - - [08/Sep/2026:13:26:40 -0500] "GET /.env.old HTTP/1.1" 403 199 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_0 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.4 Mobile/15E148 Safari/604.1; compatible; Applebot/0.1; +http://www.apple.com/go/applebot" 34.84.177.82
34.84.177.82 - - [08/Sep/2026:13:26:40 -0500] "GET /.env.staging HTTP/1.1" 403 199 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexity-user) Chrome/134.0.296.231 Safari/537.36" 34.84.177.82
34.84.177.82 - - [08/Sep/2026:13:26:40 -0500] "GET /.env.swp HTTP/1.1" 403 199 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko; compatible; TelegramBot/1.0) Chrome/85.0.4701.234 Safari/537.36" 34.84.177.82
34.84.177.82 - - [08/Sep/202
...
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
Octopuce
2026-09-08 18:09:15
(4 hours ago)
Aggressive web search of vulnerable pages: /assets../.env /laravel/.env /images../.env /.docker/.env ...
show more
Aggressive web search of vulnerable pages: /assets../.env /laravel/.env /images../.env /.docker/.env /config/.env ...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 18:04:45
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.84.177.82 (82.177.84.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.84.177.82 (82.177.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 14:04:41.611279 2026] [security2:error] [pid 21970:tid 21970] [client 34.84.177.82:59946] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.debzy.tolenaar.com"] [uri "/@fs/root/.env"] [unique_id "aqBOOYHkX3GxwECUTVb0xAAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TAY
2026-09-08 17:56:34
(4 hours ago)
34.84.177.82 - - [09/Sep/2026:01:56:03 +0800] "GET /@fs/../../.env?raw?? HTTP/1.1" 400 2589 "-" "Moz ...
show more
34.84.177.82 - - [09/Sep/2026:01:56:03 +0800] "GET /@fs/../../.env?raw?? HTTP/1.1" 400 2589 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; GrokBot/1.0; +https://x.ai/grokbot)"
34.84.177.82 - - [09/Sep/2026:01:56:04 +0800] "GET /@fs/../.env?raw?? HTTP/1.1" 404 41554 "-" "Mozilla/5.0 (compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexity-user)"
34.84.177.82 - - [09/Sep/2026:01:56:27 +0800] "GET /@fs/../../../../../proc/self/environ?raw?? HTTP/1.1" 400 2589 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; [email protected] )"
34.84.177.82 - - [09/Sep/2026:01:56:27 +0800] "GET /@fs/../../../../../app/.env?raw?? HTTP/1.1" 400 2589 "-" "Mozilla/5.0 (compatible; GrokBot/1.0; +https://x.ai/grokbot)"
34.84.177.82 - - [09/Sep/2026:01:56:27 +0800] "GET /@fs/../../../../../root/.env?raw?? HTTP/1.1" 400 2589 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; +h
...
show less
Brute-Force
🇬🇧
consul.to
2026-09-08 16:47:45
(5 hours ago)
Web attack/malicious scanning detected
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 16:36:40
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.84.177.82 (82.177.84.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.84.177.82 (82.177.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 12:36:35.942454 2026] [security2:error] [pid 10475:tid 10475] [client 34.84.177.82:21198] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.fredlandia.com"] [uri "/@fs/.env"] [unique_id "aqA5k-epTngGDrgP_xLsvwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 16:05:10
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.84.177.82 (82.177.84.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.84.177.82 (82.177.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 12:05:04.239390 2026] [security2:error] [pid 27392:tid 27392] [client 34.84.177.82:14930] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.greatplainswingcaf.org"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252fapp/.env"] [unique_id "aqAyMAzRRIhg6r0Q4nCaRAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 15:47:33
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.84.177.82 (82.177.84.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.84.177.82 (82.177.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 11:47:25.558937 2026] [security2:error] [pid 11201:tid 11201] [client 34.84.177.82:2744] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.menzelassociates.com"] [uri "/@fs/src/.env"] [unique_id "aqAuDcnsE_NBTVVPxdAhTwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇮
JLKnoch Software GmbH
2026-09-08 15:39:27
(7 hours ago)
CrowdSec crowdsecurity/http-path-traversal-probing
Brute-Force
Web App Attack