🇧🇪
cmbplf
2026-09-08 21:39:06
(1 day ago)
158 requests with url.path *.ssh/*
Brute-Force
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-08 20:14:46
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.84.39.173 (173.39.84.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.84.39.173 (173.39.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 16:14:41.552355 2026] [security2:error] [pid 31075:tid 31075] [client 34.84.39.173:12206] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.ashleycroft.com"] [uri "/@fs/.env.local"] [unique_id "aqBssdQQco3ohiPyuZWa3AAAACY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 19:32:15
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.84.39.173 (173.39.84.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.84.39.173 (173.39.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 15:32:08.444994 2026] [security2:error] [pid 699:tid 838] [client 34.84.39.173:1160] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.retrieversocal.com"] [uri "/@fs/.env.production"] [unique_id "aqBiuLpXjFsHUBKaXXW-VAAAAEM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 19:02:37
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.84.39.173 (173.39.84.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.84.39.173 (173.39.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 15:02:30.847264 2026] [security2:error] [pid 20345:tid 20345] [client 34.84.39.173:46082] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.alkahf.xyz"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252fapp/.env"] [unique_id "aqBbxnGfMP00DvCINjG0ZQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
blik2108
2026-09-08 18:46:23
(1 day ago)
34.84.39.173 - - [08/Sep/2026:18:46:20 +0000] "GET /@fs/.env?raw?? HTTP/1.1" 404 3431 "-" "Mozilla/5 ...
show more
34.84.39.173 - - [08/Sep/2026:18:46:20 +0000] "GET /@fs/.env?raw?? HTTP/1.1" 404 3431 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot)" "-"
34.84.39.173 - - [08/Sep/2026:18:46:20 +0000] "GET /@fs/.env.production?raw?? HTTP/1.1" 404 3431 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/118.0.6266.119 Safari/537.36; compatible; ClaudeBot/1.0; [email protected] " "-"
34.84.39.173 - - [08/Sep/2026:18:46:20 +0000] "GET /@fs/proc/self/environ?raw?? HTTP/1.1" 404 3431 "-" "Mozilla/5.0 (Linux; Android 15; SM-S918B) AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; +https://www.anthropic.com/claude-user) Chrome/131.0.8136.49 Mobile Safari/537.36" "-"
34.84.39.173 - - [08/Sep/2026:18:46:20 +0000] "GET /@fs/etc/passwd?raw?? HTTP/1.1" 404 3431 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Applebot/0.1; +http://www.apple.com/go/applebo
...
show less
Web App Attack
🇨🇭
Sonics
2026-09-08 18:31:34
(1 day ago)
Automated scanner: .env/.git/phpinfo scan
Web App Attack
🇳🇱
Site.eu
2026-09-08 17:49:42
(1 day ago)
Excessive multi-domain requests
Brute-Force
🇺🇸
TPI-Abuse
2026-09-08 17:33:15
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.84.39.173 (173.39.84.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.84.39.173 (173.39.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 13:33:07.510457 2026] [security2:error] [pid 11082:tid 11082] [client 34.84.39.173:2274] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.ohanameetup.party"] [uri "/@fs/src/.env"] [unique_id "aqBG06O8hpS_2cePMPdk8QAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Savvii
2026-09-08 17:32:20
(1 day ago)
20 attempts against mh-misbehave-ban on ceres
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-08 17:23:25
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-path-traversal-probing
Web App Attack
Hacking
🇩🇪
updown.io
2026-09-08 17:15:58
(1 day ago)
{"level":"info","ts":1788887670.9076245,"logger":"http.log.access.log0","msg":"handled request","req ...
show more
{"level":"info","ts":1788887670.9076245,"logger":"http.log.access.log0","msg":"handled request","request":{"remote_ip":"34.84.39.173","remote_port":"25794","client_ip":"34.84.39.173","proto":"HTTP/1.1","method":"GET","host":"txit.status.updown.io","uri":"/","headers":{"Accept-Encoding":["gzip"],"User-Agent":["Mozilla/5.0 (iPhone; CPU iPhone OS 17_0 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Mobile/15E148 Safari/604.1"],"Accept":["*/*"]}},"bytes_read":0,"user_id":"","duration":0.000079942,"size":0,"status":308,"resp_headers":{"Server":["Caddy"],"Connection":["close"],"Location":["https://txit.status.updown.io/"],"Content-Type":[]}}
{"level":"info","ts":1788887676.3662686,"logger":"http.log.access.log0","msg":"handled request","request":{"remote_ip":"34.84.39.173","remote_port":"17036","client_ip":"34.84.39.173","proto":"HTTP/1.1","method":"GET","host":"txit.status.updown.io","uri":"/@fs/app/rootkey.csv?raw??","headers":{"Accept-Language":["en-US,en;q=0.9"],"Acc
...
show less
DDoS Attack
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 17:03:08
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.84.39.173 (173.39.84.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.84.39.173 (173.39.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 13:03:03.354488 2026] [security2:error] [pid 26823:tid 26823] [client 34.84.39.173:11978] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.guavaroad.com"] [uri "/@fs/../../.env"] [unique_id "aqA_xzdwIHRWp7YE27w5BQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-08 17:02:04
(1 day ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
Anonymous
2026-09-08 16:39:50
(1 day ago)
Aggressive web scan
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 16:30:17
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.84.39.173 (173.39.84.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.84.39.173 (173.39.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 12:30:11.700010 2026] [security2:error] [pid 7507:tid 7507] [client 34.84.39.173:41090] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.intrialconsultants.com"] [uri "/@fs/.env.local"] [unique_id "aqA4E5yPuYaGbnbFmakG-AAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack