๐ง๐ช
cmbplf
2026-09-08 22:28:27
(2 days ago)
1.521 requests with url.path */@fs/*
717 requests with url.path *.env
442 requests with url.path ...
show more
1.521 requests with url.path */@fs/*
717 requests with url.path *.env
442 requests with url.path *.aws/*
294 requests with url.path *credentials.json
292 requests with url.path *.config/*
162 requests with url.path */proc/*
show less
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-08 19:55:48
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.84.50.202 (202.50.84.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.84.50.202 (202.50.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 15:55:40.530100 2026] [security2:error] [pid 5166:tid 5246] [client 34.84.50.202:53578] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.pattinauction.com"] [uri "/@fs/src/.env"] [unique_id "aqBoPIwz1fJYo7FObpg-zQAAAVY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-09-08 19:39:04
(2 days ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-08 19:26:16
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.84.50.202 (202.50.84.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.84.50.202 (202.50.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 15:26:10.193853 2026] [security2:error] [pid 11892:tid 11892] [client 34.84.50.202:27224] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.guavaroad.com"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252fapp/.env"] [unique_id "aqBhUgTKOeEK3n6Rwdhh7AAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-08 19:10:59
(2 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-08 19:09:39
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.84.50.202 (202.50.84.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.84.50.202 (202.50.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 15:09:32.190352 2026] [security2:error] [pid 133685:tid 133777] [client 34.84.50.202:16268] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wijaya.biz"] [uri "/@fs/.env"] [unique_id "aqBdbC9LffOl39NJj_pAbwAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ช
vaia.cloud
2026-09-08 19:05:01
(2 days ago)
crowdsecurity/http-probing
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-08 18:43:54
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.84.50.202 (202.50.84.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.84.50.202 (202.50.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 14:43:49.070354 2026] [security2:error] [pid 30190:tid 30190] [client 34.84.50.202:16404] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.rantell.net"] [uri "/@fs/root/.env"] [unique_id "aqBXZSJROZwnpyfSppOJmwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
[email protected]
2026-09-08 18:43:41
(2 days ago)
PrestaShop Security Module: suspicious probe path detected (/.env)
Web App Attack
๐ซ๐ท
Octopuce
2026-09-08 18:00:35
(2 days ago)
Aggressive web search of vulnerable pages: /.docker/.env /v2/.env /v1/.env /images../.env /.env ...
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-08 17:22:06
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.84.50.202 (202.50.84.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.84.50.202 (202.50.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 13:22:00.995884 2026] [security2:error] [pid 14968:tid 14968] [client 34.84.50.202:34042] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.anythingsoldworldwide.deckmasterscompany.com"] [uri "/@fs/.env.production"] [unique_id "aqBEOGLJUGd3tDQkvMvgTwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-08 17:09:39
(2 days ago)
Aggressive web scan
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-09-08 16:50:07
(2 days ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-08 16:49:05
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.84.50.202 (202.50.84.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.84.50.202 (202.50.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 12:48:58.748159 2026] [security2:error] [pid 3898152:tid 3898152] [client 34.84.50.202:11948] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.azpinklimos.com"] [uri "/@fs/root/.env"] [unique_id "aqA8emgieT0xMsjZQPeuoQAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
netman
2026-09-08 16:36:45
(2 days ago)
34.84.50.202 www.job-market.net - [08/Sep/2026:16:36:43 +0000] "GET /@fs/home/ubuntu/.openai/config. ...
show more
34.84.50.202 www.job-market.net - [08/Sep/2026:16:36:43 +0000] "GET /@fs/home/ubuntu/.openai/config.json?raw?? HTTP/1.1" 404 341 "-" "Mozilla/5.0 (compatible; OAI-SearchBot/1.4; robots.txt; +https://openai.com/searchbot)"
34.84.50.202 www.job-market.net - [08/Sep/2026:16:36:43 +0000] "GET /@fs/home/ubuntu/.config/anthropic/credentials/default.json?raw?? HTTP/1.1" 404 341 "-" "Mozilla/5.0 (compatible; meta-externalagent/1.1; +https://developers.facebook.com/docs/sharing/webmasters/crawler)"
34.84.50.202 www.job-market.net - [08/Sep/2026:16:36:43 +0000] "GET /@fs/root/.config/openai/config.json?raw?? HTTP/1.1" 404 341 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko; compatible; TelegramBot/1.0) Chrome/122.0.5700.138 Safari/537.36 Edg/122.0.5700.138"
34.84.50.202 www.job-market.net - [08/Sep/2026:16:36:43 +0000] "GET /@fs/proc/self/cwd/.env?raw?? HTTP/1.1" 404 341 "-" "Mozilla/5.0 (Windows NT 10.0; rv:132.19) Gecko/20100101 Firefox/132.19; compatible; GPTBot/1.2
...
show less
DDoS Attack
Web App Attack