🇪🇸
alferez
2026-08-29 22:52:50
(2 weeks ago)
Searching .(env|sql|zip|tar|rar) files
Hacking
Exploited Host
Web App Attack
🇫🇷
tecnicorioja
2026-08-29 22:02:36
(2 weeks ago)
(Mod_security)
Web App Attack
Brute-Force
Bad Web Bot
🇬🇷
setupgr
2026-08-29 18:14:29
(2 weeks ago)
(mod_security) mod_security (id:990005) triggered by 34.87.112.246 (SG/Singapore/-/Singapore/-/[AS39 ...
show more
(mod_security) mod_security (id:990005) triggered by 34.87.112.246 (SG/Singapore/-/Singapore/-/[AS396982 GOOGLE-CLOUD-PLATFORM]): 1 in the last 86400 secs (CF_ENABLE); Ports: *; Direction: inout; Trigger: LF_MODSEC; Logs: [Sat Aug 29 21:14:25.235786 2026] [security2:error] [pid 965499:tid 965534] [client 34.87.112.246:44916] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "oai-searchbot" at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec/modsec2.user.conf"] [line "159"] [id "990005"] [msg "Blocked AI Scraper from Google Cloud Platform"] [hostname "babis.photo"] [uri "/@fs/src/.env"] [unique_id "apMhgYupa3wNUVNYV4OnBwAAAQg"]
show less
Port Scan
🇬🇧
OptimusGO
2026-08-29 18:06:33
(2 weeks ago)
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Time ...
show more
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Timestamp: 2026-08-29 19:06:33 UTC
Log evidence:
34.87.112.246 - - [29/Aug/2026:19:06:27 +0100] "GET / HTTP/1.1" 301 162 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
08/29/2026-19:06:32.579886 [wDrop] [**] [1:7000500:1] FINSERV CRITICAL: Aggressive Port Scan [**] [Classification: Attempted Information Leak] [Priority: 2] {TCP} 34.87.112.246:34796 -> 185.127.18.66:443
08/29/2026-19:06:32.610704 [**] [1:9000060:2] AUTONOMOUS Long-term Reconnaissance [**] [Classification: (null)] [Priority: 2] {TCP} 34.87.112.246:34948 -> 185.127.18.66:443
show less
Port Scan
Brute-Force
🇺🇸
TPI-Abuse
2026-08-29 16:01:34
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.87.112.246 (246.112.87.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.87.112.246 (246.112.87.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 12:01:29.215443 2026] [security2:error] [pid 11657:tid 11657] [client 34.87.112.246:11636] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.cwchamber.com"] [uri "/@fs/.env"] [unique_id "apMCWQI5Mf9B6Pad3AdJRAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-29 14:52:50
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.87.112.246 (246.112.87.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.87.112.246 (246.112.87.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 10:52:44.508026 2026] [security2:error] [pid 10635:tid 10635] [client 34.87.112.246:51948] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "agchurchkuwait.com"] [uri "/@fs/app/.env"] [unique_id "apLyPEZrbFpidbV_3cXvGgAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇿🇦
conure.sh
2026-08-29 12:01:37
(2 weeks ago)
csagent: score 20.5: 404 noise floor x2, secrets grab x2; 2 domain(s) in 7s
Web App Attack
🇳🇿
Antinson
2026-08-29 11:57:06
(2 weeks ago)
Scraping with a high error ratio and request rate
Bad Web Bot
🇺🇸
TPI-Abuse
2026-08-29 11:28:10
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.87.112.246 (246.112.87.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.87.112.246 (246.112.87.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 07:28:02.974275 2026] [security2:error] [pid 12248:tid 12248] [client 34.87.112.246:30654] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ultratec.com.mx.activethinkers.net"] [uri "/@fs/src/.env"] [unique_id "apLCQmJYoUGnOr2KqYNs0AAAADA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇮
000rosiu
2026-08-29 11:27:34
(2 weeks ago)
Triggered Cloudflare WAF (firewallCustom) from SG.
Action: BLOCK | Protocol: HTTP/1.1 (GET) | Endpoi ...
show more
Triggered Cloudflare WAF (firewallCustom) from SG.
Action: BLOCK | Protocol: HTTP/1.1 (GET) | Endpoint: /.openclaw/.env | UA: Mozilla/5.0 (compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot) • Generated by: github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
🇨🇦
Sakusen
2026-08-29 08:46:00
(2 weeks ago)
Automated web attack: 340 reqs, 269 paths probed, 319 returned 404; probed: 77 .env, 47 .json, 44 ot ...
show more
Automated web attack: 340 reqs, 269 paths probed, 319 returned 404; probed: 77 .env, 47 .json, 44 other, 36 cloud-cred, 24 secret, 11 ssh-key, 9 config, 8 .php, 7 .yml, 5 .git, 1 .jsp
show less
Hacking
Bad Web Bot
Web App Attack
🇸🇪
vaia.cloud
2026-08-29 08:20:03
(2 weeks ago)
crowdsecurity/http-path-traversal-probing
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-08-29 07:30:17
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.87.112.246 (246.112.87.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.87.112.246 (246.112.87.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 03:30:12.639416 2026] [security2:error] [pid 19104:tid 19104] [client 34.87.112.246:62518] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.campbellsclan.com"] [uri "/@fs/.env"] [unique_id "apKKhKXDiKr_S3J3w5UwdgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-29 07:12:06
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.87.112.246 (246.112.87.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.87.112.246 (246.112.87.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 03:12:02.341686 2026] [security2:error] [pid 25678:tid 25678] [client 34.87.112.246:51084] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.steamboatrowena.com"] [uri "/@fs/root/.env"] [unique_id "apKGQpVf83dSWTLloCjiygAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
Octopuce
2026-08-29 06:59:35
(2 weeks ago)
Aggressive web search of vulnerable pages: /_nuxt/../.env /v1/.env /v2/.env /images../.env /admin/.e ...
show more
Aggressive web search of vulnerable pages: /_nuxt/../.env /v1/.env /v2/.env /images../.env /admin/.env ...
show less
Web App Attack