๐ฉ๐ช
Dominik Lysiak
2026-08-29 01:05:04
(2 minutes ago)
34.91.167.31 - - [29/Aug/2026:03:04:50 +0200] "GET / HTTP/1.1" 444 0 "-" "Mozilla/5.0 (X11; Linux x8 ...
show more
34.91.167.31 - - [29/Aug/2026:03:04:50 +0200] "GET / HTTP/1.1" 444 0 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36"
34.91.167.31 - - [29/Aug/2026:03:04:50 +0200] "GET / HTTP/1.1" 401 574 "-" "Mozilla/5.0 (Linux; Android 13; SM-G935R6; Build/TP1A.180718.91) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.6261.127 Mobile Safari/537.36"
34.91.167.31 - - [29/Aug/2026:03:04:54 +0200] "GET /@fs/root/.env?raw?? HTTP/1.1" 401 172 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Applebot/0.1; +http://www.apple.com/go/applebot)"
34.91.167.31 - - [29/Aug/2026:03:04:54 +0200] "GET / HTTP/1.1" 401 574 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Safari/537.36"
34.91.167.31 - - [29/Aug/2026:03:04:54 +0200] "GET /@fs/etc/passwd?raw?? HTTP/1.1" 401 172 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14.5; rv:105.2) Gecko/20100101 Firefox/105.2; compatible; fac
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 00:45:31
(22 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.91.167.31 (31.167.91.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.91.167.31 (31.167.91.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 20:45:23.358838 2026] [security2:error] [pid 23691:tid 23691] [client 34.91.167.31:36926] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.havelocktruckandauto.ca"] [uri "/@fs/root/.env"] [unique_id "apIrowKlS4KXYwdmZ5G8VwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Gwyneth Llewelyn
2026-08-29 00:31:14
(36 minutes ago)
2026/08/29 01:31:12 [error] 380594#380594: *1237244 access forbidden by rule, client: 34.91.167.31, ...
show more
2026/08/29 01:31:12 [error] 380594#380594: *1237244 access forbidden by rule, client: 34.91.167.31, server: regapi.betatechnologies.info, request: "GET /.docker/.env HTTP/1.1", host: "regapi.betatechnologies.info"
2026/08/29 01:31:12 [error] 380595#380595: *1237245 access forbidden by rule, client: 34.91.167.31, server: regapi.betatechnologies.info, request: "GET /v2/.env HTTP/1.1", host: "regapi.betatechnologies.info"
2026/08/29 01:31:12 [error] 380594#380594: *1237243 access forbidden by rule, client: 34.91.167.31, server: regapi.betatechnologies.info, request: "GET /_nuxt/../.env HTTP/1.1", host: "regapi.betatechnologies.info"
show less
Brute-Force
Web App Attack
๐ณ๐ฑ
middelkoopcc
2026-08-29 00:31:01
(36 minutes ago)
2026-08-29 02:29:05 GET /@fs/proc/self/environ?raw?? [301] && 2026-08-29 02:29:05 GET /@fs/home/node ...
show more
2026-08-29 02:29:05 GET /@fs/proc/self/environ?raw?? [301] && 2026-08-29 02:29:05 GET /@fs/home/node/.aws/config?raw?? [301] && 2026-08-29 02:29:05 GET /@fs/root/.aws/credentials.backup?raw?? [301] && 142 more within 20 minutes
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 00:19:09
(48 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.91.167.31 (31.167.91.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.91.167.31 (31.167.91.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 20:19:04.999492 2026] [security2:error] [pid 14370:tid 14370] [client 34.91.167.31:14258] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.bjennehall.com"] [uri "/@fs/app/.env"] [unique_id "apIleE8cMtx6y4hcotSIxAAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alboweb B.V.
2026-08-29 00:11:10
(56 minutes ago)
Bad web bot activity detected by Fail2Ban in plesk-apache-badbot jail
Bad Web Bot
๐ซ๐ท
Octopuce
2026-08-28 23:22:27
(1 hour ago)
Aggressive web search of vulnerable pages: /assets../.env /.env /v1/.env /v2/.env /.docker/.env ...
Web App Attack
๐ฎ๐น
VHosting
2026-08-28 23:20:05
(1 hour ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐ธ๐ช
vaia.cloud
2026-08-28 23:20:03
(1 hour ago)
crowdsecurity/http-probing
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 22:56:41
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.91.167.31 (31.167.91.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.91.167.31 (31.167.91.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 18:56:36.911056 2026] [security2:error] [pid 31296:tid 31296] [client 34.91.167.31:39452] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.peterjohnsonauthor.com"] [uri "/@fs/root/.env"] [unique_id "apISJMPBQZIVM0pgS5w2LQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 22:32:09
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.91.167.31 (31.167.91.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.91.167.31 (31.167.91.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 18:32:01.551972 2026] [security2:error] [pid 32380:tid 32380] [client 34.91.167.31:48036] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.zebax.com"] [uri "/@fs/.env"] [unique_id "apIMYUPp0OKHmDNm-HoAdwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack