๐จ๐ฆ
polycoda
2026-08-28 13:00:58
(33 minutes ago)
AutoBlock: ๐ฏ Vulnerability Scanner (Non Decay-Based)
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
snappic
2026-08-28 12:14:20
(1 hour ago)
Scanning for config [GET /config.json.js] [Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compat ...
show more
Scanning for config [GET /config.json.js] [Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; WhatsApp/10.0.2.1)]
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
leasj
2026-08-28 11:50:28
(1 hour ago)
Observed Scanned 86 known-sensitive endpoint(s), e.g.: /@fs/.env?raw??, /@fs/app/.env?raw??, /@fs/.. ...
show more
Observed Scanned 86 known-sensitive endpoint(s), e.g.: /@fs/.env?raw??, /@fs/app/.env?raw??, /@fs/..%2f..%2f..%2f..%2f..%2froot/.env?raw??, /.env?raw??, /@fs/src/.env?raw??.
show less
Hacking
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-08-28 10:40:13
(2 hours ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 35.252.141.151 (US/United States/151. ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 35.252.141.151 (US/United States/151.141.252.35.bc.googleusercontent.com): 2 in the last 3600 secs (0-196)
show less
Hacking
๐จ๐ญ
zynex
2026-08-28 09:02:56
(4 hours ago)
URL Probing: /@fs/var/www/.env
Web App Attack
๐ณ๐ฑ
ConsulHosting
2026-08-28 08:59:36
(4 hours ago)
Automatically blocked due to distributed attack
Hacking
๐ฆ๐น
penguin-solutions.at
2026-08-28 07:59:47
(5 hours ago)
Excessive 403/404 errors
...
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 07:28:32
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.252.141.151 (151.141.252.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.252.141.151 (151.141.252.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 03:28:26.979433 2026] [security2:error] [pid 859:tid 859] [client 35.252.141.151:43320] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "katzcreationz.celtickyss.com"] [uri "/@fs/.env"] [unique_id "apE4mtAVJ3IHMkUq9VItGgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 06:45:36
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.252.141.151 (151.141.252.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.252.141.151 (151.141.252.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 02:45:29.043913 2026] [security2:error] [pid 13592:tid 13592] [client 35.252.141.151:26492] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.guardmagic.com"] [uri "/@fs/root/.env"] [unique_id "apEuietE2f6TSTIpX762twAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
snappic
2026-08-28 06:01:49
(7 hours ago)
Scanning for config [GET /config.json.js] [Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compat ...
show more
Scanning for config [GET /config.json.js] [Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; [email protected] )]
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 05:46:53
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.252.141.151 (151.141.252.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.252.141.151 (151.141.252.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 01:46:48.809929 2026] [security2:error] [pid 1465:tid 1465] [client 35.252.141.151:59602] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.tracybur.net"] [uri "/@fs/.env"] [unique_id "apEgyHqrsZxUCfx9LZpyuwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Baking333
2026-08-28 05:38:25
(7 hours ago)
[redacted] 35.252.141.151 - - [28/Aug/2026:06:38:23 +0100] "GET /@fs/home/node/.aws/credentials?raw? ...
show more
[redacted] 35.252.141.151 - - [28/Aug/2026:06:38:23 +0100] "GET /@fs/home/node/.aws/credentials?raw?? HTTP/1.1" 302 1564 0/68151 "-" "Mozilla/5.0 (compatible; Google-Extended/1.0; +http://[redacted]/[redacted])" [redacted] 35.252.141.151 - - [28/Aug/2026:06:38:23 +0100] "GET /@fs/..%252f..%252f..%252f..%252f..%252froot/.env?raw?? HTTP/1.1" 302 1564 0/74985 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; Google-Extended/1.0; +http://[redacted]/[redacted]"
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 05:24:39
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.252.141.151 (151.141.252.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.252.141.151 (151.141.252.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 01:24:34.718279 2026] [security2:error] [pid 18541:tid 18575] [client 35.252.141.151:31316] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.attorneylouisiana.com"] [uri "/@fs/src/.env"] [unique_id "apEbkmG8VyGirw4uykfoUgAAAFU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฑ๐น
NotACaptcha
2026-08-28 05:21:41
(8 hours ago)
webserver:80 [28/Aug/2026] "GET / HTTP/1.1" 200 396 "-" "Mozilla/5.0 (Linux; Android 8; Mi 8 Explor ...
show more
webserver:80 [28/Aug/2026] "GET / HTTP/1.1" 200 396 "-" "Mozilla/5.0 (Linux; Android 8; Mi 8 Explorer Edition; Build/OPM3.221001.211) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/130.0.6723.101 Mobile Safari/537.36"
webserver:443 [28/Aug/2026] "GET /@fs/root/.config/gcloud/credentials.db?raw?? HTTP/1.1" 404 5442 "-" "Mozilla/5.0 (compatible; Bytespider; +https://zhanzhang.toutiao.com/)"
webserver:443 [28/Aug/2026] "GET /@fs/home/ubuntu/.oci/config?raw?? HTTP/1.1" 404 5442 "-" "Mozilla/5.0 (Windows NT 11.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko; compatible; TelegramBot/1.0) Chrome/122.0.1729.204 Safari/537.36"
webserver:443 [28/Aug/2026] "GET /@fs/root/.vultr-cli.yaml?raw?? HTTP/1.1" 404 5442 "-" "Mozilla/5.0 (Windows NT 11.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.1206.150 Safari/537.36 Edg/128.0.1206.150; compatible; GrokBot/1.0; +https://x.ai/grokbot"
webserver:443 [28/Aug/2026] "GET /@fs/home/ubuntu/.config/gcloud/application_default_creden...
show less
Web App Attack
๐จ๐ญ
๐จ๐ญ Hosting
2026-08-28 05:10:33
(8 hours ago)
Automated WAF report: 200-300 blocked requests from this IP detected by our WAF.
Bad Web Bot
Web App Attack