🇬🇧
consul.to
2026-09-12 22:25:56
(3 hours ago)
Web attack/malicious scanning detected
Web App Attack
🇺🇸
Charlesiv
2026-09-12 22:02:18
(4 hours ago)
Triggered Cloudflare WAF (firewallCustom) from TW.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Prot ...
show more
Triggered Cloudflare WAF (firewallCustom) from TW.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Protocol: HTTP/2 (GET method)
Endpoint: /manage/env
Timestamp: 2026-09-12T20:15:33Z
Ray ID: a3a195b83b674a24
UA: Mozilla/5.0 (compatible; Hunyuan/1.0; +https://hunyuan.tencent.com/)
show less
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-12 18:57:41
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 107.167.179.48 (48.179.167.107.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 107.167.179.48 (48.179.167.107.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 14:57:38.403213 2026] [security2:error] [pid 12489:tid 12489] [client 107.167.179.48:38288] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.cmcnow.net"] [uri "/%2E%2E/%2E%2E/%2E%2E/%2E%2E/.env"] [unique_id "aqWgogVnpMbogN073TtDKAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 06:09:29
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 107.167.179.48 (48.179.167.107.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 107.167.179.48 (48.179.167.107.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 02:09:20.205961 2026] [security2:error] [pid 20917:tid 20917] [client 107.167.179.48:49442] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.carbonless.net"] [uri "/@fs/proc/self/cwd/.env"] [unique_id "aqTskMLIyFUjryE4_7wqLQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
Charlesiv
2026-09-12 00:19:30
(1 day ago)
Triggered Cloudflare WAF (firewallCustom) from TW.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Prot ...
show more
Triggered Cloudflare WAF (firewallCustom) from TW.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Protocol: HTTP/2 (GET method)
Endpoint: /@fs/var/run/secrets/kubernetes.io/serviceaccount/token
Query: ?raw??
Timestamp: 2026-09-11T20:23:29Z
Ray ID: a39963f6aed44a94
UA: Mozilla/5.0 (compatible; YouBot/1.0; +https://you.com/bot)
show less
Bad Web Bot
Anonymous
2026-09-11 21:22:15
(1 day ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
🇺🇸
nyt
2026-09-11 19:12:39
(1 day ago)
GraphQL Probe
Web App Attack
Anonymous
2026-09-11 18:42:58
(1 day ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
🇺🇸
Charlesiv
2026-09-11 18:02:04
(1 day ago)
Triggered Cloudflare WAF (firewallCustom) from TW.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Prot ...
show more
Triggered Cloudflare WAF (firewallCustom) from TW.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Protocol: HTTP/2 (GET method)
Endpoint: /telescope/requests
Timestamp: 2026-09-11T16:38:16Z
Ray ID: a3981a13b97c302a
UA: Mozilla/5.0 (compatible; PanguBot/1.0; +https://www.huaweicloud.com/)
show less
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-11 17:46:51
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 107.167.179.48 (48.179.167.107.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 107.167.179.48 (48.179.167.107.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 13:46:46.666520 2026] [security2:error] [pid 6653:tid 6674] [client 107.167.179.48:41090] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||coldwave.net|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "coldwave.net"] [uri "/rclone.conf"] [unique_id "aqQ-hpheESlYQguXcmSzDgAAANM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
masterguru
2026-09-11 17:38:14
(1 day ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-195)
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 17:26:07
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 107.167.179.48 (48.179.167.107.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 107.167.179.48 (48.179.167.107.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 13:25:59.585422 2026] [security2:error] [pid 11905:tid 11905] [client 107.167.179.48:57082] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "clip24.net"] [uri "/%2E%2E/%2E%2E/%2E%2E/%2E%2E/.env"] [unique_id "aqQ5p_yi1MYvXnIAUiTsLwAAACQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
LRob
2026-09-11 17:23:58
(1 day ago)
Declared crawler ignoring robots.txt and the refusals it is given | ua: Mozilla/5.0 AppleWebKit/537. ...
show more
Declared crawler ignoring robots.txt and the refusals it is given | ua: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; [email protected] ) (+1 more) | path: /.//.env (+5 more) | 2026-09-11 17:23 UTC
show less
Bad Web Bot
🇬🇧
consul.to
2026-09-11 17:23:00
(1 day ago)
Web attack/malicious scanning detected
Web App Attack
🇳🇱
Alboweb B.V.
2026-09-11 17:11:05
(1 day ago)
Bad web bot activity detected by Fail2Ban in plesk-apache-badbot jail
Bad Web Bot