๐ง๐ช
cmbplf
2026-10-03 02:42:12
(5 minutes ago)
120 requests with url.path */@fs/*
Brute-Force
Bad Web Bot
๐ฌ๐ท
setupgr
2026-10-03 01:55:01
(52 minutes ago)
(mod_security) mod_security (id:11000010) triggered by 34.104.188.229 (JP/Japan/Tokyo/Tokyo/-/[AS396 ...
show more
(mod_security) mod_security (id:11000010) triggered by 34.104.188.229 (JP/Japan/Tokyo/Tokyo/-/[AS396982 Google LLC]): 1 in the last 86400 secs (CF_ENABLE); Ports: *; Direction: inout; Trigger: LF_MODSEC; Logs: [Sat Oct 03 04:54:59.414330 2026] [security2:error] [pid 2909019:tid 2909083] [remote 34.104.188.229:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "+claudebot" at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec/modsec2.user.conf"] [line "114"] [id "11000010"] [msg "BLOCKED BOT: +claudebot on santoriniicon.com"] [severity "ALERT"] [hostname "santoriniicon.com"] [uri "/z9x8c7v6b5-debug-trigger-santoriniicon.com"] [unique_id "asBgcwz-7jdlC89n9SXPEwAEQA0"]
show less
Port Scan
๐ฉ๐ช
lespbaj
2026-10-03 00:52:34
(1 hour ago)
{"time":"2026-10-03T00:52:33+00:00","ip":"34.104.188.229","method":"GET","uri":"/.env","ua":"Mozilla ...
show more
{"time":"2026-10-03T00:52:33+00:00","ip":"34.104.188.229","method":"GET","uri":"/.env","ua":"Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexitybot)","referer":""}
...
show less
Bad Web Bot
Web App Attack
๐ฌ๐ท
setupgr
2026-10-02 23:11:30
(3 hours ago)
(mod_security) mod_security (id:11000010) triggered by 34.104.188.229 (JP/Japan/Tokyo/Tokyo/-/[AS396 ...
show more
(mod_security) mod_security (id:11000010) triggered by 34.104.188.229 (JP/Japan/Tokyo/Tokyo/-/[AS396982 Google LLC]): 1 in the last 86400 secs (CF_ENABLE); Ports: *; Direction: inout; Trigger: LF_MODSEC; Logs: [Sat Oct 03 02:11:26.171969 2026] [security2:error] [pid 2615260:tid 2615336] [remote 34.104.188.229:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "DeepSeekBot" at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec/modsec2.user.conf"] [line "114"] [id "11000010"] [msg "BLOCKED BOT: DeepSeekBot on www.santoriniicon.com"] [severity "ALERT"] [hostname "www.santoriniicon.com"] [uri "/z9x8c7v6b5-debug-trigger-www.santoriniicon.com"] [unique_id "asA6HnbN-fusySk4AnrAFQADxRU"]
show less
Port Scan
๐ธ๐ฌ
crimefireNOC
2026-10-02 22:26:54
(4 hours ago)
[waf.lfi.php_filter] waf.lfi.php_filter on https://manakmewa.com via GET (action: ban+403)
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 16:35:08
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.104.188.229 (229.188.104.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.104.188.229 (229.188.104.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 12:35:01.054661 2026] [security2:error] [pid 22421:tid 22421] [client 34.104.188.229:42656] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.loneoakhoney.com"] [uri "/.env.dev"] [unique_id "ar_dNZiOiDBGBsOEvKIUyQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 16:11:48
(10 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.104.188.229 (229.188.104.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 34.104.188.229 (229.188.104.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 12:11:42.151436 2026] [security2:error] [pid 14056:tid 14056] [client 34.104.188.229:34692] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.saudigreenrecycling.com|F|2"] [data ".saudigreenrecycling.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.saudigreenrecycling.com"] [uri "/z9x8c7v6b5-debug-trigger-www.saudigreenrecycling.com"] [unique_id "ar_XvhWU-Q2vJ6goy3ReZAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-10-02 15:52:03
(10 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
antlac1
2026-10-02 15:43:31
(11 hours ago)
crowdsecurity/http-path-traversal-probing
Brute-Force
Web App Attack
๐ฉ๐ช
LRob
2026-10-02 14:55:54
(11 hours ago)
Wordlist path sweep | method: POST, GET | path: /lib/terminal-xhr.php, /ygetaypzxm5b5eq2wfcj, /manif ...
show more
Wordlist path sweep | method: POST, GET | path: /lib/terminal-xhr.php, /ygetaypzxm5b5eq2wfcj, /manifest.json (+4 more) | ua: Mozilla/5.0 (compatible; Meta-ExternalAgent/1.0; +https://developers.facebook.com/docs/sharing/webmasters/crawler), Mozilla/5.0 (compatible; Hunyuan/1.0; +https://hunyuan.tencent.com/), Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36 Edg/152.0.0.0 (+3 more)
show less
Port Scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 14:39:39
(12 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.104.188.229 (229.188.104.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 34.104.188.229 (229.188.104.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 10:39:35.706954 2026] [security2:error] [pid 8012:tid 8037] [client 34.104.188.229:41018] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||joeandlane.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "joeandlane.com"] [uri "/z9x8c7v6b5-debug-trigger-joeandlane.com"] [unique_id "ar_CJ8che2yC4qf5aNcARgAAAVI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
IndigoRidge
2026-10-02 14:16:51
(12 hours ago)
34.104.188.229 - - [02/Oct/2026:10:16:47 -0400] "GET /static//home/user/.env HTTP/1.1" 403 5511 "-" ...
show more
34.104.188.229 - - [02/Oct/2026:10:16:47 -0400] "GET /static//home/user/.env HTTP/1.1" 403 5511 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Safari/605.1.15 (Applebot/0.1)"
34.104.188.229 - - [02/Oct/2026:10:16:49 -0400] "GET /static../.env HTTP/1.1" 403 5511 "-" "Mozilla/5.0 (compatible; PanguBot/1.0; +https://www.huaweicloud.com/)"
34.104.188.229 - - [02/Oct/2026:10:16:51 -0400] "GET /media../.env HTTP/1.1" 403 5511 "-" "CCBot/2.0 (https://commoncrawl.org/faq/)"
...
show less
Web App Attack
๐บ๐ธ
kbeezie
2026-10-02 14:03:41
(12 hours ago)
34.104.188.229 - - [02/Oct/2026:10:03:41 -0400] "GET /auth HTTP/1.1" 429 564 "-" "Mozilla/5.0 (Linux ...
show more
34.104.188.229 - - [02/Oct/2026:10:03:41 -0400] "GET /auth HTTP/1.1" 429 564 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Mobile Safari/537.36"
34.104.188.229 - - [02/Oct/2026:10:03:41 -0400] "GET /account/login HTTP/1.1" 429 564 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Mobile Safari/537.36"
34.104.188.229 - - [02/Oct/2026:10:03:41 -0400] "GET /users/login HTTP/1.1" 429 564 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Mobile Safari/537.36"
34.104.188.229 - - [02/Oct/2026:10:03:41 -0400] "GET /6hljny0wns5ts977oz6b HTTP/1.1" 429 162 "https://www.karlblessing.com/6hljny0wns5ts977oz6b" "Mozilla/5.0 (compatible; PanguBot/1.0; +https://www.huaweicloud.com/)"
34.104.188.229 - - [02/Oct/2026:10:03:41 -0400] "GET /signup HTTP/1.1" 429 564 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Mobile Safari/537.36"
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 13:55:05
(12 hours ago)
(mod_security) mod_security (id:243320) triggered by 34.104.188.229 (229.188.104.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:243320) triggered by 34.104.188.229 (229.188.104.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 09:54:59.671249 2026] [security2:error] [pid 16246:tid 16246] [client 34.104.188.229:50402] ModSecurity: Access denied with code 403 (phase 2). String match "/.profile" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "6621"] [id "243320"] [rev "1"] [msg "COMODO WAF: Information disclosure vulnerability in Cloud Foundry PHP Buildpack (aka php-buildpack) before 4.3.18 and PHP Buildpack Cf-release before 242, as used in Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.6.38 and 1.7.x before 1.7.19 and other products (CVE-2016-6639)||samimartin.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "samimartin.com"] [uri "/.profile"] [unique_id "ar-3s-2ulFoyzHK5cz89eQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
rh24
2026-10-02 13:14:10
(13 hours ago)
(badbots) Bad bot user-agent [redacted] from 34.104.188.229 (JP/Japan/229.188.104.34.bc.googleuserco ...
show more
(badbots) Bad bot user-agent [redacted] from 34.104.188.229 (JP/Japan/229.188.104.34.bc.googleusercontent.com)
show less
Hacking