๐จ๐ฆ
Anytech
2026-09-04 01:55:22
(3 minutes ago)
Blocked by ConnMonitor: Bad Bot
Bad Web Bot
Spoofing
๐ธ๐ช
vaia.cloud
2026-09-04 01:55:01
(4 minutes ago)
crowdsecurity/http-admin-interface-probing
Brute-Force
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-09-04 01:20:07
(39 minutes ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-04 00:44:22
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.104.240.106 (106.240.104.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.104.240.106 (106.240.104.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 20:44:16.392589 2026] [security2:error] [pid 26206:tid 26206] [client 34.104.240.106:52984] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.luxurymicrobikini.com"] [uri "/@fs/.env"] [unique_id "apoUYB42kbilPmm9XiC_TwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-04 00:25:12
(1 hour ago)
Bot / seems abusive / Apache connections: 63
DDoS Attack
Web Spam
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-04 00:12:04
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.104.240.106 (106.240.104.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.104.240.106 (106.240.104.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 20:11:56.408904 2026] [security2:error] [pid 5086:tid 5086] [client 34.104.240.106:13468] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.khodel.info"] [uri "/@fs/.env"] [unique_id "apoMzCWFKjeWZTz2RxXVDQAAACg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
eliosbrocchi
2026-09-03 22:27:01
(3 hours ago)
34.104.240.106 - - [04/Sep/2026:00:26:58 +0200] "GET /@fs/app/rootkey.csv?raw?? HTTP/1.1" 404 816 "- ...
show more
34.104.240.106 - - [04/Sep/2026:00:26:58 +0200] "GET /@fs/app/rootkey.csv?raw?? HTTP/1.1" 404 816 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; GPTBot/1.2; +https://openai.com/gptbot"
...
show less
VPN IP
๐บ๐ธ
TPI-Abuse
2026-09-03 21:59:59
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.104.240.106 (106.240.104.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.104.240.106 (106.240.104.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 17:59:51.168647 2026] [security2:error] [pid 14132:tid 14132] [client 34.104.240.106:58456] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.leannebostwick.com"] [uri "/@fs/root/.env"] [unique_id "apnt1z9843Kx5AUCv0HaugAAADM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-03 21:13:22
(4 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐จ๐ญ
zynex
2026-09-03 21:09:04
(4 hours ago)
URL Probing: /@fs/src/.env
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-03 20:59:17
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.104.240.106 (106.240.104.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.104.240.106 (106.240.104.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 16:59:13.577102 2026] [security2:error] [pid 15738:tid 15738] [client 34.104.240.106:58902] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.thegoldentether.com"] [uri "/@fs/.env"] [unique_id "apnfoaGY2zIPCk7rG55oiwAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
alferez
2026-09-03 20:57:53
(5 hours ago)
Searching .(env|sql|zip|tar|rar) files
Hacking
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-03 20:33:02
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.104.240.106 (106.240.104.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.104.240.106 (106.240.104.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 16:32:56.542977 2026] [security2:error] [pid 24463:tid 24463] [client 34.104.240.106:5422] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.hotelkona.com"] [uri "/@fs/app/.env"] [unique_id "apnZeOaJBZifc4ju4wYrawAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
updown.io
2026-09-03 20:28:06
(5 hours ago)
{"level":"info","ts":1788467236.3143122,"logger":"http.log.access.log0","msg":"handled request","req ...
show more
{"level":"info","ts":1788467236.3143122,"logger":"http.log.access.log0","msg":"handled request","request":{"remote_ip":"34.104.240.106","remote_port":"30350","client_ip":"34.104.240.106","proto":"HTTP/1.1","method":"GET","host":"cs8q.status.updown.io","uri":"/","headers":{"User-Agent":["Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"],"Accept":["*/*"],"Accept-Encoding":["gzip"]}},"bytes_read":0,"user_id":"","duration":0.000060706,"size":0,"status":308,"resp_headers":{"Server":["Caddy"],"Connection":["close"],"Location":["https://cs8q.status.updown.io/"],"Content-Type":[]}}
{"level":"info","ts":1788467244.6480925,"logger":"http.log.access.log0","msg":"handled request","request":{"remote_ip":"34.104.240.106","remote_port":"17190","client_ip":"34.104.240.106","proto":"HTTP/1.1","method":"GET","host":"cs8q.status.updown.io","uri":"/@fs/.env.local?raw??","headers":{"User-Agent":["Mozilla/5.0 (Macintosh; Intel Mac OS X 13_6_7)
...
show less
DDoS Attack
Web App Attack
๐ณ๐ฟ
Antinson
2026-09-03 19:52:50
(6 hours ago)
Scraping with a high error ratio and request rate
Bad Web Bot