๐บ๐ธ
TPI-Abuse
2026-10-05 04:06:46
(48 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.107.4.44 (44.4.107.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.107.4.44 (44.4.107.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 00:06:38.740876 2026] [security2:error] [pid 22795:tid 22795] [client 34.107.4.44:50524] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wildimaginings.org"] [uri "/static../.env"] [unique_id "asMiTlU9GyZxOdAWhL3ojgAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-05 03:51:31
(1 hour ago)
34.107.4.44 detected on srv01
Brute-Force
Anonymous
2026-10-05 03:35:52
(1 hour ago)
Fail2Ban apache-noscript
Bad Web Bot
๐ฒ๐พ
Rizzy
2026-10-05 03:27:34
(1 hour ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐ฉ๐ช
Gwyneth Llewelyn
2026-10-05 03:24:49
(1 hour ago)
2026/10/05 04:24:47 [error] 3069275#3069275: *131602 access forbidden by rule, client: 34.107.4.44, ...
show more
2026/10/05 04:24:47 [error] 3069275#3069275: *131602 access forbidden by rule, client: 34.107.4.44, server: simetria.org, request: "GET /public../.env HTTP/2.0", host: "simetria.org"
2026/10/05 04:24:47 [error] 3069276#3069276: *131603 access forbidden by rule, client: 34.107.4.44, server: simetria.org, request: "GET /img../.env HTTP/2.0", host: "simetria.org"
2026/10/05 04:24:47 [error] 3069275#3069275: *131604 access forbidden by rule, client: 34.107.4.44, server: simetria.org, request: "GET /images../.env HTTP/2.0", host: "simetria.org"
show less
Brute-Force
Web App Attack
Anonymous
2026-10-05 03:19:05
(1 hour ago)
34.107.4.44 - - [04/Oct/2026:22:19:04 -0500] "GET /.env?import&raw HTTP/1.1" 403 199 "-" "Mozilla/5. ...
show more
34.107.4.44 - - [04/Oct/2026:22:19:04 -0500] "GET /.env?import&raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; PanguBot/1.0; +https://www.huaweicloud.com/)" 34.107.4.44
34.107.4.44 - - [04/Oct/2026:22:19:04 -0500] "GET /.env.production?import&raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; MistralAI-User/1.0; +https://mistral.ai/)" 34.107.4.44
34.107.4.44 - - [04/Oct/2026:22:19:04 -0500] "GET /.env?raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36; compatible; OAI-SearchBot/1.4; +https://openai.com/searchbot" 34.107.4.44
34.107.4.44 - - [04/Oct/2026:22:19:04 -0500] "GET /.env.local?import&raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; Bytespider; [email protected] ) AppleWebKit/537.36" 34.107.4.44
34.107.4.44 - - [04/Oct/2026:22:19:04 -0500] "GET /.env.production?raw HTTP/1.1" 403 199 "-" "CCBot/2.0 (https://commoncrawl.org/faq/)" 34.107.4.44
34.107.4.44 - - [04/Oct/20
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 02:55:23
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.107.4.44 (44.4.107.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.107.4.44 (44.4.107.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 22:55:18.660693 2026] [security2:error] [pid 15709:tid 15709] [client 34.107.4.44:58600] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ohleap.org"] [uri "/build../.env"] [unique_id "asMRliWEhRTOmuJkLf56RwAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 02:40:06
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.107.4.44 (44.4.107.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.107.4.44 (44.4.107.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 22:39:57.005936 2026] [security2:error] [pid 26056:tid 26056] [client 34.107.4.44:35784] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "montepulciano.org"] [uri "/app/.env"] [unique_id "asMN_WxCpg7--ORT0GtxegAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
konseptit
2026-10-05 02:35:35
(2 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 34.107.4.44 (DE/Germany/44.4.107.34.bc. ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.107.4.44 (DE/Germany/44.4.107.34.bc.googleusercontent.com)
show less
SQL Injection
๐ณ๐ฑ
melroy89
2026-10-05 02:26:43
(2 hours ago)
34.107.4.44 - - [05/Oct/2026:04:26:34 +0200] "GET /fvze0r27qgb3qcuojhw7 HTTP/2.0" 403 93 "-" "Mozil ...
show more
34.107.4.44 - - [05/Oct/2026:04:26:34 +0200] "GET /fvze0r27qgb3qcuojhw7 HTTP/2.0" 403 93 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot)" "libreweb.org" 0.001
34.107.4.44 - - [05/Oct/2026:04:26:34 +0200] "GET /vgmx6dm74uy1ao2qdiwf HTTP/2.0" 403 93 "-" "CCBot/2.0 (https://commoncrawl.org/faq/)" "libreweb.org" 0.000
34.107.4.44 - - [05/Oct/2026:04:26:34 +0200] "GET /z9x8c7v6b5-debug-trigger-libreweb.org HTTP/2.0" 403 93 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; GPTBot/1.4; +https://openai.com/gptbot" "libreweb.org" 0.001
34.107.4.44 - - [05/Oct/2026:04:26:34 +0200] "POST / HTTP/2.0" 403 93 "-" "Mozilla/5.0 (compatible; YouBot/1.0; +https://you.com/bot)" "libreweb.org" 0.001
34.107.4.44 - - [05/Oct/2026:04:26:34 +0200] "GET /assets/manifest.json HTTP/2.0" 403 64 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Mobile Safari/537.36" "li
...
show less
Web App Attack
๐ฎ๐น
VHosting
2026-10-05 02:25:03
(2 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐ซ๐ฎ
Kotisivu.org
2026-10-05 02:22:12
(2 hours ago)
Automated web scanner probe: GET /.ssh/id_rsa on kotisivu.org.
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 02:21:43
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.107.4.44 (44.4.107.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.107.4.44 (44.4.107.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 22:21:35.791475 2026] [security2:error] [pid 7903:tid 7903] [client 34.107.4.44:50910] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "knowbuddy.org"] [uri "/api/fs/read"] [unique_id "asMJryoiyeedhLmcGvaNkQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ฌ
HighWay
2026-10-05 02:17:25
(2 hours ago)
34.107.4.44 - - [05/Oct/2026:02:17:12 +0000] "GET /api/console/api_server?sense_version=%40%40SENSE_ ...
show more
34.107.4.44 - - [05/Oct/2026:02:17:12 +0000] "GET /api/console/api_server?sense_version=%40%40SENSE_VERSION&apis=../../../../../../.env HTTP/1.1" 403 421 "-" "Mozilla/5.0 (compatible; MoonshotBot/1.0; +https://kimi.ai/)"
34.107.4.44 - - [05/Oct/2026:02:17:13 +0000] "GET /userfiles?path=../../../.env HTTP/1.1" 403 421 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexitybot)"
34.107.4.44 - - [05/Oct/2026:02:17:13 +0000] "GET /userfiles?path=../../.env HTTP/1.1" 403 421 "-" "Mozilla/5.0 (compatible; PanguBot/1.0; +https://www.huaweicloud.com/)"
...
show less
Port Scan
Bad Web Bot
Web App Attack
Anonymous
2026-10-05 02:08:47
(2 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking