Anonymous
2026-10-02 19:51:02
(1 hour ago)
34.138.14.126 - - [02/Oct/2026:21:51:01 +0200] "GET /model/info HTTP/1.1" 404 448 "-" "Mozilla/5.0 ( ...
show more
34.138.14.126 - - [02/Oct/2026:21:51:01 +0200] "GET /model/info HTTP/1.1" 404 448 "-" "Mozilla/5.0 (compatible; DeepSeekBot/1.0; +https://www.deepseek.com/)"
34.138.14.126 - - [02/Oct/2026:21:51:01 +0200] "GET /model/info HTTP/1.1" 404 252 "-" "Mozilla/5.0 (compatible; DeepSeekBot/1.0; +https://www.deepseek.com/)"
34.138.14.126 - - [02/Oct/2026:21:51:01 +0200] "GET /v523z15myi9cauoapf4u HTTP/1.1" 404 252 "-" "Mozilla/5.0 (compatible; YiBot/1.0; +https://01.ai/)"
34.138.14.126 - - [02/Oct/2026:21:51:01 +0200] "GET /v523z15myi9cauoapf4u HTTP/1.1" 404 448 "-" "Mozilla/5.0 (compatible; YiBot/1.0; +https://01.ai/)"
34.138.14.126 - - [02/Oct/2026:21:51:01 +0200] "POST /lib/terminal-xhr.php HTTP/1.1" 403 124 "-" "Mozilla/5.0 (compatible; YouBot/1.0; +https://you.com/bot)"
34.138.14.126 - - [02/Oct/2026:21:51:01 +0200] "GET /i4rh8fzmet1lpbyhdwd5 HTTP/1.1" 403 124 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot)"
34.138
...
show less
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-10-02 19:24:30
(2 hours ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.138.14.126 (US/United States/126.1 ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.138.14.126 (US/United States/126.14.138.34.bc.googleusercontent.com): 2 in the last 3600 secs (0-196)
show less
Hacking
๐ฌ๐ง
Aetherweb Ark
2026-10-02 19:07:32
(2 hours ago)
(mod_security) mod_security (id:949110) triggered by 34.138.14.126 (US/United States/126.14.138.34.b ...
show more
(mod_security) mod_security (id:949110) triggered by 34.138.14.126 (US/United States/126.14.138.34.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 19:03:11
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.138.14.126 (126.14.138.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.138.14.126 (126.14.138.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 15:03:07.215516 2026] [security2:error] [pid 18167:tid 18167] [client 34.138.14.126:52404] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.yalaz.com"] [uri "/.env.php.bak"] [unique_id "ar__62ZuJ_PSYjKqncsqJwAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
NXTwoThou
2026-10-02 18:25:02
(3 hours ago)
/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh
Web App Attack
๐ฆ๐บ
A.i.D.A.N.N
2026-10-02 18:19:25
(3 hours ago)
A.i.D.A.N.N: Anomaly Detected - Signature match Web Service - Web vulnerability scanning detected
Web App Attack
Anonymous
2026-10-02 17:56:59
(3 hours ago)
IP matched detection query more than 2 hosts and only bad rq long ban.
Brute-Force
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-10-02 17:35:40
(4 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.138.14.126 (126.14.138.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.138.14.126 (126.14.138.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 13:35:35.037265 2026] [security2:error] [pid 8516:tid 8516] [client 34.138.14.126:38490] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||veracurnow.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "veracurnow.com"] [uri "/z9x8c7v6b5-debug-trigger-veracurnow.com"] [unique_id "ar_rZw34XaoN_E6sScSB8wAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
BlueWire Hosting
2026-10-02 16:26:55
(5 hours ago)
Bad bot ignoring robot.txt
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-02 16:00:15
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.138.14.126 (126.14.138.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.138.14.126 (126.14.138.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 12:00:08.800265 2026] [security2:error] [pid 29454:tid 29454] [client 34.138.14.126:39306] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.vgforever.com"] [uri "/static../.env"] [unique_id "ar_VCEOqun27TkgapgfwvQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TAY
2026-10-02 15:53:06
(5 hours ago)
34.138.14.126 - - [02/Oct/2026:23:53:05 +0800] "GET /static../.env HTTP/1.1" 404 42716 "-" "Mozilla/ ...
show more
34.138.14.126 - - [02/Oct/2026:23:53:05 +0800] "GET /static../.env HTTP/1.1" 404 42716 "-" "Mozilla/5.0 (compatible; Google-Extended; +http://www.google.com/bot.html)"
34.138.14.126 - - [02/Oct/2026:23:53:05 +0800] "GET /files../.env HTTP/1.1" 404 42716 "-" "Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; +https://kimi.ai/)"
34.138.14.126 - - [02/Oct/2026:23:53:05 +0800] "GET /media../.env HTTP/1.1" 404 42716 "-" "Mozilla/5.0 (compatible; MistralAI-User/1.0; +https://mistral.ai/)"
34.138.14.126 - - [02/Oct/2026:23:53:05 +0800] "GET /images../.env HTTP/1.1" 404 48461 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot)"
34.138.14.126 - - [02/Oct/2026:23:53:05 +0800] "GET /uploads../.env HTTP/1.1" 404 48461 "-" "Mozilla/5.0 (compatible; Qwenbot/1.0; +https://qwen.alibaba.com/)"
34.138.14.126 - - [02/Oct/2026:23:53:05 +0800] "GET /assets../.env HTTP/1.1" 404 42716 "-" "Mozilla/5.0 (compatible; KimiBot/1.0; +https://kimi.
...
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-10-02 15:25:08
(6 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.138.14.126 (126.14.138.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.138.14.126 (126.14.138.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 11:24:58.441843 2026] [security2:error] [pid 25598:tid 25598] [client 34.138.14.126:47206] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.usaenquirer.com|F|2"] [data ".usaenquirer.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.usaenquirer.com"] [uri "/z9x8c7v6b5-debug-trigger-www.usaenquirer.com"] [unique_id "ar_Myt79trqOTU65gTXQKQAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-10-02 15:01:36
(6 hours ago)
Excessive multi-domain requests
Brute-Force
๐ณ๐ฑ
Mangelot Hosting
2026-10-02 14:54:36
(6 hours ago)
(web_sensitive_file) srv102 Sensitive file probe (.env/.git/backup) 34.138.14.126 (US/United States/ ...
show more
(web_sensitive_file) srv102 Sensitive file probe (.env/.git/backup) 34.138.14.126 (US/United States/126.14.138.34.bc.googleusercontent.com): 2 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 14:54:23
(6 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.138.14.126 (126.14.138.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.138.14.126 (126.14.138.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 10:54:16.364449 2026] [security2:error] [pid 17337:tid 17337] [client 34.138.14.126:41514] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.vitess.com|F|2"] [data ".vitess.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.vitess.com"] [uri "/z9x8c7v6b5-debug-trigger-mail.vitess.com"] [unique_id "ar_FmOidaq7-qMJmh7HlBgAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack