๐ซ๐ท
SpaceHost-Server
2026-09-22 22:23:38
(1 week ago)
Brute-Force
Web App Attack
๐ซ๐ท
SpaceHost-Server
2026-09-21 22:22:14
(1 week ago)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 05:45:15
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.139.74.244 (244.74.139.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.139.74.244 (244.74.139.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 01:45:12.152434 2026] [security2:error] [pid 1140:tid 1140] [client 34.139.74.244:45904] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.sitexpress.es"] [uri "/.env.js"] [unique_id "arDEaP6a7kiMRnG7Kl2p7gAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 04:06:14
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.139.74.244 (244.74.139.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.139.74.244 (244.74.139.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 00:06:09.371815 2026] [security2:error] [pid 15013:tid 15013] [client 34.139.74.244:36074] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.cederberg.es"] [uri "/.git/HEAD"] [unique_id "arCtMbPPoJcukVS1aAjBoQAAACg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-21 03:36:47
(1 week ago)
IP matched detection query many 3xx errors.
Brute-Force
๐ณ๐ฑ
Site.eu
2026-09-21 03:23:22
(1 week ago)
Excessive multi-domain requests
Brute-Force
๐ช๐ธ
robotstxt
2026-09-21 03:17:25
(1 week ago)
34.139.74.244 - - [21/Sep/2026:03:16:22 +0000] "GET /config.json HTTP/2.0" 403 27043 "-" "Mozilla/5. ...
show more
34.139.74.244 - - [21/Sep/2026:03:16:22 +0000] "GET /config.json HTTP/2.0" 403 27043 "-" "Mozilla/5.0 (compatible; Bytespider; [email protected] ) AppleWebKit/537.36" "-" edge="34.139.74.244"
34.139.74.244 - - [21/Sep/2026:03:16:22 +0000] "GET /wp-content/plugins/woocommerce/assets/js/frontend/woocommerce.min.js?ver=11.1.0 HTTP/2.0" 403 25855 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36" "-" edge="34.139.74.244"
34.139.74.244 - - [21/Sep/2026:03:16:22 +0000] "GET /config.js HTTP/2.0" 403 27042 "-" "Mozilla/5.0 (compatible; ChatGLM-Spider/1.0; +https://zhipuai.cn/)" "-" edge="34.139.74.244"
34.139.74.244 - - [21/Sep/2026:03:16:22 +0000] "GET /__/firebase/init.json HTTP/2.0" 403 27046 "-" "Mozilla/5.0 (compatible; YiBot/1.0; +https://01.ai/)" "-" edge="34.139.74.244"
34.139.74.244 - - [21/Sep/2026:03:16:22 +0000] "GET /dist/manifest.json HTTP/2.0" 403 25790 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) Ap
...
show less
Web App Attack
๐ช๐ธ
robotstxt
2026-09-21 02:51:09
(1 week ago)
34.139.74.244 - - [21/Sep/2026:02:51:06 +0000] "GET /%2e%2e/.env HTTP/1.1" 400 193 "-" "-" "-" edge= ...
show more
34.139.74.244 - - [21/Sep/2026:02:51:06 +0000] "GET /%2e%2e/.env HTTP/1.1" 400 193 "-" "-" "-" edge="34.139.74.244"
34.139.74.244 - - [21/Sep/2026:02:51:06 +0000] "GET /%2e%2e/.env HTTP/1.1" 400 193 "-" "-" "-" edge="34.139.74.244"
34.139.74.244 - - [21/Sep/2026:02:51:06 +0000] "GET /..%2f..%2f.env HTTP/1.1" 400 193 "-" "-" "-" edge="34.139.74.244"
34.139.74.244 - - [21/Sep/2026:02:51:06 +0000] "GET /..%2f..%2f.env HTTP/1.1" 400 193 "-" "-" "-" edge="34.139.74.244"
34.139.74.244 - - [21/Sep/2026:02:51:06 +0000] "GET /public/plugins/alertlist/../../../../../../../../proc/self/environ HTTP/1.1" 400 193 "-" "-" "-" edge="34.139.74.244"
...
show less
Web Spam
Web App Attack
๐ช๐ธ
Francisco Vallejo
2026-09-21 02:39:06
(1 week ago)
[Mon Sep 21 04:39:05.923119 2026] [core:info] [pid 3385638:tid 133530650662592] [client 34.139.74.24 ...
show more
[Mon Sep 21 04:39:05.923119 2026] [core:info] [pid 3385638:tid 133530650662592] [client 34.139.74.244:43682] AH00128: File does not exist: /var/www/franvallejo/packages/.env
[Mon Sep 21 04:39:06.020213 2026] [core:info] [pid 3385638:tid 133531716011712] [client 34.139.74.244:43682] AH00128: File does not exist: /var/www/franvallejo/static/manifest.json
[Mon Sep 21 04:39:06.117072 2026] [core:info] [pid 3385638:tid 133530910705344] [client 34.139.74.244:43700] AH00128: File does not exist: /var/www/franvallejo/.aws/config
[Mon Sep 21 04:39:06.119705 2026] [core:info] [pid 3385638:tid 133531590186688] [client 34.139.74.244:43682] AH00128: File does not exist: /var/www/franvallejo/assets/manifest.json
[Mon Sep 21 04:39:06.121705 2026] [core:info] [pid 3385638:tid 133531598579392] [client 34.139.74.244:43696] AH00128: File does not exist: /var/www/franvallejo/dist/manifest.json
...
show less
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-09-21 02:38:12
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.139.74.244 (244.74.139.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.139.74.244 (244.74.139.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 22:38:06.104858 2026] [security2:error] [pid 30428:tid 30428] [client 34.139.74.244:59076] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.auracb.es"] [uri "/.git/config"] [unique_id "arCYjpm7jP0OgGBQCVrntgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 00:18:39
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.139.74.244 (244.74.139.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.139.74.244 (244.74.139.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 20:18:34.830478 2026] [security2:error] [pid 13253:tid 13253] [client 34.139.74.244:55762] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.totenclaus.es"] [uri "/.env.js"] [unique_id "arB32kKbT28qB9rINx3A3QAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
masterguru
2026-09-21 00:12:19
(1 week ago)
Inbound Anomaly Score Exceeded (Total Score: 5). Operator GE matched 5 at TX:anomaly_score. (949110- ...
show more
Inbound Anomaly Score Exceeded (Total Score: 5). Operator GE matched 5 at TX:anomaly_score. (949110-122)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-20 23:46:06
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.139.74.244 (244.74.139.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.139.74.244 (244.74.139.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 19:45:59.755079 2026] [security2:error] [pid 9291:tid 9291] [client 34.139.74.244:54626] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "journ-e.sabri.es"] [uri "/.env.production"] [unique_id "arBwNxNpkgoiGdfM2Q0ARAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
updown.io
2026-09-20 23:36:33
(1 week ago)
{"level":"info","ts":1789947389.0990295,"logger":"http.log.access.log1","msg":"handled request","req ...
show more
{"level":"info","ts":1789947389.0990295,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"34.139.74.244","remote_port":"37082","client_ip":"34.139.74.244","proto":"HTTP/2.0","method":"GET","host":"status.cloudbit.es","uri":"/manage/env","headers":{"User-Agent":["Mozilla/5.0 (compatible; Hunyuan/1.0; +https://hunyuan.tencent.com/)"],"Accept":["*/*"],"Accept-Encoding":["gzip"],"X-Middleware-Subrequest":["src/middleware:nowaf:src/middleware:src/middleware:src/middleware:src/middleware:middleware:middleware:nowaf:middleware:middleware:middleware:pages/_middleware"],"X-Nextjs-Data":["1"]},"tls":{"resumed":false,"version":772,"cipher_suite":4865,"proto":"h2","server_name":"status.cloudbit.es","ech":false}},"bytes_read":0,"user_id":"","duration":0.000449988,"size":0,"status":429,"resp_headers":{"Server":["Caddy"],"Alt-Svc":["h3=\":443\"; ma=2592000"],"Retry-After":["1"]}}
{"level":"info","ts":1789947389.170226,"logger":"http.log.access.log1","msg":"handled reques
...
show less
DDoS Attack
Web App Attack
๐ฉ๐ช
macrob
2026-09-20 23:21:12
(1 week ago)
2026/09/20 23:21:10 [error] 631206#631206: *19462205 access forbidden by rule, client: 34.139.74.244 ...
show more
2026/09/20 23:21:10 [error] 631206#631206: *19462205 access forbidden by rule, client: 34.139.74.244, server: fn.binixo.es, request: "GET /cmd/.env HTTP/2.0", host: "fn.binixo.es"
2026/09/20 23:21:10 [error] 631206#631206: *19462208 access forbidden by rule, client: 34.139.74.244, server: fn.binixo.es, request: "GET /scripts/.env HTTP/2.0", host: "fn.binixo.es"
2026/09/20 23:21:10 [error] 631206#631206: *19462210 access forbidden by rule, client: 34.139.74.244, server: fn.binixo.es, request: "GET /pkg/.env HTTP/2.0", host: "fn.binixo.es"
...
show less
Web App Attack