Anonymous
2026-08-23 19:48:53
(3 days ago)
$f2bV_matches
Brute-Force
๐ซ๐ท
mail.avx.gr
2026-08-23 00:09:23
(4 days ago)
Plesk Fail2Ban jail: Plesk-Web-Exploits. Evidence: default-10-0-0-4:443 34.140.39.69 - - [16/Aug/202 ...
show more
Plesk Fail2Ban jail: Plesk-Web-Exploits. Evidence: default-10-0-0-4:443 34.140.39.69 - - [16/Aug/2026:04:02:52 +0300] "GET /static../.env HTTP/1.1" 403 2432 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ChatGPT-User/1.0; +https://openai.com/bot)"
show less
Web App Attack
๐ฌ๐ท
mail.avx.gr
2026-08-21 17:34:19
(5 days ago)
Plesk Fail2Ban jail: Plesk-Web-Exploits. Evidence: default-10-0-0-4:443 34.140.39.69 - - [16/Aug/202 ...
show more
Plesk Fail2Ban jail: Plesk-Web-Exploits. Evidence: default-10-0-0-4:443 34.140.39.69 - - [16/Aug/2026:04:02:52 +0300] "GET /static../.env HTTP/1.1" 403 2432 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ChatGPT-User/1.0; +https://openai.com/bot)"
show less
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-08-16 21:59:42
(1 week ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-08-15.
show less
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-16 05:49:32
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.140.39.69 (69.39.140.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.140.39.69 (69.39.140.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 01:49:24.114203 2026] [security2:error] [pid 13452:tid 13452] [client 34.140.39.69:13568] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.ttlatl.com"] [uri "/.git/HEAD"] [unique_id "aoFPZBeBf8HyUcmARGAQHQAAADg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-16 05:23:59
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.140.39.69 (69.39.140.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.140.39.69 (69.39.140.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 01:23:45.606279 2026] [security2:error] [pid 13888:tid 13888] [client 34.140.39.69:6502] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.trhs70.com"] [uri "/media../.env"] [unique_id "aoFJYYizc_c50QPVOD3U5QAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-16 05:07:54
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.140.39.69 (69.39.140.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.140.39.69 (69.39.140.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 01:07:44.591780 2026] [security2:error] [pid 12785:tid 12785] [client 34.140.39.69:57084] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.transportdelivery.com"] [uri "/app/.env"] [unique_id "aoFFoKc90oRxPgnj9y5mkgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-08-16 04:28:46
(1 week ago)
Excessive multi-domain requests
Brute-Force
Anonymous
2026-08-16 04:18:10
(1 week ago)
Fuzzing/Looking for credentials files.
Brute-Force
Web App Attack
๐ฌ๐ง
blik2108
2026-08-16 03:17:41
(1 week ago)
34.140.39.69 - - [16/Aug/2026:03:17:39 +0000] "GET /fetch?uri=http%3A%2F%2F169.254.169.254%2Flatest% ...
show more
34.140.39.69 - - [16/Aug/2026:03:17:39 +0000] "GET /fetch?uri=http%3A%2F%2F169.254.169.254%2Flatest%2Fmeta-data%2Fiam%2Fsecurity-credentials%2F HTTP/1.1" 404 3431 "-" "Mozilla/5.0 (compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot)" "-"
34.140.39.69 - - [16/Aug/2026:03:17:39 +0000] "GET /fetch?uri=http%3A%2F%2F169.254.169.254%2Flatest%2Fmeta-data%2F HTTP/1.1" 404 3431 "-" "Mozilla/5.0 (compatible; Google-Extended/1.0; +http://www.google.com/bot.html)" "-"
34.140.39.69 - - [16/Aug/2026:03:17:39 +0000] "GET /fetch?url=http%3A%2F%2F169.254.169.254%2Flatest%2Fmeta-data%2F HTTP/1.1" 404 3431 "-" "Mozilla/5.0 (compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot)" "-"
34.140.39.69 - - [16/Aug/2026:03:17:39 +0000] "GET /fetch?uri=http%3A%2F%2F169.254.169.254%2Flatest%2Fmeta-data%2Fiam%2Finfo HTTP/1.1" 404 3431 "-" "Mozilla/5.0 (compatible; Google-Extended/1.0; +http://www.google.com/bot.html)" "-"
34.140.39.69 - - [16/Aug/2026:03:17:39 +0000] "GET /fetc
...
show less
Web App Attack
๐ฉ๐ช
iNetWorker
2026-08-16 01:59:43
(1 week ago)
trolling for resource vulnerabilities
Web App Attack
๐ซ๐ท
masterguru
2026-08-16 01:51:16
(1 week ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.140.39.69 (BE/Belgium/69.39.140.34 ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.140.39.69 (BE/Belgium/69.39.140.34.bc.googleusercontent.com): 1 in the last 3600 secs (0-195)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-16 01:50:15
(1 week ago)
(mod_security) mod_security (id:210580) triggered by 34.140.39.69 (69.39.140.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210580) triggered by 34.140.39.69 (69.39.140.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 15 21:50:09.569827 2026] [security2:error] [pid 24475:tid 24475] [client 34.140.39.69:32068] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "proc/self/environ" at ARGS:url. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/08_Global_Other.conf"] [line "57"] [id "210580"] [rev "2"] [msg "COMODO WAF: OS File Access Attempt||mail.independentmusicconference.com|F|2"] [data "Matched Data: proc/self/environ found within ARGS:url: file:/proc/self/environ"] [severity "CRITICAL"] [tag "CWAF"] [tag "Other"] [hostname "mail.independentmusicconference.com"] [uri "/read"] [unique_id "aoEXUTBbrfI6oL7gymGevgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-16 01:38:12
(1 week ago)
Bot / seems abusive / Apache connections: 42
DDoS Attack
Web Spam
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-08-16 01:18:52
(1 week ago)
Restricted File Access Attempt. Matched phrase ".git-credentials" at REQUEST_FILENAME. (930130-193)
Hacking
Web App Attack