π©πͺ
updown.io
2026-09-30 02:01:00
(2 hours ago)
{"level":"info","ts":1790733659.838833,"logger":"http.log.access.log0","msg":"handled request","requ ...
show more
{"level":"info","ts":1790733659.838833,"logger":"http.log.access.log0","msg":"handled request","request":{"remote_ip":"34.140.97.7","remote_port":"49552","client_ip":"34.140.97.7","proto":"HTTP/2.0","method":"POST","host":"iuea.status.updown.io","uri":"/graphql","headers":{"Sec-Ch-Ua-Platform":["\"macOS\""],"Sec-Fetch-Site":["same-origin"],"Content-Type":["application/json"],"Referer":["https://iuea.status.updown.io"],"Accept-Encoding":["gzip, deflate, br, zstd"],"Accept":["*/*"],"Sec-Ch-Ua":["\"Chromium\";v=\"152\", \"Not?A_Brand\";v=\"24\", \"Google Chrome\";v=\"152\""],"Accept-Language":["en-US,en;q=0.9"],"Content-Length":["86"],"Origin":["https://iuea.status.updown.io"],"Cookie":["REDACTED"],"Priority":["u=1, i"],"Sec-Fetch-Mode":["cors"],"Sec-Fetch-Dest":["empty"],"User-Agent":["Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36"],"Sec-Ch-Ua-Mobile":["?0"]},"tls":{"resumed":false,"version":772,"cipher_suite":4865,"
...
show less
DDoS Attack
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-30 01:27:15
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.140.97.7 (7.97.140.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.140.97.7 (7.97.140.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 21:27:08.387225 2026] [security2:error] [pid 23749:tid 23749] [client 34.140.97.7:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.rareearth.technology"] [uri "/userfiles/x"] [unique_id "arxlbGEqkr2ncG9YQEGe-QAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
Hans Renses
2026-09-30 01:06:09
(3 hours ago)
Web app attack: 4 requests for known vulnerable paths (.env, xmlrpc.php, web shells, config backups) ...
show more
Web app attack: 4 requests for known vulnerable paths (.env, xmlrpc.php, web shells, config backups) within one hour. Reported automatically by BotZoom.
show less
Web App Attack
Hacking
π¬π§
andypiper
2026-09-30 01:02:25
(3 hours ago)
CrowdSec ban for AbuseIPDB Top List
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-30 01:01:32
(3 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.140.97.7 (7.97.140.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.140.97.7 (7.97.140.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 21:01:24.369668 2026] [security2:error] [pid 7148:tid 7201] [client 34.140.97.7:0] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||raytbrown.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "raytbrown.com"] [uri "/z9x8c7v6b5-debug-trigger-raytbrown.com"] [unique_id "arxfZPKJbtdfFL3JAUAUQgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-30 00:32:06
(3 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.140.97.7 (7.97.140.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.140.97.7 (7.97.140.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 20:32:00.926155 2026] [security2:error] [pid 19689:tid 19689] [client 34.140.97.7:37024] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ipv6.pghsea.com|F|2"] [data ".pghsea.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ipv6.pghsea.com"] [uri "/z9x8c7v6b5-debug-trigger-ipv6.pghsea.com"] [unique_id "arxYgDmHuU4QZfDvgBworwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
Site.eu
2026-09-30 00:12:18
(4 hours ago)
Excessive multi-domain requests
Brute-Force
π«π·
LiloBzH
2026-09-30 00:00:57
(4 hours ago)
34.140.97.7 - - [30/Sep/2026:02:00:53 +0200] "GET /.git/config HTTP/2.0" 403 107 "-" "Mozilla/5.0 Ap ...
show more
34.140.97.7 - - [30/Sep/2026:02:00:53 +0200] "GET /.git/config HTTP/2.0" 403 107 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot"
34.140.97.7 - - [30/Sep/2026:02:00:55 +0200] "POST /cgi-bin/php-cgi.exe?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input HTTP/2.0" 200 1291 "-" "Mozilla/5.0 (compatible; PanguBot/1.0; +https://www.huaweicloud.com/)"
34.140.97.7 - - [30/Sep/2026:02:00:55 +0200] "POST /cgi-bin/php?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input HTTP/2.0" 200 1291 "-" "Mozilla/5.0 (compatible; MoonshotBot/1.0; +https://kimi.ai/)"
show less
Web App Attack
π©πͺ
maxpower
2026-09-29 23:21:56
(4 hours ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 34.140.97.7 (BE/Belgium/7.97.140.34.bc.g ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 34.140.97.7 (BE/Belgium/7.97.140.34.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 34.140.97.7 - - [30/Sep/2026:01:21:54 +0200] "GET /secrets.json HTTP/2.0" 403 0 "-" "Mozilla/5.0 (compatible; Qwenbot/1.0; +https://qwen.alibaba.com/)" "34.140.97.7" host=ipv6.masterlabvideoproduzioni.it
show less
Port Scan
πΊπΈ
TPI-Abuse
2026-09-29 23:00:53
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.140.97.7 (7.97.140.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.140.97.7 (7.97.140.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 19:00:48.700753 2026] [security2:error] [pid 22754:tid 22754] [client 34.140.97.7:36386] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pentesters.in"] [uri "/public/.env"] [unique_id "arxDIMlxt5v6IrZQzvWD9AAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π§πͺ
cmbplf
2026-09-29 22:59:24
(5 hours ago)
4.100 requests from abuseipdb.com blacklisted IP (1yr10mos4d)
Brute-Force
Bad Web Bot
π³π±
Alt255
2026-09-29 22:40:38
(5 hours ago)
[ti-01al] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail apac ...
show more
[ti-01al] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail apache-404. Example: 34.140.97.7 - - [30/Sep/2026:00:40:33 +0200] "GET /z9x8c7v6b5-debug-trigger-monitor.alt255.net HTTP/2.0" 404 1855 "-" "Mozilla/5.0 (compatible; Meta-ExternalAgent/1.0; +https://developers.facebook.com/docs/sharing/webmasters/crawler)"
34.140.97.7 - - [30/Sep/2026:00:40:33 +0200] "GET /8c4i2cp340ep861tbnbs HTTP/2.0" 404 1855 "-" "Mozilla/5.0 (compatible; Google-Extended; +http://www.google.com/bot.html)"
34.140.97.7 - - [30/Sep/2026:00:40:33 +0200] "GET /login HTTP/2.0" 404 1855 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36"
34.140.97.7 - - [30/Sep/2026:00:40:33 +0200] "GET /auth/login HTTP/2.0" 404 1855 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML,
...
show less
Bad Web Bot
Web App Attack
πΊπΈ
oralunal
2026-09-29 22:33:49
(5 hours ago)
IP banned by Fail2Ban in jail its-suss access.log mvfnds
...
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-29 22:32:53
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.140.97.7 (7.97.140.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.140.97.7 (7.97.140.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 18:32:45.783214 2026] [security2:error] [pid 24483:tid 24483] [client 34.140.97.7:58156] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/Web.config" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pist.org.tr"] [uri "/web.config"] [unique_id "arw8jRCPoaBOJ11hHAIWLgAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-29 21:51:14
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.140.97.7 (7.97.140.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.140.97.7 (7.97.140.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 17:51:10.750138 2026] [security2:error] [pid 10751:tid 10770] [client 34.140.97.7:59984] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "appraisalteam.net"] [uri "/.env.dev"] [unique_id "arwyzv4LrcsAL5HXSG3u2AAAANE"]
show less
Brute-Force
Bad Web Bot
Web App Attack