🇩🇪
Hazzard
2026-09-13 08:43:45
(3 hours ago)
(mod_security) mod_security triggered on hostname [redacted]): (CF_ENABLE)
SQL Injection
Anonymous
2026-09-13 06:19:20
(6 hours ago)
34.145.240.250 - - [13/Sep/2026:08:19:18 +0200] "GET / HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Windows N ...
show more
34.145.240.250 - - [13/Sep/2026:08:19:18 +0200] "GET / HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
34.145.240.250 - - [13/Sep/2026:08:19:19 +0200] "GET /api/uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2fproc/self/environ HTTP/1.1" 400 168 "-" "-"
34.145.240.250 - - [13/Sep/2026:08:19:19 +0200] "GET /rclone.conf HTTP/1.1" 403 124 "-" "Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; +https://kimi.ai/)"
34.145.240.250 - - [13/Sep/2026:08:19:19 +0200] "GET /@fs/proc/self/cwd/.env?raw?? HTTP/1.1" 403 124 "-" "Mozilla/5.0 (compatible; YouBot/1.0; +https://you.com/bot)"
34.145.240.250 - - [13/Sep/2026:08:19:19 +0200] "GET /z9x8c7v6b5-debug-trigger-medsabhustlehub.online HTTP/1.1" 403 124 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Safari/605.1.15 (Applebot/0.1)"
34.145.240.250 - - [13/Sep/2026:08:19:19 +0200] "GET /public/plugins/alertl
...
show less
Bad Web Bot
Web App Attack
🇮🇳
evicky2002
2026-09-13 06:00:01
(6 hours ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
🇩🇪
akasolutions.de
2026-09-13 05:26:01
(7 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 34.145.240.250 (US/United States/250.24 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.145.240.250 (US/United States/250.240.145.34.bc.googleusercontent.com)
show less
SQL Injection
🇺🇸
TPI-Abuse
2026-09-13 02:17:04
(10 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.145.240.250 (250.240.145.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 34.145.240.250 (250.240.145.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 22:16:56.354150 2026] [security2:error] [pid 25956:tid 25956] [client 34.145.240.250:51882] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||blackoakprop.com|F|2"] [data ".key"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "blackoakprop.com"] [uri "/ssl/localhost.key"] [unique_id "aqYHmDiDts4d4LcfOJVNjAAAAEA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-13 02:08:45
(10 hours ago)
Bot detected scanning for vulnerable pages
Port Scan
🇮🇹
ciccio diddo
2026-09-13 02:04:34
(10 hours ago)
High Burst multiple 40X port:Tcp/80,443
Brute-Force
Web App Attack
🇫🇷
Catalin Negru
2026-09-13 01:50:01
(10 hours ago)
Recidive ban by fail2ban on server.blackbit.ro
Brute-Force
🇺🇸
TPI-Abuse
2026-09-13 00:47:02
(11 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.145.240.250 (250.240.145.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 34.145.240.250 (250.240.145.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 20:46:56.910933 2026] [security2:error] [pid 12282:tid 12282] [client 34.145.240.250:42510] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||bizzmail.net|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "bizzmail.net"] [uri "/rclone.conf"] [unique_id "aqXygBenLels5jkXspo2KwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
svr
2026-09-13 00:21:18
(12 hours ago)
HC-Flood Web Scanner
Web App Attack
🇬🇧
Aetherweb Ark
2026-09-12 23:48:03
(12 hours ago)
(mod_security) mod_security (id:949110) triggered by 34.145.240.250 (US/United States/250.240.145.34 ...
show more
(mod_security) mod_security (id:949110) triggered by 34.145.240.250 (US/United States/250.240.145.34.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
🇩🇪
maxpower
2026-09-12 23:11:51
(13 hours ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 34.145.240.250 (US/United States/250.240 ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 34.145.240.250 (US/United States/250.240.145.34.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 34.145.240.250 - - [13/Sep/2026:01:11:48 +0200] "GET /config/secrets.yml HTTP/2.0" 200 12129 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexitybot)" "-" host=birreriadelcorso.it
show less
Port Scan
🇺🇸
TPI-Abuse
2026-09-12 22:59:27
(13 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.145.240.250 (250.240.145.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 34.145.240.250 (250.240.145.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 18:59:21.002804 2026] [security2:error] [pid 12225:tid 12225] [client 34.145.240.250:59172] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||birdlovesfish.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "birdlovesfish.com"] [uri "/rclone.conf"] [unique_id "aqXZSBllAyKF77xm3gZ9rQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
decisionconcepts
2026-09-12 22:55:58
(13 hours ago)
34.145.240.250 - - [12/Sep/2026:15:55:58 -0700] "GET /@fs/app/.env?raw?? HTTP/2.0" 403 199 "-" "Mozi ...
show more
34.145.240.250 - - [12/Sep/2026:15:55:58 -0700] "GET /@fs/app/.env?raw?? HTTP/2.0" 403 199 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot)"
34.145.240.250 - - [12/Sep/2026:15:55:58 -0700] "GET /@fs/../.env?raw?? HTTP/2.0" 403 199 "-" "Mozilla/5.0 (compatible; Google-Extended; +http://www.google.com/bot.html)"
show less
Brute-Force
SSH
🇫🇷
Baking333
2026-09-12 22:45:10
(13 hours ago)
[redacted] 34.145.240.250 - - [12/Sep/2026:23:45:08 +0100] "GET /@fs/app/.env?raw?? HTTP/1.1" 302 15 ...
show more
[redacted] 34.145.240.250 - - [12/Sep/2026:23:45:08 +0100] "GET /@fs/app/.env?raw?? HTTP/1.1" 302 1564 0/64032 "-" "Mozilla/5.0 (compatible; MoonshotBot/1.0; +https://[redacted]/)" [redacted] 34.145.240.250 - - [12/Sep/2026:23:45:08 +0100] "GET /@fs/src/.env?raw?? HTTP/1.1" 302 1564 0/81616 "-" "Mozilla/5.0 (compatible; MistralAI-User/1.0; +https://[redacted]/)"
show less
Bad Web Bot
Web App Attack