๐ช๐ธ
tutaim.com
2026-10-10 20:00:06
(13 minutes ago)
โ [10/10/26] This IP has been detected performing multiple attacks on websites (592 attempts blocked ...
show more
โ [10/10/26] This IP has been detected performing multiple attacks on websites (592 attempts blocked). Potential malicious activity.
show less
Brute-Force
SSH
Web App Attack
FTP Brute-Force
๐ฉ๐ช
ghostwarriors
2026-10-10 19:50:17
(23 minutes ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
๐ฉ๐ช
yitzhaq
2026-10-10 19:40:32
(33 minutes ago)
34.150.144.252 - - [10/Oct/2026:21:40:29 +0200] "GET /@fs/src/.env?import&raw?? HTTP/2.0" 403 296 "- ...
show more
34.150.144.252 - - [10/Oct/2026:21:40:29 +0200] "GET /@fs/src/.env?import&raw?? HTTP/2.0" 403 296 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; [email])"
34.150.144.252 - - [10/Oct/2026:21:40:29 +0200] "GET /@fs/proc/self/cmdline?raw?? HTTP/2.0" 403 296 "-" "Mozilla/5.0 (compatible; Qwenbot/1.0; +https://qwen.alibaba.com/)"
34.150.144.252 - - [10/Oct/2026:21:40:29 +0200] "GET /@fs/../.env?import&raw?? HTTP/2.0" 403 296 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-SearchBot/1.0; [email])"
34.150.144.252 - - [10/Oct/2026:21:40:29 +0200] "GET /__vite_rsc_findSourceMapURL?filename=file:///proc/self/environ&environmentName=rsc HTTP/2.0" 404 293 "-" "Mozilla/5.0 (compatible; Hunyuan/1.0; +https://hunyuan.tencent.com/)"
34.150.144.252 - - [10/Oct/2026:21:40:29 +0200] "GET /__vite_rsc_findSourceMapURL?filename=file:///app/.env&environmentName=rsc HTTP/2.0" 403 296 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compa
show less
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-10-10 19:36:00
(38 minutes ago)
(mod_security) mod_security (id:210730) triggered by 34.150.144.252 (252.144.150.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 34.150.144.252 (252.144.150.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 15:35:56.644951 2026] [security2:error] [pid 4300:tid 4300] [client 34.150.144.252:49366] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||scottwithers.xyz|F|2"] [data ".key"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "scottwithers.xyz"] [uri "/server.key"] [unique_id "asqTnNYjUsa2Ad0hPMUMFQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
VirtualAllocEx
2026-10-10 18:17:38
(1 hour ago)
Cloudflare automated security report.
Action: BLOCK; events: 18.
Sources: firewallCustom.
Request pa ...
show more
Cloudflare automated security report.
Action: BLOCK; events: 18.
Sources: firewallCustom.
Request paths: /.env.backup, /.env.save, /api/fs/read, /%2eenv, /.env.bak.
Countries: US.
ASNs: 396982.
User agents: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; OAI-AdsBot/1.0; +https://openai.com/adsbot, Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html), Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm), Mozilla/5.0 (compatible; Meta-WebIndexer/1.0; +https://developers.facebook.com/docs/sharing/webmasters/crawler), Mozilla/5.0 (compatible; Bravebot/1.0; +https://brave.com/search/).
show less
Web App Attack
๐บ๐ธ
VirtualAllocEx
2026-10-10 18:08:34
(2 hours ago)
Cloudflare automated security report.
Action: BLOCK; events: 8.
Sources: firewallCustom.
Request pat ...
show more
Cloudflare automated security report.
Action: BLOCK; events: 8.
Sources: firewallCustom.
Request paths: /userfiles, /api/fs/read, /.env.backup, /css../.env, /js../.env.
Countries: US.
ASNs: 396982.
User agents: Mozilla/5.0 (compatible; DeepSeekBot/1.0; +https://www.deepseek.com/), Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm), Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot), Mozilla/5.0 (compatible; Meta-ExternalAgent/1.0; +https://developers.facebook.com/docs/sharing/webmasters/crawler), Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexity-user).
show less
Web App Attack
๐บ๐ธ
VirtualAllocEx
2026-10-10 17:22:35
(2 hours ago)
Cloudflare automated security report.
Action: BLOCK; events: 13.
Sources: firewallCustom.
Request pa ...
show more
Cloudflare automated security report.
Action: BLOCK; events: 13.
Sources: firewallCustom.
Request paths: /.env.backup, /.env, /userfiles, /userfiles/x, /images../.env.
Countries: US.
ASNs: 396982.
User agents: Mozilla/5.0 (compatible; Hunyuan/1.0; +https://hunyuan.tencent.com/), Mozilla/5.0 (compatible; ChatGLM-Spider/1.0; +https://zhipuai.cn/), Mozilla/5.0 (compatible; Qwenbot/1.0; +https://qwen.alibaba.com/), Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm), Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; [email protected] ).
show less
Web App Attack
๐บ๐ธ
VirtualAllocEx
2026-10-10 17:15:01
(2 hours ago)
Cloudflare automated security report.
Action: BLOCK; events: 11.
Sources: firewallCustom.
Request pa ...
show more
Cloudflare automated security report.
Action: BLOCK; events: 11.
Sources: firewallCustom.
Request paths: /.//.env, //.env, /.env.live, /.svn/entries, /media../.env.
Countries: US.
ASNs: 396982.
User agents: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot), Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html), Mozilla/5.0 (compatible; Meta-ExternalFetcher/1.0; +https://developers.facebook.com/docs/sharing/webmasters/crawler), Mozilla/5.0 (Linux; Android 6.0.1; Nexus 5X Build/MMB29P) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Mobile Safari/537.36 (compatible; Googlebot/2.1; +http://www.google.com/bot.html), Mozilla/5.0 (compatible; ChatGLM-Spider/1.0; +https://zhipuai.cn/).
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-10 17:07:15
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.150.144.252 (252.144.150.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.150.144.252 (252.144.150.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 13:07:09.446184 2026] [security2:error] [pid 19878:tid 19887] [client 34.150.144.252:38760] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "oftv.xyz"] [uri "/userfiles/x"] [unique_id "aspwvVJYDux8a5dTNmFAcAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
neo101
2026-10-10 16:57:07
(3 hours ago)
Secret Hunting & Credential Harvesting: Automated scanner (Nuclei (Secret Hunter)) probed decoy secr ...
show more
Secret Hunting & Credential Harvesting: Automated scanner (Nuclei (Secret Hunter)) probed decoy secrets path '/.env'. Served AI System Override decoy payload as counter-measure.
show less
Hacking
Web App Attack
๐ฉ๐ช
lolyay
2026-10-10 16:37:59
(3 hours ago)
34.150.144.252 - - [10/Oct/2026:16:37:57 +0000] "GET /keys/service-account.json HTTP/1.1" 200 4 "-" ...
show more
34.150.144.252 - - [10/Oct/2026:16:37:57 +0000] "GET /keys/service-account.json HTTP/1.1" 200 4 "-" "Mozilla/5.0 (compatible; MoonshotBot/1.0; +https://kimi.ai/)"
34.150.144.252 - - [10/Oct/2026:16:37:57 +0000] "GET /userfiles?path=../../../../.env HTTP/1.1" 200 4 "-" "DuckAssistBot/1.1 (https://duckduckgo.com/duckassistbot)"
...
show less
Web App Attack
Bad Web Bot
๐บ๐ธ
VirtualAllocEx
2026-10-10 16:37:31
(3 hours ago)
Cloudflare automated security report.
Action: BLOCK; events: 6.
Sources: firewallCustom.
Request pat ...
show more
Cloudflare automated security report.
Action: BLOCK; events: 6.
Sources: firewallCustom.
Request paths: /.env, /.git/HEAD, /.env.local, /.env.example.
Countries: US.
ASNs: 396982.
User agents: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot, Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; [email protected] ), Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; [email protected] ), Mozilla/5.0 (compatible; KimiBot/1.0; +https://kimi.ai/), Mozilla/5.0 (compatible; Bytespider; [email protected] ) AppleWebKit/537.36.
show less
Web App Attack
๐บ๐ธ
Jasper will
2026-10-10 16:28:10
(3 hours ago)
Repeated probing of common sensitive web application paths: 5 requests within 10 minutes over HTTP/2 ...
show more
Repeated probing of common sensitive web application paths: 5 requests within 10 minutes over HTTP/2.
show less
Web App Attack