๐บ๐ธ
alsmanifesto
2026-10-05 12:34:46
(15 hours ago)
Enumerated hostnames across our wildcard domain (account.fluentops.org) against fluentops.org. 288 r ...
show more
Enumerated hostnames across our wildcard domain (account.fluentops.org) against fluentops.org. 288 requests, 2026-10-05 12:34:46 UTC. Blocked at our edge.
show less
Port Scan
Bad Web Bot
๐ฉ๐ช
Gwyneth Llewelyn
2026-10-05 11:29:36
(16 hours ago)
2026/10/05 12:29:32 [error] 3069275#3069275: *215701 access forbidden by rule, client: 34.151.222.28 ...
show more
2026/10/05 12:29:32 [error] 3069275#3069275: *215701 access forbidden by rule, client: 34.151.222.28, server: simetria.org, request: "GET /admin%2F.env HTTP/2.0", host: "simetria.org"
2026/10/05 12:29:32 [error] 3069275#3069275: *215704 access forbidden by rule, client: 34.151.222.28, server: simetria.org, request: "GET /dashboard%2F.env HTTP/2.0", host: "simetria.org"
2026/10/05 12:29:33 [error] 3069275#3069275: *215705 access forbidden by rule, client: 34.151.222.28, server: simetria.org, request: "GET /api%2F.env HTTP/2.0", host: "simetria.org"
show less
Brute-Force
Web App Attack
Anonymous
2026-10-05 11:25:01
(16 hours ago)
[Drupal AbuseIPDB module] Request path is blacklisted. /.env.bak
Web App Attack
Anonymous
2026-10-05 11:23:50
(16 hours ago)
34.151.222.28 - - [05/Oct/2026:06:23:48 -0500] "GET /.env?raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 (co ...
show more
34.151.222.28 - - [05/Oct/2026:06:23:48 -0500] "GET /.env?raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; YiBot/1.0; +https://01.ai/)" 34.151.222.28
34.151.222.28 - - [05/Oct/2026:06:23:48 -0500] "GET /.env?import&url&inline HTTP/1.1" 403 199 "-" "CCBot/2.0 (https://commoncrawl.org/faq/)" 34.151.222.28
34.151.222.28 - - [05/Oct/2026:06:23:48 -0500] "GET /.env?import&raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexitybot)" 34.151.222.28
34.151.222.28 - - [05/Oct/2026:06:23:49 -0500] "GET /.env.local?raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Safari/605.1.15 (Applebot/0.1)" 34.151.222.28
34.151.222.28 - - [05/Oct/2026:06:23:49 -0500] "GET /.env.local?import&raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; cohere-ai; +https://cohere.com/crawler)" 34.151.222.28
34.151.222.28 - - [05/Oct/2026:06:23:49 -0500]
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Rocky Mountain Bioengineering Symposium
2026-10-05 11:18:36
(16 hours ago)
34.151.222.28 - - [05/Oct/2026:05:18:35 -0600] "GET /.git/config HTTP/2.0" 300 4342 "-" "Mozilla/5.0 ...
show more
34.151.222.28 - - [05/Oct/2026:05:18:35 -0600] "GET /.git/config HTTP/2.0" 300 4342 "-" "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)"
...
show less
Web App Attack
Anonymous
2026-10-05 11:16:20
(16 hours ago)
Logfile match
Web App Attack
๐ฉ๐ช
Blexyel
2026-10-05 11:07:20
(16 hours ago)
34.151.222.28 - - [05/Oct/2026:13:07:19 +0200] "GET /.git/config HTTP/1.1" 200 265 "-" "Mozilla/5.0 ...
show more
34.151.222.28 - - [05/Oct/2026:13:07:19 +0200] "GET /.git/config HTTP/1.1" 200 265 "-" "Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; +https://kimi.ai/)" "pingusmc.org"
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 10:43:12
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.151.222.28 (28.222.151.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.151.222.28 (28.222.151.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 06:43:05.831094 2026] [security2:error] [pid 27115:tid 27115] [client 34.151.222.28:45500] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mosheimlib.org"] [uri "/.htpasswd"] [unique_id "asN_OckIo07eeC38Z6cm2AAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
LoneRider
2026-10-05 10:24:00
(17 hours ago)
[05/Oct/2026:12:23:59.635926 +0200] asN6v-8b56h5CMeC_nGo2AAAAA0 34.151.222.28 52748 127.0.0.1 7081
[ ...
show more
[05/Oct/2026:12:23:59.635926 +0200] asN6v-8b56h5CMeC_nGo2AAAAA0 34.151.222.28 52748 127.0.0.1 7081
[05/Oct/2026:12:23:59.883129 +0200] asN6v1ya8DFYhL9q3wYbEgAAAAg 34.151.222.28 36120 127.0.0.1 7081
[05/Oct/2026:12:24:00.113857 +0200] asN6wFbakjTOFP83T5bPQQAAAAM 34.151.222.28 36130 127.0.0.1 7081
...
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-10-05 10:16:47
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.151.222.28 (28.222.151.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.151.222.28 (28.222.151.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 06:16:43.371993 2026] [security2:error] [pid 14712:tid 14712] [client 34.151.222.28:60732] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lunchtimers.org"] [uri "/%2E%2E/%2E%2E/%2E%2E/%2E%2E/.env"] [unique_id "asN5C3VOk9bSljjraWgn6AAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
melroy89
2026-10-05 10:08:06
(17 hours ago)
34.151.222.28 - - [05/Oct/2026:12:07:39 +0200] "GET /z9x8c7v6b5-debug-trigger-libreweb.org HTTP/2.0 ...
show more
34.151.222.28 - - [05/Oct/2026:12:07:39 +0200] "GET /z9x8c7v6b5-debug-trigger-libreweb.org HTTP/2.0" 403 93 "-" "Mozilla/5.0 (compatible; Qwenbot/1.0; +https://qwen.alibaba.com/)" "libreweb.org" 0.001
34.151.222.28 - - [05/Oct/2026:12:07:39 +0200] "GET /upiiyvtsgjo3h59jxlc0 HTTP/2.0" 403 93 "-" "DuckAssistBot/1.1 (https://duckduckgo.com/duckassistbot)" "libreweb.org" 0.001
34.151.222.28 - - [05/Oct/2026:12:07:39 +0200] "POST / HTTP/2.0" 403 93 "-" "Mozilla/5.0 (compatible; Google-Extended; +http://www.google.com/bot.html)" "libreweb.org" 0.001
34.151.222.28 - - [05/Oct/2026:12:07:39 +0200] "POST /graphql HTTP/2.0" 403 64 "https://libreweb.org" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Mobile Safari/537.36" "libreweb.org" 0.000
34.151.222.28 - - [05/Oct/2026:12:07:40 +0200] "POST /api/graphql HTTP/2.0" 403 64 "https://libreweb.org" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Mobile Saf
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 09:52:40
(17 hours ago)
(mod_security) mod_security (id:210580) triggered by 34.151.222.28 (28.222.151.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210580) triggered by 34.151.222.28 (28.222.151.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 05:52:33.473913 2026] [security2:error] [pid 26499:tid 26499] [client 34.151.222.28:0] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "proc/self/environ" at ARGS:file. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/08_Global_Other.conf"] [line "57"] [id "210580"] [rev "2"] [msg "COMODO WAF: OS File Access Attempt||kirklandhighlands.org|F|2"] [data "Matched Data: proc/self/environ found within ARGS:file: /proc/self/environ"] [severity "CRITICAL"] [tag "CWAF"] [tag "Other"] [hostname "kirklandhighlands.org"] [uri "/api/system/fileView"] [unique_id "asNzYc-h1498k0KmueU3iAAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 08:59:14
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.151.222.28 (28.222.151.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.151.222.28 (28.222.151.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 04:59:09.203920 2026] [security2:error] [pid 27360:tid 27360] [client 34.151.222.28:44888] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hbgmccormickfoundation.org"] [uri "/%2e%2e/.env"] [unique_id "asNm3dBpdzAQWVJ52o_IVQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 08:42:05
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.151.222.28 (28.222.151.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.151.222.28 (28.222.151.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 04:42:01.743409 2026] [security2:error] [pid 27222:tid 27222] [client 34.151.222.28:43810] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "glendaleheritage.org"] [uri "/.htpasswd"] [unique_id "asNi2ZzdHhUNGUA40Sc-0gAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-10-05 08:20:00
(19 hours ago)
Not following 301 redirects โ wasted requests | method: GET | path: / | ua: Mozilla/5.0 (Windows NT ...
show more
Not following 301 redirects โ wasted requests | method: GET | path: / | ua: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36 Edg/152.0.0.0
show less
Bad Web Bot