Anonymous
2026-09-30 19:23:26
(4 days ago)
34.158.11.136 - - [30/Sep/2026:14:23:25 -0500] "GET /.env.js HTTP/1.1" 403 199 "-" "Mozilla/5.0 (com ...
show more
34.158.11.136 - - [30/Sep/2026:14:23:25 -0500] "GET /.env.js HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; Meta-ExternalAgent/1.0; +https://developers.facebook.com/docs/sharing/webmasters/crawler)" 34.158.11.136
34.158.11.136 - - [30/Sep/2026:14:23:25 -0500] "GET /.env.local?import&raw HTTP/1.1" 403 199 "-" "CCBot/2.0 (https://commoncrawl.org/faq/)" 34.158.11.136
34.158.11.136 - - [30/Sep/2026:14:23:25 -0500] "GET /.env.production?raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; xAI-Grok/1.0; +https://x.ai/)" 34.158.11.136
34.158.11.136 - - [30/Sep/2026:14:23:25 -0500] "GET /.env.production?import&raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; [email protected] )" 34.158.11.136
34.158.11.136 - - [30/Sep/2026:14:23:25 -0500] "GET /.env.development?raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; [email protected] )" 34.158.11.136
34.158.11.136 - - [30/Sep/20
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
ciccio diddo
2026-09-30 18:36:20
(4 days ago)
High Burst multiple 40X port:Tcp/80,443
Brute-Force
Web App Attack
๐ฉ๐ช
Sรฉfora Srl
2026-09-30 18:18:35
(4 days ago)
crowdsecurity/http-probing detected by CrowdSec
Web App Attack
๐บ๐ธ
Charlesiv
2026-09-30 18:00:52
(4 days ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Prot ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Protocol: HTTP/2 (GET method)
Endpoint: /actuator/gateway/routes
Timestamp: 2026-09-30T16:50:07Z
Ray ID: a434b98f8eb6d95b
UA: Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)
show less
Bad Web Bot
๐ฉ๐ช
Sรฉfora Srl
2026-09-30 18:00:36
(4 days ago)
Failed attempt detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
๐ฉ๐ช
Hagen Schoebel
2026-09-30 17:24:03
(4 days ago)
Blocked by CrowdSec - Enabling body inspection (US)
Port Scan
Brute-Force
Web App Attack
SSH
๐ฆ๐บ
clapper
2026-09-30 16:57:31
(4 days ago)
(mod_security) mod_security (id:980001) triggered by 34.158.11.136 (US/United States/136.11.158.34.b ...
show more
(mod_security) mod_security (id:980001) triggered by 34.158.11.136 (US/United States/136.11.158.34.bc.googleusercontent.com): 3 in the last 3600 secs; ID: LUC
show less
Brute-Force
Bad Web Bot
Anonymous
2026-09-30 16:30:08
(4 days ago)
34.158.11.136 - - [30/Sep/2026:18:30:00 +0200] "GET /test.php HTTP/2.0" 404 106 "-" "Mozilla/5.0 (co ...
show more
34.158.11.136 - - [30/Sep/2026:18:30:00 +0200] "GET /test.php HTTP/2.0" 404 106 "-" "Mozilla/5.0 (compatible; Google-Extended; +http://www.google.com/bot.html)"
...
show less
Web App Attack
๐ต๐ฑ
sefinek.net
2026-09-30 16:00:26
(4 days ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action: BLOCK | Protocol: HTTP/2 (POST) | Endpoin ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action: BLOCK | Protocol: HTTP/2 (POST) | Endpoint: /index.php | UA: Mozilla/5.0 (compatible; Qwenbot/1.0; +https://qwen.alibaba.com/) โข Generated by: github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-30 15:24:24
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.158.11.136 (136.11.158.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.158.11.136 (136.11.158.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 11:24:19.341504 2026] [security2:error] [pid 27888:tid 27888] [client 34.158.11.136:46402] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "verdeprofundo.net"] [uri "/static../.env"] [unique_id "ar0po-EDYYFKSl7ujV0unwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
firestorm
2026-09-30 15:22:21
(4 days ago)
34.158.11.136 - - [30/Sep/2026:17:22:21 +0200] "GET /static/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2fproc ...
show more
34.158.11.136 - - [30/Sep/2026:17:22:21 +0200] "GET /static/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2fproc/self/environ HTTP/1.1" 400 150 "-" "-"
34.158.11.136 - - [30/Sep/2026:17:22:21 +0200] "GET /resources/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f.env HTTP/1.1" 400 150 "-" "-"
34.158.11.136 - - [30/Sep/2026:17:22:21 +0200] "GET /static/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f.env HTTP/1.1" 400 150 "-" "-"
...
show less
Brute-Force
Web App Attack
๐ซ๐ท
masterguru
2026-09-30 14:36:31
(4 days ago)
BAD BOT - Detected and Blocked.. Matched phrase "ccbot" at REQUEST_HEADERS:User-Agent. (1100000-196)
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-30 14:22:53
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.158.11.136 (136.11.158.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.158.11.136 (136.11.158.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 10:22:48.723346 2026] [security2:error] [pid 421:tid 421] [client 34.158.11.136:55636] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.brupharm.net"] [uri "/static../.env"] [unique_id "ar0bOHcdWZJHPBuyYsWHKgAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 14:05:27
(4 days ago)
(mod_security) mod_security (id:218420) triggered by 34.158.11.136 (136.11.158.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:218420) triggered by 34.158.11.136 (136.11.158.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 10:05:22.867234 2026] [security2:error] [pid 11342:tid 11342] [client 34.158.11.136:50016] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i)php://(std(in|out|err)|(in|out)put|fd|memory|temp|filter)" at ARGS_NAMES:\\xadd allow_url_include=1 \\xadd auto_prepend_file=php://input. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/21_PHP_PHPGen.conf"] [line "22"] [id "218420"] [rev "2"] [msg "COMODO WAF: PHP Injection Attack: I/O Stream Found||zost.net|F|2"] [data "Matched Data: php://input found within ARGS_NAMES:\\x5cxadd allow_url_include=1 \\x5cxadd auto_prepend_file=php://input: \\xadd allow_url_include=1 \\xadd auto_prepend_file=php://input"] [severity "CRITICAL"] [tag "CWAF"] [tag "PHPGen"] [hostname "zost.net"] [uri "/index.php"] [unique_id "ar0XIvvB1CMsnsA6laYkkgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 13:48:20
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.158.11.136 (136.11.158.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.158.11.136 (136.11.158.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 09:48:13.349322 2026] [security2:error] [pid 28470:tid 28470] [client 34.158.11.136:39458] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.creationorevolution.net"] [uri "/.env.dev"] [unique_id "ar0THWHy4QsPyiROYZynygAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack