๐ฉ๐ช
updown.io
2026-10-07 04:01:47
(2 days ago)
{"level":"info","ts":1791345706.6947932,"logger":"http.log.access.log1","msg":"handled request","req ...
show more
{"level":"info","ts":1791345706.6947932,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"34.159.130.149","remote_port":"41402","client_ip":"34.159.130.149","proto":"HTTP/2.0","method":"GET","host":"d2jsp-status.own3r.com","uri":"/media../.env","headers":{"Accept-Encoding":["gzip"],"Accept":["*/*"],"Cookie":["REDACTED"],"X-Middleware-Subrequest":["src/middleware:nowaf:src/middleware:src/middleware:src/middleware:src/middleware:middleware:middleware:nowaf:middleware:middleware:middleware:pages/_middleware"],"X-Nextjs-Data":["1"],"User-Agent":["Mozilla/5.0 (compatible; Bravebot/1.0; +https://brave.com/search/)"]},"tls":{"resumed":false,"version":772,"cipher_suite":4865,"proto":"h2","server_name":"d2jsp-status.own3r.com","ech":false}},"bytes_read":0,"user_id":"","duration":0.000207756,"size":0,"status":429,"resp_headers":{"Server":["Caddy"],"Alt-Svc":["h3=\":443\"; ma=2592000"],"Retry-After":["1"]}}
{"level":"info","ts":1791345706.6988475,"logger":"http.log.a
...
show less
DDoS Attack
Web App Attack
๐ง๐ช
cmbplf
2026-10-07 03:24:37
(2 days ago)
579 requests with url.path *.env
277 requests with url.path */@fs/*
Brute-Force
Bad Web Bot
๐ช๐ธ
robotstxt
2026-10-07 03:05:03
(2 days ago)
34.159.130.149 - - [07/Oct/2026:03:04:01 +0000] "GET /auth/login HTTP/2.0" 403 165 "-" "Mozilla/5.0 ...
show more
34.159.130.149 - - [07/Oct/2026:03:04:01 +0000] "GET /auth/login HTTP/2.0" 403 165 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Mobile Safari/537.36 EdgA/153.0.0.0" "-" edge="34.159.130.149"
34.159.130.149 - - [07/Oct/2026:03:04:01 +0000] "GET /auth HTTP/2.0" 403 165 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Mobile Safari/537.36 EdgA/153.0.0.0" "-" edge="34.159.130.149"
34.159.130.149 - - [07/Oct/2026:03:04:01 +0000] "GET /login HTTP/2.0" 403 165 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Mobile Safari/537.36 EdgA/153.0.0.0" "-" edge="34.159.130.149"
34.159.130.149 - - [07/Oct/2026:03:04:01 +0000] "POST / HTTP/2.0" 403 189 "-" "Mozilla/5.0 (compatible; GrokBot/1.0; +https://x.ai/)" "-" edge="34.159.130.149"
34.159.130.149 - - [07/Oct/2026:03:04:01 +0000] "GET /users/login HTTP/2.0" 403 165 "-" "Mozilla/5.0 (Linux; Android 10; K) A
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 02:53:08
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 34.159.130.149 (149.130.159.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 34.159.130.149 (149.130.159.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 22:53:03.131264 2026] [security2:error] [pid 15200:tid 15200] [client 34.159.130.149:54838] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||cuteswimwear.brazilianbottom.com|F|2"] [data ".brazilianbottom.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "cuteswimwear.brazilianbottom.com"] [uri "/z9x8c7v6b5-debug-trigger-cuteswimwear.brazilianbottom.com"] [unique_id "asW0D194dxtQM4wMR9w5nQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-06 14:17:22
(3 days ago)
34.159.130.149 - - [06/Oct/2026:16:17:17 +0200] "GET /assets/manifest.json HTTP/1.1" 404 60368
34.15 ...
show more
34.159.130.149 - - [06/Oct/2026:16:17:17 +0200] "GET /assets/manifest.json HTTP/1.1" 404 60368
34.159.130.149 - - [06/Oct/2026:16:17:17 +0200] "GET /static/manifest.json HTTP/1.1" 404 65202
34.159.130.149 - - [06/Oct/2026:16:17:17 +0200] "GET /manifest.json HTTP/1.1" 404 60346
34.159.130.149 - - [06/Oct/2026:16:17:17 +0200] "GET /asset-manifest.json HTTP/1.1" 404 65198
34.159.130.149 - - [06/Oct/2026:16:17:17 +0200] "GET /webpack-stats.json HTTP/1.1" 404 65195
34.159.130.149 - - [06/Oct/2026:16:17:17 +0200] "GET /dist/manifest.json HTTP/1.1" 404 60362
34.159.130.149 - - [06/Oct/2026:16:17:17 +0200] "GET /z9x8c7v6b5-debug-trigger-veravalor.com HTTP/1.1" 404 65255
34.159.130.149 - - [06/Oct/2026:16:17:18 +0200] "GET /graphql HTTP/1.1" 404 60328
34.159.130.149 - - [06/Oct/2026:16:17:19 +0200] "GET /v1/graphql HTTP/1.1" 404 60338
34.159.130.149 - - [06/Oct/2026:16:17:21 +0200] "GET /public/admin.json HTTP/1.1" 404 60359
...
show less
Web Spam
Web App Attack
๐ณ๐ฑ
Site.eu
2026-10-06 14:09:27
(3 days ago)
Excessive multi-domain requests
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-10-06 14:08:19
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 34.159.130.149 (149.130.159.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 34.159.130.149 (149.130.159.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 10:08:12.289500 2026] [security2:error] [pid 11559:tid 11559] [client 34.159.130.149:60696] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||tonylai.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "tonylai.com"] [uri "/z9x8c7v6b5-debug-trigger-tonylai.com"] [unique_id "asUAzB-B_zgMmbfgZTa44QAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
zXero
2026-10-06 13:52:01
(3 days ago)
Fail2Ban automatic report - jail: web-exploit
Brute-Force
SSH
DDoS Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 13:28:26
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 34.159.130.149 (149.130.159.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 34.159.130.149 (149.130.159.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 09:28:22.757263 2026] [security2:error] [pid 30064:tid 30064] [client 34.159.130.149:48994] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||postermodelsworldwideinc.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "postermodelsworldwideinc.com"] [uri "/z9x8c7v6b5-debug-trigger-postermodelsworldwideinc.com"] [unique_id "asT3dnSoSKm7k437gPdQ6AAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
on-com
2026-10-06 13:14:17
(3 days ago)
URL scan
Brute-Force
Web App Attack
๐ท๐ด
clauss
2026-10-06 12:46:09
(3 days ago)
34.159.130.149 - - [06/Oct/2026:15:46:08 +0300] "GET /secrets.yml HTTP/2.0" 403 207 "-" "Mozilla/5.0 ...
show more
34.159.130.149 - - [06/Oct/2026:15:46:08 +0300] "GET /secrets.yml HTTP/2.0" 403 207 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-SearchBot/1.0; [email protected] )"
34.159.130.149 - - [06/Oct/2026:15:46:08 +0300] "GET /firebase-adminsdk.json HTTP/2.0" 403 207 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-SearchBot/1.0; [email protected] )"
...
show less
Web App Attack
๐ซ๐ท
GoodOldTOS
2026-10-06 12:15:56
(3 days ago)
Highly suspect IP
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 12:15:24
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 34.159.130.149 (149.130.159.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 34.159.130.149 (149.130.159.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 08:15:16.241925 2026] [security2:error] [pid 7986:tid 7986] [client 34.159.130.149:52518] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||goatedlottosecrets.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "goatedlottosecrets.com"] [uri "/z9x8c7v6b5-debug-trigger-goatedlottosecrets.com"] [unique_id "asTmVPrkZki38MpEE0GwZwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
bazter.pro
2026-10-06 12:13:38
(3 days ago)
Fail2Ban: plesk-bot-aggressive - 15 failures
Port Scan
Bad Web Bot
Web App Attack
๐ฉ๐ช
TheDjRider
2026-10-06 12:03:56
(3 days ago)
CrowdSec detected Web application reconnaissance. Scenario: crowdsecurity/http-probing. Automatic ba ...
show more
CrowdSec detected Web application reconnaissance. Scenario: crowdsecurity/http-probing. Automatic ban triggered. Detection time (UTC): 2026-10-06T12:03:48.237589237Z. Context: http_status=404, http_status=403
show less
Web App Attack