๐บ๐ธ
Charlesiv
2026-09-30 18:00:48
(8 minutes ago)
Triggered Cloudflare WAF (firewallCustom) from NL.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Prot ...
show more
Triggered Cloudflare WAF (firewallCustom) from NL.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Protocol: HTTP/2 (GET method)
Endpoint: /data/.env
Timestamp: 2026-09-30T17:06:27Z
Ray ID: a434d17b59221de3
UA: Mozilla/5.0 (compatible; YouBot/1.0; +https://you.com/bot)
show less
Bad Web Bot
๐ฉ๐ช
AetherFox
2026-09-30 17:49:09
(20 minutes ago)
AetherFox VoidGuard detected: [Wed Sep 30 17:49:08.851139 2026] [authz_core:error] [pid 626047:tid 6 ...
show more
AetherFox VoidGuard detected: [Wed Sep 30 17:49:08.851139 2026] [authz_core:error] [pid 626047:tid 626065] [client 34.178.163.130:34714] AH01630: client denied by server configuration: proxy:https://[MASKED]/
[Wed Sep 30 17:49:08.928691 2026] [authz_core:error] [pid 626047:tid 626071] [client 34.178.163.130:34714] AH01630: client denied by server configuration: proxy:https://[MASKED]/z9x8c7v6b5-debug-trigger-draconigen.net
[Wed Sep 30 17:49:08.941487 2026] [authz_core:error] [pid 626047:tid 626050] [client 34.178.163.130:34714] AH01630: client denied by server configuration: proxy:https://[MASKED]/model/info
[Wed Sep 30 17:49:08.953978 2026] [authz_core:error] [pid 626047:tid 626051] [client 34.178.163.130:34714] AH01630: client denied by server configuration: proxy:https://[MASKED]/
[Wed Sep 30 17:49:08.963985 2026] [authz_core:error] [pid 626047:tid 626060] [client 34.178.163.130:34736] AH01630: client denied by server configuration: proxy:https://5.75
...
show less
Bad Web Bot
Web App Attack
Anonymous
2026-09-30 16:48:24
(1 hour ago)
34.178.163.130 detected on srv01
Brute-Force
๐ช๐ธ
robotstxt
2026-09-30 16:12:35
(1 hour ago)
34.178.163.130 - - [30/Sep/2026:16:12:17 +0000] "GET /?2c09cd=cbbf085ee5.js& HTTP/2.0" 403 2 "-" "Mo ...
show more
34.178.163.130 - - [30/Sep/2026:16:12:17 +0000] "GET /?2c09cd=cbbf085ee5.js& HTTP/2.0" 403 2 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36" "-" edge="34.178.163.130"
34.178.163.130 - - [30/Sep/2026:16:12:18 +0000] "GET /wp-content/plugins/stop-user-enumeration/frontend/js/frontend.js?ver=1.7.8 HTTP/2.0" 403 15065 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36" "-" edge="34.178.163.130"
34.178.163.130 - - [30/Sep/2026:16:12:18 +0000] "GET /z9x8c7v6b5-debug-trigger-wppodcast.net HTTP/2.0" 403 15574 "https://wppodcast.net/z9x8c7v6b5-debug-trigger-wppodcast.net" "Mozilla/5.0 (compatible; YouBot/1.0; +https://you.com/bot)" "-" edge="34.178.163.130"
34.178.163.130 - - [30/Sep/2026:16:12:18 +0000] "GET /wp-content/plugins/podlove-web-player/js/cache.js?ver=5.9.2 HTTP/2.0" 403 15065 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML,
...
show less
Web App Attack
๐ฉ๐ช
rh24
2026-09-30 15:41:33
(2 hours ago)
(badbots) Bad bot user-agent [redacted] from 34.178.163.130 (130.163.178.34.bc.googleusercontent.com ...
show more
(badbots) Bad bot user-agent [redacted] from 34.178.163.130 (130.163.178.34.bc.googleusercontent.com)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-30 15:14:51
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.178.163.130 (130.163.178.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.178.163.130 (130.163.178.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 11:14:43.947662 2026] [security2:error] [pid 10166:tid 10166] [client 34.178.163.130:51112] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.intelligent-design.net"] [uri "/.env.js"] [unique_id "ar0nYxtYlGvVLCWX-vR-5wAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 14:14:20
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.178.163.130 (130.163.178.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.178.163.130 (130.163.178.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 10:14:15.469842 2026] [security2:error] [pid 19461:tid 19461] [client 34.178.163.130:46862] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.davesullivan.net"] [uri "/__vite_rsc_findSourceMapURL"] [unique_id "ar0ZN0kQyoY0tVlrCZzZOwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 13:54:21
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.178.163.130 (130.163.178.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.178.163.130 (130.163.178.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 09:54:14.123803 2026] [security2:error] [pid 26778:tid 26778] [client 34.178.163.130:40324] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.haarr.net"] [uri "/.env.js"] [unique_id "ar0UhtoqDd3qNsVtLwZcNAAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-09-30 13:42:51
(4 hours ago)
OS File Access Attempt. Matched phrase "proc/self/environ" at ARGS:0. (930120-131)
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-30 13:19:12
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.178.163.130 (130.163.178.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.178.163.130 (130.163.178.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 09:19:07.895480 2026] [security2:error] [pid 15462:tid 15462] [client 34.178.163.130:56726] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "verdeprofundo.net"] [uri "/assets../.env"] [unique_id "ar0MS5XUIFic8n1JgTrRogAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
IRISIO
2026-09-30 13:04:51
(5 hours ago)
scans/SQL injection/spam posts : 492 queries
Web App Attack
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-09-30 12:53:27
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.178.163.130 (130.163.178.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.178.163.130 (130.163.178.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 08:53:20.915981 2026] [security2:error] [pid 11641:tid 11641] [client 34.178.163.130:38050] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.fixitz.net"] [uri "/css../.env"] [unique_id "ar0GQIn3qbv9XIQpgDZ3KQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-30 12:40:07
(5 hours ago)
| Common web attack.
Web App Attack
Hacking
SQL Injection
๐ฉ๐ช
ghostwarriors
2026-09-30 12:20:03
(5 hours ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
๐บ๐ธ
ersei.net
2026-09-30 12:04:21
(6 hours ago)
Web app exploiting
Web App Attack