๐ง๐ช
cmbplf
2026-09-30 19:38:36
(10 minutes ago)
1.060 requests with url.path *.env
221 requests with url.path */@fs/*
Brute-Force
Bad Web Bot
๐จ๐ญ
4server
2026-09-30 18:47:20
(1 hour ago)
[WedSep3020:47:15.0560422026][security2:error][pid2502870:tid2502873][client34.178.21.122:0]ModSecur ...
show more
[WedSep3020:47:15.0560422026][security2:error][pid2502870:tid2502873][client34.178.21.122:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Matchedphrase\"proc/self/\"atARGS:path.[file\"/etc/apache2/conf.d/modsec_rules/10_asl_rules.conf\"][line\"135\"][id\"344360\"][rev\"5\"][msg\"Atomicorp.comWAFRules:UnauthorizedOperatingSystemFileAccessAttempt\"][data\"MatchedData:proc/self/foundwithinARGS:path:/proc/self/environ\"][severity\"CRITICAL\"][tag\"attack-lfi\"][hostname\"www.hosting-e-domini.net\"][uri\"/api/fs/read\"][unique_id\"ar1ZM3GLIj3fjCBSH-IAyQAAAEE\"]
show less
Hacking
Web App Attack
๐ฉ๐ช
LRob
2026-09-30 18:25:22
(1 hour ago)
Wordlist path sweep | method: GET | path: /34iqakdyqyv0n789c8ki, /.vite/manifest.json, /build/manife ...
show more
Wordlist path sweep | method: GET | path: /34iqakdyqyv0n789c8ki, /.vite/manifest.json, /build/manifest.json (+3 more) | ua: Mozilla/5.0 (compatible; DeepSeekBot/1.0; +https://www.deepseek.com/), Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Mobile Safari/537.36 EdgA/153.0.0.0, Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot)
show less
Port Scan
Web App Attack
๐ฉ๐ช
AetherFox
2026-09-30 17:19:43
(2 hours ago)
AetherFox VoidGuard detected: [Wed Sep 30 17:19:42.776961 2026] [authz_core:error] [pid 626047:tid 6 ...
show more
AetherFox VoidGuard detected: [Wed Sep 30 17:19:42.776961 2026] [authz_core:error] [pid 626047:tid 626050] [client 34.178.21.122:56532] AH01630: client denied by server configuration: proxy:https://[MASKED]/
[Wed Sep 30 17:19:42.999820 2026] [authz_core:error] [pid 626047:tid 626087] [client 34.178.21.122:56532] AH01630: client denied by server configuration: proxy:https://[MASKED]/bu0tc9pza4un6jafxozf
[Wed Sep 30 17:19:43.033862 2026] [authz_core:error] [pid 626047:tid 626090] [client 34.178.21.122:56554] AH01630: client denied by server configuration: proxy:https://[MASKED]/z9x8c7v6b5-debug-trigger-draconigen.net
[Wed Sep 30 17:19:43.034285 2026] [authz_core:error] [pid 626047:tid 626053] [client 34.178.21.122:56556] AH01630: client denied by server configuration: proxy:https://[MASKED]/model/info
[Wed Sep 30 17:19:43.035606 2026] [authz_core:error] [pid 626047:tid 626059] [client 34.178.21.122:56542] AH01630: client denied by server configuration: pro
...
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alboweb B.V.
2026-09-30 16:11:16
(3 hours ago)
Bad web bot activity detected by Fail2Ban in plesk-apache-badbot jail
Bad Web Bot
๐ฌ๐ง
consul.to
2026-09-30 15:43:35
(4 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐ซ๐ท
masterguru
2026-09-30 14:34:41
(5 hours ago)
Remote Command Execution: Direct Unix Command Execution. Pattern match "(?i)(?:^|b (932250-195)
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-30 13:59:14
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.178.21.122 (122.21.178.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.178.21.122 (122.21.178.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 09:59:07.951745 2026] [security2:error] [pid 19701:tid 19701] [client 34.178.21.122:42772] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "elegantweddinginvitations.net"] [uri "/.env.js"] [unique_id "ar0Vq7bJ2MLiCe7v7ALvfQAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 13:35:29
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.178.21.122 (122.21.178.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.178.21.122 (122.21.178.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 09:35:22.572114 2026] [security2:error] [pid 4651:tid 4666] [client 34.178.21.122:33636] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.helppeopleshare.net"] [uri "/.env.js"] [unique_id "ar0QGrC6Ai5gio-Pz8DaVQAAAQ0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 12:52:09
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.178.21.122 (122.21.178.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.178.21.122 (122.21.178.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 08:52:04.615719 2026] [security2:error] [pid 3331:tid 3331] [client 34.178.21.122:55506] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.heavenonearthonline.net"] [uri "/.env.js"] [unique_id "ar0F9JsFEO0s5yE2JKPHpAAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-30 12:50:03
(6 hours ago)
| Multiple common web attacks from same source ip. (multiple servers)
Web App Attack
Hacking
SQL Injection
๐บ๐ธ
dot.mg
2026-09-30 12:05:02
(7 hours ago)
Bad behaviour
Web Spam
๐ฎ๐น
VHosting
2026-09-30 11:50:08
(7 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 11:46:15
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.178.21.122 (122.21.178.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.178.21.122 (122.21.178.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 07:46:10.526197 2026] [security2:error] [pid 1266:tid 1266] [client 34.178.21.122:42586] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.gerrytolentino.net"] [uri "/.env.js"] [unique_id "arz2ggVGTgV3m8MVZ-twzAAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
konseptit
2026-09-30 11:31:39
(8 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 34.178.21.122 (122.21.178.34.bc.googleu ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.178.21.122 (122.21.178.34.bc.googleusercontent.com)
show less
SQL Injection