Anonymous
2026-10-08 21:29:39
(18 minutes ago)
34.19.215.12 - - [08/Oct/2026:21:29:39 +0000] "GET /.ssh/config HTTP/2.0" 444 0 "-" "Mozilla/5.0 (c ...
show more
34.19.215.12 - - [08/Oct/2026:21:29:39 +0000] "GET /.ssh/config HTTP/2.0" 444 0 "-" "Mozilla/5.0 (compatible; Bravebot/1.0; +https://brave.com/search/)" "34.19.215.12" "-"
...
show less
Web App Attack
๐ฟ๐ฆ
vanderhost
2026-10-08 20:08:20
(1 hour ago)
[Laravel HoneypotPlus] Automated report - Honeypot access detected on path: /.env.js via rule: regex ...
show more
[Laravel HoneypotPlus] Automated report - Honeypot access detected on path: /.env.js via rule: regex:/^\/\.env/i
show less
Web App Attack
Bad Web Bot
๐ฉ๐ช
rh24
2026-10-08 20:05:51
(1 hour ago)
(secretscan) Secret-Scanner (env/git/ssh/credentials) from 34.19.215.12 (CA/Canada/12.215.19.34.bc.g ...
show more
(secretscan) Secret-Scanner (env/git/ssh/credentials) from 34.19.215.12 (CA/Canada/12.215.19.34.bc.googleusercontent.com)
show less
Hacking
๐จ๐ฟ
akac
2026-10-08 20:04:50
(1 hour ago)
Web vulnerability scanning: HTTP/2 GET /assets/manifest.json
Hacking
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-10-08 19:45:03
(2 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐ธ๐ช
vaia.cloud
2026-10-08 19:45:01
(2 hours ago)
crowdsecurity/http-probing
Brute-Force
Web App Attack
๐ฒ๐พ
Rizzy
2026-10-08 19:38:52
(2 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 19:32:32
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.19.215.12 (12.215.19.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.19.215.12 (12.215.19.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 15:32:24.713847 2026] [security2:error] [pid 31925:tid 31925] [client 34.19.215.12:38968] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||utah17.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "utah17.com"] [uri "/z9x8c7v6b5-debug-trigger-utah17.com"] [unique_id "asfvyH33RZq4PNAwMFdv8wAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-08 19:00:07
(2 hours ago)
suspicious request in access.log
Web App Attack
๐ฉ๐ช
LRob
2026-10-08 18:53:01
(2 hours ago)
Crawler ignoring refusals | ua: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 ( ...
show more
Crawler ignoring refusals | ua: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36, Mozilla/5.0 (compatible; Google-Extended; +http://www.google.com/bot.html), Mozilla/5.0 (compatible; MistralAI-User/1.0; +https://mistral.ai/) (+3 more) | path: /build/manifest.json, /lib/terminal-xhr.php, /fs37bmuk5anr5dezpifz (+6 more)
show less
Bad Web Bot
๐ณ๐ฑ
Alt255
2026-10-08 18:41:22
(3 hours ago)
[ti-05al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-05al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 34.19.215.12 - - [08/Oct/2026:20:41:06 +0200] "GET /.ssh/id_ed25519 HTTP/2.0" 403 372 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-SearchBot/1.0; [email protected] )"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 18:26:59
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.19.215.12 (12.215.19.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.19.215.12 (12.215.19.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 14:26:54.875068 2026] [security2:error] [pid 29503:tid 29503] [client 34.19.215.12:44584] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "usefulendeavors.org"] [uri "/static../.env"] [unique_id "asfgbo8bCEXwwO2I9oAXGQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
AWW-Admin
2026-10-08 18:23:35
(3 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 34.19.215.12 (CA/Canada/12.215.19.34.bc ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.19.215.12 (CA/Canada/12.215.19.34.bc.googleusercontent.com)
show less
SQL Injection
๐ณ๐ฑ
Site.eu
2026-10-08 18:20:25
(3 hours ago)
Excessive multi-domain requests
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-10-08 18:06:09
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.19.215.12 (12.215.19.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.19.215.12 (12.215.19.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 14:06:05.627833 2026] [security2:error] [pid 30933:tid 30933] [client 34.19.215.12:33622] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "us-war-crimes-commission.org"] [uri "/.htpasswd"] [unique_id "asfbjW53gTgbo_fnWSJRVwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack