🇺🇸
Charlesiv
2026-09-21 10:02:39
(37 minutes ago)
Triggered Cloudflare WAF (firewallCustom) from SG.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Prot ...
show more
Triggered Cloudflare WAF (firewallCustom) from SG.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Protocol: HTTP/2 (GET method)
Endpoint: /
Timestamp: 2026-09-21T06:12:24Z
Ray ID: a3e6eb04bbe19b99
UA: Mozilla/5.0 (compatible; cohere-ai; +https://cohere.com/crawler)
show less
Bad Web Bot
Anonymous
2026-09-21 08:17:14
(2 hours ago)
34.21.128.45 - - [20/Sep/2026:23:59:09 -0500] "GET /.env.save HTTP/1.1" 403 199 "-" "Mozilla/5.0 (co ...
show more
34.21.128.45 - - [20/Sep/2026:23:59:09 -0500] "GET /.env.save HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot)" 34.21.128.45
34.21.128.45 - - [20/Sep/2026:23:59:09 -0500] "GET /.env.stage HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; Qwenbot/1.0; +https://qwen.alibaba.com/)" 34.21.128.45
34.21.128.45 - - [20/Sep/2026:23:59:09 -0500] "GET /.env.live HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; xAI-Grok/1.0; +https://x.ai/)" 34.21.128.45
34.21.128.45 - - [20/Sep/2026:23:59:09 -0500] "GET /.env.www HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; Bytespider; [email protected] ) AppleWebKit/537.36" 34.21.128.45
34.21.128.45 - - [20/Sep/2026:23:59:09 -0500] "GET /.env.prod HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; YouBot/1.0; +https://you.com/bot)" 34.21.128.45
34.21.128.45 - - [20/Sep/2026:23:59:09 -0500] "GET /.env HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.ht
...
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-09-21 06:11:27
(4 hours ago)
Web attack/malicious scanning detected
Web App Attack
🇩🇪
LRob
2026-09-21 05:46:19
(4 hours ago)
Enumerating paths that do not exist (scanning) | method: GET | path: /static/manifest.json (+5 more) ...
show more
Enumerating paths that do not exist (scanning) | method: GET | path: /static/manifest.json (+5 more) | ua: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36 Edg/153.0.0.0 (+3 more) | 2026-09-21 05:46 UTC
show less
Port Scan
Web App Attack
🇺🇸
TPI-Abuse
2026-09-21 05:44:26
(4 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.21.128.45 (45.128.21.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.21.128.45 (45.128.21.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 01:44:20.178667 2026] [security2:error] [pid 21573:tid 21573] [client 34.21.128.45:46214] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.robcruickshank.net|F|2"] [data ".key"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.robcruickshank.net"] [uri "/ssl/localhost.key"] [unique_id "arDENKwIBklSpCkajMvjVwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
PacketFilter
2026-09-21 05:24:43
(5 hours ago)
Fail2Ban
Hacking
Web App Attack
🇷🇴
iulianh
2026-09-21 04:36:02
(6 hours ago)
80,443
Brute-Force
SSH
🇺🇸
TPI-Abuse
2026-09-21 04:29:27
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.21.128.45 (45.128.21.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.21.128.45 (45.128.21.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 00:29:25.323424 2026] [security2:error] [pid 31052:tid 31052] [client 34.21.128.45:60414] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.theledman.net"] [uri "/.env.js"] [unique_id "arCypePrpHGO_VdCwwr7XgAAACk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
Starburst SysOp Team
2026-09-21 04:07:07
(6 hours ago)
HTTP header is restricted by policy (/x-middleware-subrequest/). String match within "/content-encod ...
show more
HTTP header is restricted by policy (/x-middleware-subrequest/). String match within "/content-encoding/ /proxy/ /lock-token/ /content-range/ /if/ /x-http-method-override/ /x-http-method/ /x-method-override/ /x-middleware-subrequest/ /expect/" at TX:header_name_920450_x-middleware-subrequest. (920450-mnz6-7)
show less
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-21 04:03:20
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.21.128.45 (45.128.21.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.21.128.45 (45.128.21.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 00:03:13.026307 2026] [security2:error] [pid 32253:tid 32253] [client 34.21.128.45:36074] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.psystems.net"] [uri "/.git/config"] [unique_id "arCsgSu8QO6XYjPIVE_1IAAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
pscriptos
2026-09-21 03:39:08
(7 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/appsec-vpatch
Web App Attack
🇺🇸
TPI-Abuse
2026-09-21 03:33:56
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.21.128.45 (45.128.21.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.21.128.45 (45.128.21.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 23:33:48.622452 2026] [security2:error] [pid 6241:tid 6241] [client 34.21.128.45:45060] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.angelonearth.net"] [uri "/core/.env"] [unique_id "arClnKiaErEGw_pBuPgPRQAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-21 02:51:17
(7 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.21.128.45 (45.128.21.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.21.128.45 (45.128.21.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 22:51:10.724887 2026] [security2:error] [pid 27643:tid 27643] [client 34.21.128.45:0] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.portfoliolighting.net|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.portfoliolighting.net"] [uri "/rclone.conf"] [unique_id "arCbnh8x7AjizQe424IskQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-21 02:32:02
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.21.128.45 (45.128.21.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.21.128.45 (45.128.21.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 22:31:56.318457 2026] [security2:error] [pid 6499:tid 6499] [client 34.21.128.45:34420] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "watsoncousins.net"] [uri "/.env"] [unique_id "arCXHKWHE2d0DwnhxastVAAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
Charlesiv
2026-09-21 02:12:10
(8 hours ago)
Triggered Cloudflare WAF (firewallCustom) from SG.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Prot ...
show more
Triggered Cloudflare WAF (firewallCustom) from SG.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Protocol: HTTP/1.1 (POST method)
Endpoint: /api
Timestamp: 2026-09-21T00:28:44Z
Ray ID: a3e4f3974fb69c4d
UA: Mozilla/5.0 (compatible; Google-Extended; +http://www.google.com/bot.html)
show less
Bad Web Bot