πΊπΈ
TPI-Abuse
2026-09-21 03:37:28
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.24.160.86 (86.160.24.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.24.160.86 (86.160.24.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 23:37:21.430949 2026] [security2:error] [pid 15745:tid 15745] [client 34.24.160.86:39648] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.bencramer.net"] [uri "/.git/HEAD"] [unique_id "arCmcYWa5IOKrd_JdjCt9QAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
updown.io
2026-09-21 03:17:18
(1 week ago)
{"level":"info","ts":1789960636.1721833,"logger":"http.log.access.log1","msg":"handled request","req ...
show more
{"level":"info","ts":1789960636.1721833,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"34.24.160.86","remote_port":"40574","client_ip":"34.24.160.86","proto":"HTTP/2.0","method":"POST","host":"status.amecelectric.net","uri":"/graphql","headers":{"Content-Length":["86"],"User-Agent":["Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36 Edg/152.0.0.0"],"Sec-Ch-Ua":["\"Chromium\";v=\"152\", \"Not?A_Brand\";v=\"24\", \"Microsoft Edge\";v=\"152\""],"Sec-Ch-Ua-Platform":["\"Windows\""],"Accept":["*/*"],"Content-Type":["application/json"],"Cookie":["REDACTED"],"Priority":["u=1, i"],"Sec-Fetch-Dest":["empty"],"Sec-Fetch-Mode":["cors"],"Accept-Encoding":["gzip, deflate, br, zstd"],"Sec-Fetch-Site":["same-origin"],"Sec-Ch-Ua-Mobile":["?0"],"Origin":["https://status.amecelectric.net"],"Referer":["https://status.amecelectric.net"],"Accept-Language":["en-US,en;q=0.9"]},"tls":{"resumed":false,"version":772,"
...
show less
DDoS Attack
Web App Attack
π¬π§
consul.to
2026-09-21 03:09:54
(1 week ago)
Web attack/malicious scanning detected
Web App Attack
π©πͺ
SiyCah
2026-09-21 03:00:02
(1 week ago)
IP banned by fail2ban; banned in jail apache-modsecurity. Report generated by fail2abuseipdb.
Hacking
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-21 02:29:10
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.24.160.86 (86.160.24.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.24.160.86 (86.160.24.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 22:29:03.924216 2026] [security2:error] [pid 19119:tid 19119] [client 34.24.160.86:51486] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.cageliners.net"] [uri "/.git/config"] [unique_id "arCWb021_4Ay8ZECH7M97gAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
masterguru
2026-09-21 02:23:22
(1 week ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.24.160.86 (US/United States/86.160 ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.24.160.86 (US/United States/86.160.24.34.bc.googleusercontent.com): 2 in the last 3600 secs (0-196)
show less
Hacking
πΊπΈ
TPI-Abuse
2026-09-21 01:34:30
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.24.160.86 (86.160.24.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.24.160.86 (86.160.24.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 21:34:24.262762 2026] [security2:error] [pid 15609:tid 15609] [client 34.24.160.86:51206] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kmp.net"] [uri "/apps/.env"] [unique_id "arCJoOX7_BtwEhHqT3ajHwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-21 00:02:26
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.24.160.86 (86.160.24.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.24.160.86 (86.160.24.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 20:02:19.352188 2026] [security2:error] [pid 13869:tid 13869] [client 34.24.160.86:34598] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.crazycoin.net"] [uri "/@fs/var/task/.env"] [unique_id "arB0C6A4A5I13QeHKf47ZQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-20 23:42:17
(1 week ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
Anonymous
2026-09-20 23:35:13
(1 week ago)
34.24.160.86 - - [20/Sep/2026:18:35:12 -0500] "GET /index.php?s=index/\\think\\app/invokefunction&fu ...
show more
34.24.160.86 - - [20/Sep/2026:18:35:12 -0500] "GET /index.php?s=index/\\think\\app/invokefunction&function=call_user_func_array&vars[0]=system&vars[1][]=env HTTP/2.0" 301 348 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexitybot)"
34.24.160.86 - - [20/Sep/2026:18:35:12 -0500] "GET /index.php?s=index/\\think\\app/invokefunction&function=call_user_func_array&vars[0]=file_get_contents&vars[1][]=.env HTTP/2.0" 301 360 "-" "Mozilla/5.0 (compatible; Qwenbot/1.0; +https://qwen.alibaba.com/)"
34.24.160.86 - - [20/Sep/2026:18:35:12 -0500] "GET /index.php?s=index/\\think\\app/invokefunction&function=call_user_func_array&vars[0]=system&vars[1][]=env HTTP/2.0" 307 352 "https://beastmark.net/index.php?s=index/\\think\\app/invokefunction&function=call_user_func_array&vars[0]=system&vars[1][]=env" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexitybot)"
...
show less
Brute-Force
Web App Attack
π³π±
Mangelot Hosting
2026-09-20 22:49:37
(1 week ago)
(modsecurity) srv201 ModSecurity 34.24.160.86 (US/United States/86.160.24.34.bc.googleusercontent.co ...
show more
(modsecurity) srv201 ModSecurity 34.24.160.86 (US/United States/86.160.24.34.bc.googleusercontent.com): 30 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-20 22:49:15
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.24.160.86 (86.160.24.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.24.160.86 (86.160.24.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 18:49:10.891333 2026] [security2:error] [pid 2414:tid 2414] [client 34.24.160.86:51324] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.tracybur.net"] [uri "/.git/config"] [unique_id "arBi5uPQUo12LqbgD_G81AAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-20 22:12:42
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.24.160.86 (86.160.24.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.24.160.86 (86.160.24.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 18:12:38.686931 2026] [security2:error] [pid 27824:tid 27824] [client 34.24.160.86:33858] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.aviil.net"] [uri "/.git/HEAD"] [unique_id "arBaVhyE_Cs9ynIeU227vgAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-20 21:33:20
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.24.160.86 (86.160.24.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.24.160.86 (86.160.24.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 17:33:12.494905 2026] [security2:error] [pid 6425:tid 6425] [client 34.24.160.86:57580] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.keyston.net"] [uri "/client/.env"] [unique_id "arBRGOyXahz2BbPjQv8CtQAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-20 21:20:47
(1 week ago)
[BestVouchers.net] Honeypot trap triggered | Path: /.env | Time: 2026-09-20T21:20:47.297Z | UA: Mozi ...
show more
[BestVouchers.net] Honeypot trap triggered | Path: /.env | Time: 2026-09-20T21:20:47.297Z | UA: Mozilla/5.0 (compatible; GrokBot/1.0; +https://x.ai/) | Action: Automatically blocked for 24h and reported
show less
Bad Web Bot
Web App Attack