๐ญ๐บ
bcsaba
2026-09-21 00:55:35
(1 hour ago)
Probing for .git:
34.24.31.90 - - [21/Sep/2026:02:55:33 +0200] "GET /.git/config HTTP/2.0" 400 230 " ...
show more
Probing for .git:
34.24.31.90 - - [21/Sep/2026:02:55:33 +0200] "GET /.git/config HTTP/2.0" 400 230 "-" "Mozilla/5.0 (compatible; xAI-Grok/1.0; +https://x.ai/)"
show less
Web App Attack
๐ฉ๐ช
zumbo.net
2026-09-21 00:13:45
(2 hours ago)
[Mon Sep 21 03:13:39.963466 2026] [proxy_fcgi:error] [pid 307183:tid 307195] [client 34.24.31.90:0] ...
show more
[Mon Sep 21 03:13:39.963466 2026] [proxy_fcgi:error] [pid 307183:tid 307195] [client 34.24.31.90:0] AH01071: Got error 'Primary script unknown'
[Mon Sep 21 03:13:40.019566 2026] [proxy_fcgi:error] [pid 318072:tid 318083] [client 34.24.31.90:0] AH01071: Got error 'Primary script unknown'
[Mon Sep 21 03:13:40.181810 2026] [proxy_fcgi:error] [pid 316968:tid 316981] [client 34.24.31.90:0] AH01071: Got error 'Primary script unknown'
[Mon Sep 21 03:13:40.323917 2026] [proxy_fcgi:error] [pid 316968:tid 316977] [client 34.24.31.90:0] AH01071: Got error 'Primary script unknown'
[Mon Sep 21 03:13:44.615703 2026] [proxy_fcgi:error] [pid 316968:tid 316993] [client 34.24.31.90:0] AH01071: Got error 'Primary script unknown'
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 00:10:01
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.24.31.90 (90.31.24.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.24.31.90 (90.31.24.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 20:09:56.504182 2026] [security2:error] [pid 15223:tid 15252] [client 34.24.31.90:45958] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.appraisalteam.net"] [uri "/config/.env"] [unique_id "arB11J16dRf0xsVxTmQbwQAAANI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ญ๐บ
kranem
2026-09-21 00:00:24
(2 hours ago)
Triggered Cloudflare WAF from US.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Protocol: HTTP/2 (GET ...
show more
Triggered Cloudflare WAF from US.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Protocol: HTTP/2 (GET method)
Endpoint: /.idea/WebServers.xml
Timestamp: 2026-09-20T22:30:40Z
User-Agent: Mozilla/5.0 (compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot)
show less
Bad Web Bot
๐ญ๐บ
bcsaba
2026-09-20 23:18:27
(2 hours ago)
Looking for json file on web server
34.24.31.90 - - [21/Sep/2026:01:18:26 +0200] "GET /__/firebase/i ...
show more
Looking for json file on web server
34.24.31.90 - - [21/Sep/2026:01:18:26 +0200] "GET /__/firebase/init.json HTTP/2.0" 400 230 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexitybot)"
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 23:02:49
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.24.31.90 (90.31.24.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.24.31.90 (90.31.24.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 19:02:45.830503 2026] [security2:error] [pid 3166:tid 3166] [client 34.24.31.90:47538] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.zavijava.net"] [uri "/.git/config"] [unique_id "arBmFfT4vsMUUvQYfjOrZwAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-20 22:55:54
(3 hours ago)
GET /@fs/app/.env?raw?? HTTP/1.1
...
Web App Attack
๐ญ๐บ
bcsaba
2026-09-20 21:49:08
(4 hours ago)
Looking for json file on web server
34.24.31.90 - - [20/Sep/2026:23:49:06 +0200] "GET /__/firebase/i ...
show more
Looking for json file on web server
34.24.31.90 - - [20/Sep/2026:23:49:06 +0200] "GET /__/firebase/init.json HTTP/2.0" 400 230 "-" "Mozilla/5.0 (compatible; ChatGLM-Spider/1.0; +https://zhipuai.cn/)"
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 20:51:05
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.24.31.90 (90.31.24.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.24.31.90 (90.31.24.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 16:51:00.491696 2026] [security2:error] [pid 647:tid 647] [client 34.24.31.90:37036] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.zabyte.net"] [uri "/.git/config"] [unique_id "arBHNPHnhFX1nb28OaMBCwAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ญ๐บ
bcsaba
2026-09-20 20:32:30
(5 hours ago)
Probing for .env file:
34.24.31.90 - - [20/Sep/2026:22:32:28 +0200] "GET /.env.example HTTP/2.0" 400 ...
show more
Probing for .env file:
34.24.31.90 - - [20/Sep/2026:22:32:28 +0200] "GET /.env.example HTTP/2.0" 400 230 "-" "Mozilla/5.0 (compatible; MoonshotBot/1.0; +https://kimi.ai/)"
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 20:27:34
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.24.31.90 (90.31.24.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.24.31.90 (90.31.24.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 16:27:28.667819 2026] [security2:error] [pid 29912:tid 29912] [client 34.24.31.90:35916] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "zost.net"] [uri "/.git/HEAD"] [unique_id "arBBsFe4Bu4fcBBBKrK9tAAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-09-20 20:25:03
(5 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐ฉ๐ช
gadix
2026-09-20 20:23:14
(5 hours ago)
[20/Sep/2026:22:23:12.726744 +0200] arBAsNDXYXTG6sOJ-SH7NgAAAIw 34.24.31.90 36756 127.0.0.1 7081
[20 ...
show more
[20/Sep/2026:22:23:12.726744 +0200] arBAsNDXYXTG6sOJ-SH7NgAAAIw 34.24.31.90 36756 127.0.0.1 7081
[20/Sep/2026:22:23:12.733021 +0200] arBAsAo1cXcvjx6qivZ7xQAAAEc 34.24.31.90 36764 127.0.0.1 7081
[20/Se
...
show less
Web App Attack
๐ณ๐ฑ
Savvii
2026-09-20 20:03:56
(6 hours ago)
20 attempts against mh-misbehave-ban on redirect
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-20 19:42:40
(6 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking