🇳🇱
Site.eu
2026-09-14 00:52:59
(3 hours ago)
Excessive multi-domain requests
Brute-Force
🇺🇸
TAY
2026-09-13 18:36:29
(9 hours ago)
34.26.193.211 - - [14/Sep/2026:02:36:25 +0800] "GET /_nuxt/../.env HTTP/1.1" 404 30454 "-" "Mozilla/ ...
show more
34.26.193.211 - - [14/Sep/2026:02:36:25 +0800] "GET /_nuxt/../.env HTTP/1.1" 404 30454 "-" "Mozilla/5.0 (compatible; KimiBot/1.0; +https://kimi.ai/)"
34.26.193.211 - - [14/Sep/2026:02:36:25 +0800] "GET /@fs/../.env?raw?? HTTP/1.1" 404 30454 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-SearchBot/1.0; [email protected] )"
34.26.193.211 - - [14/Sep/2026:02:36:27 +0800] "GET /static../.env HTTP/1.1" 404 30278 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; [email protected] )"
34.26.193.211 - - [14/Sep/2026:02:36:27 +0800] "GET /media../.env HTTP/1.1" 404 30278 "-" "Mozilla/5.0 (compatible; PanguBot/1.0; +https://www.huaweicloud.com/)"
34.26.193.211 - - [14/Sep/2026:02:36:27 +0800] "GET /files../.env HTTP/1.1" 404 30278 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; [email protected] )"
34.26.193.211 - - [14/Sep/2026:02:36:28 +0800] "GET /uploads../.env HTTP/1.1" 404 30278
...
show less
Brute-Force
🇩🇪
Hazzard
2026-09-13 18:24:58
(9 hours ago)
(mod_security) mod_security triggered on hostname [redacted]): (CF_ENABLE)
SQL Injection
🇬🇷
setupgr
2026-09-13 18:21:31
(9 hours ago)
(mod_security) mod_security (id:11000011) triggered by 34.26.193.211 (US/United States/South Carolin ...
show more
(mod_security) mod_security (id:11000011) triggered by 34.26.193.211 (US/United States/South Carolina/North Charleston/-/[AS396982 Google LLC]): 1 in the last 86400 secs (CF_ENABLE); Ports: *; Direction: inout; Trigger: LF_MODSEC; Logs: [Sun Sep 13 21:21:30.360898 2026] [security2:error] [pid 309813:tid 309875] [remote 34.26.193.211:43646] ModSecurity: Access denied with code 406 (phase 1). Matched phrase "googleusercontent.com" at REMOTE_HOST. [file "/etc/apache2/conf.d/modsec/modsec2.user.conf"] [line "141"] [id "11000011"] [msg "BLOCKED BAD DOMAIN: 211.193.26.34.bc.googleusercontent.com"] [severity "CRITICAL"] [hostname "mail.babis.photo"] [uri "/"] [unique_id "aqbpqVGYFyu-8z7Zli3GrAACwQo"]
show less
Port Scan
🇺🇸
daveoctober
2026-09-13 08:42:38
(19 hours ago)
October Sentinel: honeypot triggered
Bad Web Bot
Web App Attack
🇧🇪
cmbplf
2026-09-13 07:39:22
(20 hours ago)
470 requests with url.path *.env
Brute-Force
Bad Web Bot
🇺🇸
TAY
2026-09-13 06:41:46
(21 hours ago)
34.26.193.211 - - [13/Sep/2026:14:41:45 +0800] "GET /_nuxt/../.env HTTP/1.1" 404 2050 "-" "Mozilla/5 ...
show more
34.26.193.211 - - [13/Sep/2026:14:41:45 +0800] "GET /_nuxt/../.env HTTP/1.1" 404 2050 "-" "Mozilla/5.0 (compatible; YouBot/1.0; +https://you.com/bot)"
34.26.193.211 - - [13/Sep/2026:14:41:45 +0800] "GET /@fs/../.env?raw?? HTTP/1.1" 404 7837 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexitybot)"
34.26.193.211 - - [13/Sep/2026:14:41:45 +0800] "GET /static../.env HTTP/1.1" 404 2050 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexitybot)"
34.26.193.211 - - [13/Sep/2026:14:41:45 +0800] "GET /media../.env HTTP/1.1" 404 2050 "-" "CCBot/2.0 (https://commoncrawl.org/faq/)"
34.26.193.211 - - [13/Sep/2026:14:41:45 +0800] "GET /files../.env HTTP/1.1" 404 2050 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Safari/605.1.15 (Applebot/0.1)"
34.26.193.211 - - [13/Sep/2026:14:41:46 +0800] "GET /assets..
...
show less
Brute-Force
🇺🇸
TPI-Abuse
2026-09-13 06:05:26
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.26.193.211 (211.193.26.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.26.193.211 (211.193.26.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 02:05:22.701937 2026] [security2:error] [pid 7427:tid 7448] [client 34.26.193.211:48138] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "markhoran.pictures"] [uri "/uploads../.env"] [unique_id "aqY9Ire0dXpKWHNn945MFQAAAVE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TAY
2026-09-13 05:30:05
(22 hours ago)
34.26.193.211 - - [13/Sep/2026:13:30:05 +0800] "GET /public/plugins/alertlist/../../../../../../../. ...
show more
34.26.193.211 - - [13/Sep/2026:13:30:05 +0800] "GET /public/plugins/alertlist/../../../../../../../../proc/self/environ HTTP/1.1" 400 2057 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; [email protected] )"
34.26.193.211 - - [13/Sep/2026:13:30:05 +0800] "GET /public/plugins/grafana-clock-panel/../../../../../../../../proc/self/environ HTTP/1.1" 400 2057 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-SearchBot/1.0; [email protected] )"
34.26.193.211 - - [13/Sep/2026:13:30:05 +0800] "GET /api/w/admins/jobs_u/get_log_file/../../../../proc/self/environ HTTP/1.1" 404 7813 "-" "Mozilla/5.0 (compatible; Bravebot/1.0; +https://brave.com/search/)"
34.26.193.211 - - [13/Sep/2026:13:30:05 +0800] "GET /public/plugins/text/../../../../../../../../proc/self/environ HTTP/1.1" 400 2057 "-" "Mozilla/5.0 (compatible; MistralAI-User/1.0; +https://mistral.ai/)"
34.26.193.211 - - [13/Sep/2026:13:30:05 +0800] "GET /api/w/default/j
...
show less
Brute-Force
🇬🇧
consul.to
2026-09-13 05:12:21
(22 hours ago)
Web attack/malicious scanning detected
Web App Attack
🇲🇾
Rizzy
2026-09-13 05:12:20
(22 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 09:00:07
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.26.193.211 (211.193.26.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.26.193.211 (211.193.26.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 04:59:58.739172 2026] [security2:error] [pid 28221:tid 28221] [client 34.26.193.211:56190] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.sailinghonu.com|F|2"] [data ".sailinghonu.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.sailinghonu.com"] [uri "/z9x8c7v6b5-debug-trigger-mail.sailinghonu.com"] [unique_id "aqUUjqgu_R5h5ecVSiTG-AAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 18:19:36
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 34.26.193.211 (211.193.26.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.26.193.211 (211.193.26.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 14:19:30.812107 2026] [security2:error] [pid 5401:tid 5401] [client 34.26.193.211:55226] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||salsberggroup.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "salsberggroup.com"] [uri "/rclone.conf"] [unique_id "aqRGMp3DHy-Ew_2_51sfPwAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
mnsf
2026-09-11 18:05:25
(2 days ago)
Too many Status 40X (18)
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 17:37:37
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 34.26.193.211 (211.193.26.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.26.193.211 (211.193.26.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 13:37:32.900826 2026] [security2:error] [pid 12283:tid 12283] [client 34.26.193.211:43732] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||salazartransfers.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "salazartransfers.com"] [uri "/z9x8c7v6b5-debug-trigger-salazartransfers.com"] [unique_id "aqQ8XM-iwnbQBFuO4nMGqQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack