🇪🇸
masterguru
2026-09-13 07:31:33
(1 minute ago)
BAD BOT - Detected and Blocked.. Matched phrase "PerplexityBot" at REQUEST_HEADERS:user-agent. (1100 ...
show more
BAD BOT - Detected and Blocked.. Matched phrase "PerplexityBot" at REQUEST_HEADERS:user-agent. (1100000-122)
show less
Bad Web Bot
🇫🇷
ELYAZ
2026-09-13 07:29:30
(3 minutes ago)
(y3) Failed access -byebye- from 34.26.3.148 (US/United States/148.3.26.34.bc.googleusercontent.com) ...
show more
(y3) Failed access -byebye- from 34.26.3.148 (US/United States/148.3.26.34.bc.googleusercontent.com): (CF_ENABLE)
show less
Hacking
🇧🇷
dominioz
2026-09-13 06:58:28
(34 minutes ago)
2026-09-13 06:58:22 GET /config.json - - 34.26.3.148 HTTP/2 Mozilla/5.0+AppleWebKit/537.36+(KHTML,+l ...
show more
2026-09-13 06:58:22 GET /config.json - - 34.26.3.148 HTTP/2 Mozilla/5.0+AppleWebKit/537.36+(KHTML,+like+Gecko;+compatible;+ClaudeBot/1.0;[email protected] ) - 301 466
2026-09-13 06:58:22 GET /settings.json - - 34.26.3.148 HTTP/2 Mozilla/5.0+(compatible;+Qwenbot/1.0;++https://qwen.alibaba.com/) - 301 466
2026-09-13 06:58:22 GET /config.js - - 34.26.3.148 HTTP/2 Mozilla/5.0+AppleWebKit/537.36+(KHTML,+like+Gecko;+compatible;+OAI-SearchBot/1.0;++https://openai.com/searchbot) - 301 466
2026-09-13 06:58:22 GET /config/.env - - 34.26.3.148 HTTP/2 Mozilla/5.0+AppleWebKit/537.36+(KHTML,+like+Gecko;+compatible;+PerplexityBot/1.0;++https://perplexity.ai/perplexitybot) - 301 466
2026-09-13 06:58:23 GET /.env.production raw - 34.26.3.148 HTTP/2 Mozilla/5.0+(compatible;+YiBot/1.0;++https://01.ai/) - 301 466
2026-09-13 06:58:23 GET /.env.production import&raw - 34.26.3.148 HTTP/2 Mozilla/5.0+(compatible;+Google-Extended;++http://www.google.com/bot.html) - 301 466
2026-09-13 06:58:23 GET /.env.
...
show less
Web App Attack
🇺🇸
ruusvuu
2026-09-13 06:53:41
(38 minutes ago)
Automated abuse report: 25 attack/probe requests from Google LLC / US.
Targeted paths: /wp-json, /v1 ...
show more
Automated abuse report: 25 attack/probe requests from Google LLC / US.
Targeted paths: /wp-json, /v1/graphql.
Sample log lines:
[shots] 📊 9/12/2026, 23:53:40 34.26.3.148 GET /wp-json 403 - 0.987 ms
[shots] 📊 9/12/2026, 23:53:40 34.26.3.148 POST /v1/graphql 429 - 0.203 ms
Detected by an automated web-server log monitor.
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-13 06:52:43
(39 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.26.3.148 (148.3.26.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.26.3.148 (148.3.26.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 02:52:36.796707 2026] [security2:error] [pid 14155:tid 14155] [client 34.26.3.148:58134] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "starvationacres.us"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252froot/.env"] [unique_id "aqZINNtLJJiCYE5oAWII5wAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-13 06:21:27
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.26.3.148 (148.3.26.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.26.3.148 (148.3.26.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 02:21:22.498095 2026] [security2:error] [pid 20851:tid 20851] [client 34.26.3.148:37124] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pistone.us"] [uri "/@fs/.env"] [unique_id "aqZA4pO3HWakYA5sDJB5gwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-09-13 06:17:37
(1 hour ago)
Web attack/malicious scanning detected
Web App Attack
🇩🇪
onlyops.app
2026-09-13 06:00:08
(1 hour ago)
Web application firewall (ModSecurity) detected malicious traffic | detected by Fail2Ban (plesk-mods ...
show more
Web application firewall (ModSecurity) detected malicious traffic | detected by Fail2Ban (plesk-modsecurity jail) | onlyops.app
show less
Exploited Host
🇺🇸
TPI-Abuse
2026-09-13 05:56:06
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.26.3.148 (148.3.26.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.26.3.148 (148.3.26.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 01:56:00.140944 2026] [security2:error] [pid 16228:tid 16252] [client 34.26.3.148:41290] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "meeker.us"] [uri "/%2E%2E/%2E%2E/%2E%2E/%2E%2E/.env"] [unique_id "aqY68EdkjZd-8LnzVgsDWgAAAJY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-13 05:48:10
(1 hour ago)
34.26.3.148 - - [13/Sep/2026:01:48:09 -0400] "GET /appearance/../../proc/self/environ HTTP/1.1" 400 ...
show more
34.26.3.148 - - [13/Sep/2026:01:48:09 -0400] "GET /appearance/../../proc/self/environ HTTP/1.1" 400 511 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
...
show less
Brute-Force
Web App Attack
SSH
🇺🇸
TPI-Abuse
2026-09-13 05:39:47
(1 hour ago)
(mod_security) mod_security (id:210730) triggered by 34.26.3.148 (148.3.26.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.26.3.148 (148.3.26.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 01:39:43.666202 2026] [security2:error] [pid 524:tid 524] [client 34.26.3.148:42250] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||guthrieclan.us|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "guthrieclan.us"] [uri "/rclone.conf"] [unique_id "aqY3H_eBqdZ3DQnPqWwiogAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 12:37:39
(18 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.26.3.148 (148.3.26.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.26.3.148 (148.3.26.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 08:37:33.350318 2026] [security2:error] [pid 13638:tid 13638] [client 34.26.3.148:57266] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.scoutinsignia.com|F|2"] [data ".scoutinsignia.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.scoutinsignia.com"] [uri "/z9x8c7v6b5-debug-trigger-mail.scoutinsignia.com"] [unique_id "aqVHjVo-t-i0pJ4Uj52bHQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 03:48:09
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.26.3.148 (148.3.26.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.26.3.148 (148.3.26.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 23:48:02.272070 2026] [security2:error] [pid 25444:tid 25444] [client 34.26.3.148:56734] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "email.seacorpolicies.com"] [uri "/.git/HEAD"] [unique_id "aqTLcu7ZXJ0-65Lrpxf3VwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Site.eu
2026-09-11 23:57:02
(1 day ago)
Excessive 404/403 errors
Brute-Force
🇫🇷
ecode hosting
2026-09-11 22:04:14
(1 day ago)
Domain : secertarim.com
Rule : env
2026-09-11 18:24:58 10.100.1.20 GET /.github/.env - 443 - 34.26.3 ...
show more
Domain : secertarim.com
Rule : env
2026-09-11 18:24:58 10.100.1.20 GET /.github/.env - 443 - 34.26.3.148 HTTP/2 Mozilla/5.0 (compatible; YiBot/1.0; https://01.ai/) - secertarim.com 301 0 0 161 383 184 - -
show less
Hacking
SQL Injection