๐ซ๐ท
masterguru
2026-07-31 06:02:10
(2 minutes ago)
BAD BOT - Detected and Blocked.. Matched phrase "bytespider" at REQUEST_HEADERS:User-Agent. (1100000 ...
show more
BAD BOT - Detected and Blocked.. Matched phrase "bytespider" at REQUEST_HEADERS:User-Agent. (1100000-193)
show less
Bad Web Bot
๐ฉ๐ช
updown.io
2026-07-31 05:24:55
(40 minutes ago)
{"level":"info","ts":1785475486.8275383,"logger":"http.log.access.log1","msg":"handled request","req ...
show more
{"level":"info","ts":1785475486.8275383,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"34.38.225.249","remote_port":"22068","client_ip":"34.38.225.249","proto":"HTTP/1.1","method":"GET","host":"updown.tianmiao.fun","uri":"/","headers":{"User-Agent":["Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/146.0.0.0 Safari/537.36"],"Accept":["*/*"],"Accept-Encoding":["gzip"]}},"bytes_read":0,"user_id":"","duration":0.000049044,"size":0,"status":308,"resp_headers":{"Content-Type":[],"Server":["Caddy"],"Connection":["close"],"Location":["https://updown.tianmiao.fun/"]}}
{"level":"info","ts":1785475490.9073713,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"34.38.225.249","remote_port":"58952","client_ip":"34.38.225.249","proto":"HTTP/1.1","method":"GET","host":"updown.tianmiao.fun","uri":"/backend/.env","headers":{"User-Agent":["Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compati
...
show less
DDoS Attack
Web App Attack
๐ฌ๐ง
consul.to
2026-07-31 05:00:12
(1 hour ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-31 04:39:59
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.38.225.249 (249.225.38.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.38.225.249 (249.225.38.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 00:39:54.090812 2026] [security2:error] [pid 3593389:tid 3593408] [client 34.38.225.249:51524] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.stanfordprofs.com"] [uri "/.env"] [unique_id "amwnGi7uSaAUwkTRfZwt4AAAAIw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฟ
Antinson
2026-07-31 04:20:32
(1 hour ago)
High error rate and elevated request volume targeting cPanel servers
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-07-31 04:15:48
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.38.225.249 (249.225.38.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.38.225.249 (249.225.38.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 00:15:42.656940 2026] [security2:error] [pid 2733424:tid 2733424] [client 34.38.225.249:19756] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.cameronwv.com"] [uri "/.env.local"] [unique_id "amwhbqrwV6On3Cgb_QU_OQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-31 03:23:55
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.38.225.249 (249.225.38.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.38.225.249 (249.225.38.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 30 23:23:47.296088 2026] [security2:error] [pid 2540873:tid 2540873] [client 34.38.225.249:34454] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.fruitsinthedesert.com"] [uri "/.env.local"] [unique_id "amwVQ4kwqVNYRBgcO1gY1QAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
brightenfield
2026-07-31 03:16:11
(2 hours ago)
Web App Attack
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-31 03:01:59
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.38.225.249 (249.225.38.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.38.225.249 (249.225.38.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 30 23:01:55.752630 2026] [security2:error] [pid 2755993:tid 2755993] [client 34.38.225.249:18728] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.holgerfeld.com"] [uri "/.env.development"] [unique_id "amwQIzVCA95C3OTAUY1irwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-31 02:24:34
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.38.225.249 (249.225.38.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.38.225.249 (249.225.38.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 30 22:24:28.490688 2026] [security2:error] [pid 16219:tid 16219] [client 34.38.225.249:20450] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.vrmapping.net"] [uri "/.env.local"] [unique_id "amwHXDeP5x9YOlG9amhDaAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-31 01:57:52
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.38.225.249 (249.225.38.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.38.225.249 (249.225.38.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 30 21:57:43.498015 2026] [security2:error] [pid 504242:tid 504242] [client 34.38.225.249:53104] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dutchgreenrecycling.mapleleaf-marketing.com"] [uri "/.env"] [unique_id "amwBF2nHQA_HESQmwbIYbAAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-31 01:34:41
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.38.225.249 (249.225.38.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.38.225.249 (249.225.38.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 30 21:34:35.042347 2026] [security2:error] [pid 3022369:tid 3022369] [client 34.38.225.249:43298] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.qxz.cc"] [uri "/.env.production"] [unique_id "amv7q8ZSYHD-CO17GumIWQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Octopuce
2026-07-31 01:26:03
(4 hours ago)
Aggressive web search of vulnerable pages: /app/.env /laravel/.env /admin/.env /backend/.env /config ...
show more
Aggressive web search of vulnerable pages: /app/.env /laravel/.env /admin/.env /backend/.env /config/.env ...
show less
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-07-31 01:10:16
(4 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐ณ๐ฑ
e.fierstra
2026-07-31 01:02:37
(5 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack