๐ฎ๐น
VHosting
2026-10-02 11:15:08
(1 hour ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐จ๐ญ
backslash
2026-10-02 11:06:01
(1 hour ago)
block ruleset WAF detection and high score on abuseIPDB 149EB1B42C242111FADBBC2EF8F90219570691E1
Bad Web Bot
๐ฉ๐ช
itsolon
2026-10-02 10:00:26
(2 hours ago)
[02/Oct/2026:12:00:26 +0200] 179093522621.488699 34.38.53.81 45398 217.154.7.177 443
[02/Oct/2026:12 ...
show more
[02/Oct/2026:12:00:26 +0200] 179093522621.488699 34.38.53.81 45398 217.154.7.177 443
[02/Oct/2026:12:00:26 +0200] 179093522649.506616 34.38.53.81 45398 217.154.7.177 443
[02/Oct/2026:12:00:26 +0200] 179093522617.663925 34.38.53.81 45398 217.154.7.177 443
[02/Oct/2026:12:00:26 +0200] 179093522677.432351 34.38.53.81 45398 217.154.7.177 443
[02/Oct/2026:12:00:26 +0200] 179093522687.454251 34.38.53.81 45398 217.154.7.177 443
...
show less
Port Scan
Hacking
Brute-Force
Web App Attack
๐จ๐ฆ
Anytech
2026-10-02 09:31:57
(2 hours ago)
Blocked by Conn-Monitor: env-probing
Web App Attack
Hacking
๐ช๐ธ
pipeline.es
2026-10-02 08:41:03
(3 hours ago)
Web scanning / probing for vulnerable paths | URL: /@fs/var/run/secrets/kubernetes.io/serviceaccount ...
show more
Web scanning / probing for vulnerable paths | URL: /@fs/var/run/secrets/kubernetes.io/serviceaccount/token?raw?? | Evidence: microsites.grupoeuropa.com 34.38.53.81 - - [02/Oct/2026:10:40:31 +0200] \"GET /@fs/var/run/secrets/kubernetes.io/serviceaccount/token?raw?? HTTP/1.1\" 404 - \"-\" \"Mozilla/5.0 (compatible; Bravebot/1.0; +https://brave.com/search/)\" GEOIP_COUNTRY_CODE=BE | ASN: GOOGLE-CLOUD-PLATFORM | Country: BE
show less
Port Scan
Web App Attack
Anonymous
2026-10-02 07:36:50
(4 hours ago)
34.38.53.81 - - [02/Oct/2026:02:34:05 -0500] "GET /.env?raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 (Maci ...
show more
34.38.53.81 - - [02/Oct/2026:02:34:05 -0500] "GET /.env?raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Safari/605.1.15 (Applebot/0.1)" 34.38.53.81
34.38.53.81 - - [02/Oct/2026:02:34:05 -0500] "GET /.env?import&raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Safari/605.1.15 (Applebot/0.1)" 34.38.53.81
34.38.53.81 - - [02/Oct/2026:02:34:05 -0500] "GET /.env.local?raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; MoonshotBot/1.0; +https://kimi.ai/)" 34.38.53.81
34.38.53.81 - - [02/Oct/2026:02:34:05 -0500] "GET /.env?import&url&inline HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; Bravebot/1.0; +https://brave.com/search/)" 34.38.53.81
34.38.53.81 - - [02/Oct/2026:02:34:05 -0500] "GET /.env.production?import&raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; Google-Extended; +http://www.google.com/bot.html)" 34.38.53.81
34.38.
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Mundo Bueno
2026-10-02 07:15:20
(5 hours ago)
[ISILIA Protection v2.3] Tentative d'accรจs: /@fs/var/task/.env [RATE LIMITED - 1800s quarantine] | P ...
show more
[ISILIA Protection v2.3] Tentative d'accรจs: /@fs/var/task/.env [RATE LIMITED - 1800s quarantine] | Pays: BE | UA: Mozilla/5.0 (compatible; KimiBot/1.0; +https://kimi.ai/)
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 07:10:16
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.38.53.81 (81.53.38.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.38.53.81 (81.53.38.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 03:10:11.790725 2026] [security2:error] [pid 7402:tid 7402] [client 34.38.53.81:42294] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.bergenoaks.com"] [uri "/.htpasswd"] [unique_id "ar9Y04U4l2tcqBn6zLD76gAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 05:43:58
(6 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.38.53.81 (81.53.38.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.38.53.81 (81.53.38.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 01:43:52.346537 2026] [security2:error] [pid 27922:tid 27922] [client 34.38.53.81:35860] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.bervick.com|F|2"] [data ".bervick.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.bervick.com"] [uri "/z9x8c7v6b5-debug-trigger-www.bervick.com"] [unique_id "ar9EmI-8RH9hif0v16oPaQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-10-02 05:24:54
(6 hours ago)
Multiple WAF Violations
Web App Attack
๐ฉ๐ช
rh24
2026-10-02 05:18:21
(7 hours ago)
(badbots) Bad bot user-agent [redacted] from 34.38.53.81 (BE/Belgium/81.53.38.34.bc.googleuserconten ...
show more
(badbots) Bad bot user-agent [redacted] from 34.38.53.81 (BE/Belgium/81.53.38.34.bc.googleusercontent.com)
show less
Hacking
๐ท๐ธ
pexodelic
2026-10-02 04:05:02
(8 hours ago)
Automated report from web, SSH and FTP server logs: 304 requests probing for exposed secrets (.env, ...
show more
Automated report from web, SSH and FTP server logs: 304 requests probing for exposed secrets (.env, .git, config files). First reported 2026-10-02 05:35 UTC, last reported 2026-10-02 06:05 UTC; counts cover the current log rotation window.
show less
Hacking
Web App Attack