Anonymous
2026-10-01 06:21:46
(1 day ago)
Fail2Ban apache-noscript
Bad Web Bot
๐ฉ๐ช
updown.io
2026-10-01 06:08:28
(1 day ago)
{"level":"info","ts":1790834901.6315298,"logger":"http.log.access.log1","msg":"handled request","req ...
show more
{"level":"info","ts":1790834901.6315298,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"34.39.169.83","remote_port":"56276","client_ip":"34.39.169.83","proto":"HTTP/2.0","method":"POST","host":"demo.updown.io","uri":"/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh","headers":{"Content-Length":["90"],"Accept-Encoding":["gzip"],"Content-Type":["text/plain"],"User-Agent":["Mozilla/5.0 (compatible; ChatGLM-Spider/1.0; +https://zhipuai.cn/)"]},"tls":{"resumed":false,"version":772,"cipher_suite":4865,"proto":"h2","server_name":"demo.updown.io","ech":false}},"bytes_read":0,"user_id":"","duration":0.000164705,"size":0,"status":429,"resp_headers":{"Server":["Caddy"],"Alt-Svc":["h3=\":443\"; ma=2592000"],"Retry-After":["1"]}}
{"level":"info","ts":1790834902.1073692,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"34.39.169.83","remote_port":"56276","client_ip":"34.39.169.83","proto":"HTTP/2.0","method":"POST","host"
...
show less
DDoS Attack
Web App Attack
๐บ๐ธ
jormaster3k
2026-10-01 05:56:43
(1 day ago)
Attack against Apache (too many 404s)
Web App Attack
Anonymous
2026-10-01 05:39:39
(1 day ago)
Aggressive web scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 03:47:40
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.39.169.83 (83.169.39.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.39.169.83 (83.169.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 23:47:34.165190 2026] [security2:error] [pid 17878:tid 17878] [client 34.39.169.83:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.wiszen.org"] [uri "/userfiles"] [unique_id "aryGVhd1Re3z7oUzhYbJJgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Steve
2026-09-30 03:47:06
(2 days ago)
Abuse of XMLRPC
Brute-Force
Web App Attack
Anonymous
2026-09-30 03:24:30
(2 days ago)
Aggressive web scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 03:18:20
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.39.169.83 (83.169.39.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.39.169.83 (83.169.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 23:18:13.064848 2026] [security2:error] [pid 1241:tid 1241] [client 34.39.169.83:43246] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.universitydental.org"] [uri "/appearance/../../.env"] [unique_id "arx_deW88GDXLWZz-y7WCAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 02:21:36
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.39.169.83 (83.169.39.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.39.169.83 (83.169.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 22:21:31.048042 2026] [security2:error] [pid 5602:tid 5602] [client 34.39.169.83:34178] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.weathercarib.net"] [uri "/.env.backup"] [unique_id "arxyK8nxFtbzXMIZknmZKQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 02:04:07
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.39.169.83 (83.169.39.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.39.169.83 (83.169.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 22:04:03.322020 2026] [security2:error] [pid 3935:tid 3935] [client 34.39.169.83:50470] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.united-kingdom-boat-registration.com"] [uri "/userfiles/x"] [unique_id "arxuE0MYfCzcRFaE00EmWAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
neckaralb-admin.de
2026-09-30 01:54:15
(2 days ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 01:26:28
(2 days ago)
(mod_security) mod_security (id:210580) triggered by 34.39.169.83 (83.169.39.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210580) triggered by 34.39.169.83 (83.169.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 21:26:24.616406 2026] [security2:error] [pid 14954:tid 14954] [client 34.39.169.83:34540] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "proc/self/environ" at ARGS:apis. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/08_Global_Other.conf"] [line "57"] [id "210580"] [rev "2"] [msg "COMODO WAF: OS File Access Attempt||yocontrolo.cl|F|2"] [data "Matched Data: proc/self/environ found within ARGS:apis: ../../../../../../proc/self/environ"] [severity "CRITICAL"] [tag "CWAF"] [tag "Other"] [hostname "yocontrolo.cl"] [uri "/api/console/api_server"] [unique_id "arxlQB7qX1IHbgQ0IW9-RgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 00:09:00
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.39.169.83 (83.169.39.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.39.169.83 (83.169.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 20:08:57.207837 2026] [security2:error] [pid 10856:tid 10856] [client 34.39.169.83:44238] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.weroinc.com"] [uri "/.env"] [unique_id "arxTGTs3wFFvl4dkdMOvsgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 23:31:59
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.39.169.83 (83.169.39.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.39.169.83 (83.169.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 19:31:54.552024 2026] [security2:error] [pid 8660:tid 8660] [client 34.39.169.83:59524] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.tttns.com"] [uri "/@fs/src/.env"] [unique_id "arxKag7CdZmL32PYoeUzEQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 23:09:34
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 34.39.169.83 (83.169.39.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.39.169.83 (83.169.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 19:09:28.068366 2026] [security2:error] [pid 29828:tid 29828] [client 34.39.169.83:59672] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||wglennburns.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "wglennburns.com"] [uri "/z9x8c7v6b5-debug-trigger-wglennburns.com"] [unique_id "arxFKF8W-z5YNwqC7SdnswAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack