๐จ๐ฑ
Fernando Soto
2026-10-01 03:05:24
(6 days ago)
WAF propio vps1 (CL): 404x35,sensx72 score 22 en 1h. sondeo rutas sensibles, barrido 404.
Port Scan
Web App Attack
๐ง๐ท
radardatelecom
2026-09-30 22:26:03
(6 days ago)
Blocked by Radar da Telecom firewall โ abuseipdb
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-09-30 22:01:24
(6 days ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-29.
show less
Web App Attack
SSH
Hacking
Anonymous
2026-09-30 04:32:13
(1 week ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
๐บ๐ธ
TPI-Abuse
2026-09-30 02:58:34
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.40.102.177 (177.102.40.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.40.102.177 (177.102.40.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 22:58:27.841343 2026] [security2:error] [pid 16623:tid 16623] [client 34.40.102.177:59260] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tlambert.us"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252froot/.env"] [unique_id "arx606A1MfmcMmy_6K-erAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
robotstxt
2026-09-30 02:48:57
(1 week ago)
34.40.102.177 - - [30/Sep/2026:02:48:12 +0000] "GET /wp-content/cache/autoptimize/1/js/autoptimize_s ...
show more
34.40.102.177 - - [30/Sep/2026:02:48:12 +0000] "GET /wp-content/cache/autoptimize/1/js/autoptimize_single_04fb3be45e83f10f4b853484ebb3ba98.js HTTP/2.0" 403 165 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Mobile Safari/537.36 EdgA/152.0.0.0" "34.40.102.177" edge="172.71.141.228"
34.40.102.177 - - [30/Sep/2026:02:48:13 +0000] "GET /static/manifest.json HTTP/2.0" 403 33372 "https://ccoo.cat/static/manifest.json" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Mobile Safari/537.36 EdgA/152.0.0.0" "34.40.102.177" edge="172.71.141.32"
34.40.102.177 - - [30/Sep/2026:02:48:13 +0000] "GET /manifest.json HTTP/2.0" 403 33401 "https://ccoo.cat/manifest.json" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Mobile Safari/537.36 EdgA/152.0.0.0" "34.40.102.177" edge="172.71.141.13"
34.40.102.177 - - [30/Sep/2026:02:48:13 +0000] "GET /assets/manifest.json HTTP/2.0"
...
show less
Web App Attack
๐ฉ๐ช
snhosting
2026-09-30 02:32:30
(1 week ago)
34.40.102.177 - - [30/Sep/2026:04:32:20 +0200] "GET /config/env/aws_credentials.env HTTP/2.0" 200 16 ...
show more
34.40.102.177 - - [30/Sep/2026:04:32:20 +0200] "GET /config/env/aws_credentials.env HTTP/2.0" 200 1601 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
34.40.102.177 - - [30/Sep/2026:04:32:20 +0200] "GET /__vite_rsc_findSourceMapURL?filename=file:///app/.env&environmentName=rsc HTTP/2.0" 200 1601 "-" "Mozilla/5.0 (compatible; Meta-ExternalAgent/1.0; +https://developers.facebook.com/docs/sharing/webmasters/crawler)"
34.40.102.177 - - [30/Sep/2026:04:32:20 +0200] "GET /.env?raw HTTP/2.0" 200 1601 "-" "Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; +https://kimi.ai/)"
34.40.102.177 - - [30/Sep/2026:04:32:20 +0200] "GET /.env.production?raw HTTP/2.0" 200 1606 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; [email protected] )"
34.40.102.177 - - [30/Sep/2026:04:32:20 +0200] "GET /.env.production?import&raw HTTP/2.0" 200 1606 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; PerplexityBot/1.0; +https://per
...
show less
DNS Compromise
DNS Poisoning
Phishing
Email Spam
Brute-Force
Web App Attack
SSH
๐บ๐ธ
TPI-Abuse
2026-09-30 01:24:33
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.40.102.177 (177.102.40.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.40.102.177 (177.102.40.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 21:24:25.264115 2026] [security2:error] [pid 31450:tid 31450] [client 34.40.102.177:35928] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "niximperial.biz"] [uri "/.env.dev"] [unique_id "arxkyYm9YrvWSjad4hZv4QAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
slay3r9903
2026-09-30 01:15:12
(1 week ago)
IP address blocked by Cloudflare security rules due to suspicious activity and security violations.
Hacking
Bad Web Bot
๐ฌ๐ง
andypiper
2026-09-30 01:02:45
(1 week ago)
CrowdSec ban for AbuseIPDB Top List
Brute-Force
Web App Attack
Anonymous
2026-09-30 00:11:33
(1 week ago)
IP matched detection query more than 2 hosts and only bad rq long ban.
Brute-Force
Web App Attack
Hacking
๐จ๐ฑ
Fernando Soto
2026-09-30 00:05:03
(1 week ago)
WAF propio vps1 (CL): 404x35,sensx72 score 22 en 1h. sondeo rutas sensibles, barrido 404.
Port Scan
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-09-30 00:04:57
(1 week ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 00:02:20
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.40.102.177 (177.102.40.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.40.102.177 (177.102.40.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 20:02:13.221725 2026] [security2:error] [pid 10751:tid 10764] [client 34.40.102.177:36650] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nickkonstantinidis.appraisalteam.net"] [uri "/userfiles/x"] [unique_id "arxRhf4LrcsAL5HXSG0WxQAAAMs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2026-09-29 23:35:00
(1 week ago)
866 requests with url.path */@fs/*
225 requests with url.path */proc/*
197 requests with url.path ...
show more
866 requests with url.path */@fs/*
225 requests with url.path */proc/*
197 requests with url.path *.php.bak
190 requests with url.path *.aws/*
175 requests with url.path *credentials.json
160 requests with url.path *.ssh/*
155 requests with url.path *config.json
show less
Brute-Force
Bad Web Bot