๐บ๐ธ
snappic
2026-10-11 09:59:47
(8 hours ago)
Scanning for .env files [GET /api/fs/read?allowOutsideWorkspace=true&path=/app/.env] [Mozilla/5.0 (c ...
show more
Scanning for .env files [GET /api/fs/read?allowOutsideWorkspace=true&path=/app/.env] [Mozilla/5.0 (compatible; Hunyuan/1.0; +https://hunyuan.tencent.com/)]
show less
Bad Web Bot
Web App Attack
๐ธ๐ช
vaia.cloud
2026-10-11 09:55:01
(8 hours ago)
crowdsecurity/http-admin-interface-probing
Brute-Force
Web App Attack
Anonymous
2026-10-11 00:30:03
(18 hours ago)
CrowdSec decision: crowdsecurity/http-bad-user-agent (origin: crowdsec)
Port Scan
๐ง๐ท
radardatelecom
2026-10-10 22:27:03
(20 hours ago)
Blocked by Radar da Telecom firewall โ abuseipdb
Bad Web Bot
Web App Attack
Anonymous
2026-10-10 22:07:03
(20 hours ago)
Automated web scanner. Requested suspicious paths: /dist/manifest.json | /z9x8c7v6b5-debug-trigger-t ...
show more
Automated web scanner. Requested suspicious paths: /dist/manifest.json | /z9x8c7v6b5-debug-trigger-tigzig.com | /asset-manifest.json. UTC: 2026-10-10 21:19:31.
show less
Web App Attack
๐บ๐ธ
antlac1
2026-10-10 21:35:22
(21 hours ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
๐บ๐ธ
[email protected]
2026-10-10 21:29:28
(21 hours ago)
CrowdSec ban: crowdsecurity/http-path-traversal-probing (duration: 71h59m58s)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-10 21:20:36
(21 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.52.157.99 (99.157.52.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.52.157.99 (99.157.52.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 17:20:32.576825 2026] [security2:error] [pid 27696:tid 27696] [client 34.52.157.99:46694] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||tonylai.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "tonylai.com"] [uri "/z9x8c7v6b5-debug-trigger-tonylai.com"] [unique_id "asqsIFj4q9dmSXzIeqhe4wAAAEA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
CDO
2026-10-10 21:10:45
(21 hours ago)
URL Injection attempt detected. Automated web attack.
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-10 20:57:23
(21 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.52.157.99 (99.157.52.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.52.157.99 (99.157.52.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 16:57:16.854417 2026] [security2:error] [pid 4193:tid 4242] [client 34.52.157.99:41782] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||robotics4fun.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "robotics4fun.com"] [uri "/z9x8c7v6b5-debug-trigger-robotics4fun.com"] [unique_id "asqmrOMEi3un0B71wlIX_wAAAFY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-10 20:51:55
(21 hours ago)
Banned by Fail2Ban on server
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-10-10 20:50:12
(21 hours ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
๐ฉ๐ช
yitzhaq
2026-10-10 20:33:20
(22 hours ago)
34.52.157.99 - - [10/Oct/2026:22:33:16 +0200] "GET /temp/.env HTTP/2.0" 301 360 "-" "Mozilla/5.0 (co ...
show more
34.52.157.99 - - [10/Oct/2026:22:33:16 +0200] "GET /temp/.env HTTP/2.0" 301 360 "-" "Mozilla/5.0 (compatible; ChatGLM-Spider/1.0; +https://zhipuai.cn/)"
34.52.157.99 - - [10/Oct/2026:22:33:16 +0200] "GET /assets/.env HTTP/2.0" 301 363 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Safari/605.1.15 (Applebot/0.1; +http://www.apple.com/go/applebot)"
34.52.157.99 - - [10/Oct/2026:22:33:16 +0200] "GET /private/.env HTTP/2.0" 301 365 "-" "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)"
34.52.157.99 - - [10/Oct/2026:22:33:16 +0200] "GET /.ssh/id_ecdsa HTTP/2.0" 301 365 "-" "Mozilla/5.0 (compatible; GrokBot/1.0; +https://x.ai/)"
34.52.157.99 - - [10/Oct/2026:22:33:16 +0200] "GET /.ssh/known_hosts HTTP/2.0" 301 372 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; GPTBot/1.4; +https://openai.com/gptbot"
34.52.157.99 - - [10/Oct/2026:22:33:17 +0200] "GET /id_ed25519 HTTP/2.0" 301 3
show less
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-10-10 20:28:33
(22 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.52.157.99 (99.157.52.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.52.157.99 (99.157.52.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 16:28:26.397231 2026] [security2:error] [pid 5264:tid 5264] [client 34.52.157.99:57880] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||rebeccapratt.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "rebeccapratt.com"] [uri "/z9x8c7v6b5-debug-trigger-rebeccapratt.com"] [unique_id "asqf6nlEcSU-65ZljN4pkgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-10 20:03:35
(22 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.52.157.99 (99.157.52.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.52.157.99 (99.157.52.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 16:03:30.007462 2026] [security2:error] [pid 25585:tid 25585] [client 34.52.157.99:48828] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||realitytourist.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "realitytourist.com"] [uri "/z9x8c7v6b5-debug-trigger-realitytourist.com"] [unique_id "asqaEoYcq6oCqDubDi-ILAAAAGY"]
show less
Brute-Force
Bad Web Bot
Web App Attack