π©πͺ
updown.io
2026-08-28 14:18:15
(8 hours ago)
{"level":"info","ts":1787926651.1985073,"logger":"http.log.access.log0","msg":"handled request","req ...
show more
{"level":"info","ts":1787926651.1985073,"logger":"http.log.access.log0","msg":"handled request","request":{"remote_ip":"34.53.103.102","remote_port":"3524","client_ip":"34.53.103.102","proto":"HTTP/1.1","method":"GET","host":"pav7.status.updown.io","uri":"/","headers":{"Accept":["*/*"],"Accept-Encoding":["gzip"],"User-Agent":["Mozilla/5.0 (iPhone; CPU iPhone OS 15_7_3 like Mac OS X) AppleWebKit/537.36 (KHTML, like Gecko) CriOS/107.0.5304.79 Mobile/15E148 Safari/537.36"]}},"bytes_read":0,"user_id":"","duration":0.000069132,"size":0,"status":308,"resp_headers":{"Location":["https://pav7.status.updown.io/"],"Content-Type":[],"Server":["Caddy"],"Connection":["close"]}}
{"level":"info","ts":1787926658.1405869,"logger":"http.log.access.log0","msg":"handled request","request":{"remote_ip":"34.53.103.102","remote_port":"29182","client_ip":"34.53.103.102","proto":"HTTP/1.1","method":"GET","host":"pav7.status.updown.io","uri":"/@fs/..%252f..%252f..%252f..%252f..%252fproc/self/environ?raw??","hea
...
show less
DDoS Attack
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-28 14:13:50
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.53.103.102 (102.103.53.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.53.103.102 (102.103.53.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 10:13:45.528348 2026] [security2:error] [pid 10078:tid 10078] [client 34.53.103.102:43202] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.frenosilent.com.ar"] [uri "/@fs/root/.env"] [unique_id "apGXme_AArmU5WOcCGZwpwAAACo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
e.fierstra
2026-08-28 13:27:09
(9 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
π©πͺ
FeG Deutschland
2026-08-28 13:08:32
(9 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 1247
Exploited Host
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-28 12:02:28
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.53.103.102 (102.103.53.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.53.103.102 (102.103.53.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 08:02:22.498654 2026] [security2:error] [pid 466:tid 466] [client 34.53.103.102:3754] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.barigby.com"] [uri "/@fs/root/.env"] [unique_id "apF4zgMmkg4jGPxET3goJwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
masterguru
2026-08-28 11:50:44
(11 hours ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.53.103.102 (US/United States/102.1 ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.53.103.102 (US/United States/102.103.53.34.bc.googleusercontent.com): 2 in the last 3600 secs (0-196)
show less
Hacking
π»π³
trung.fun
2026-08-28 11:49:42
(11 hours ago)
DDoS, Hack, Brute Force, Web Attack
...
DDoS Attack
Web Spam
Hacking
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-28 11:37:28
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.53.103.102 (102.103.53.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.53.103.102 (102.103.53.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 07:37:24.148957 2026] [security2:error] [pid 25076:tid 25076] [client 34.53.103.102:35676] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.stagemadrid.com"] [uri "/@fs/root/.env"] [unique_id "apFy9EAZdXh6aWocBTy8LQAAAEg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
javierin
2026-08-28 11:18:43
(11 hours ago)
34.53.103.102 - wedding-planer.es - - [28/Aug/2026:11:18:42 +0000] "GET /@fs/..%252f..%252f..%252f.. ...
show more
34.53.103.102 - wedding-planer.es - - [28/Aug/2026:11:18:42 +0000] "GET /@fs/..%252f..%252f..%252f..%252f..%252froot/.env?raw?? HTTP/1.1" 404 178 "-" "Mozilla/5.0 (Linux; Android 12; Pixel 6) AppleWebKit/537.36 (KHTML, like Gecko; compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot) Chrome/151.0.9020.70 Mobile Safari/537.36"
34.53.103.102 - wedding-planer.es - - [28/Aug/2026:11:18:42 +0000] "GET /@fs/..%252f..%252f..%252f..%252f..%252fproc/self/environ?raw?? HTTP/1.1" 404 117 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; GrokBot/1.0; +https://x.ai/grokbot)"
...
show less
Web App Attack
Hacking
πΊπΈ
TPI-Abuse
2026-08-28 11:05:30
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.53.103.102 (102.103.53.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.53.103.102 (102.103.53.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 07:05:23.623723 2026] [security2:error] [pid 19492:tid 19492] [client 34.53.103.102:4874] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.technicallydental.com"] [uri "/@fs/root/.env"] [unique_id "apFrc9FrFmf1ycUf3IzrEgAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¦πΉ
Starburst SysOp Team
2026-08-28 10:50:44
(12 hours ago)
Restricted File Access Attempt. Matched phrase "/@fs/" at REQUEST_FILENAME. (930130-vie6-1)
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-28 10:48:20
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.53.103.102 (102.103.53.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.53.103.102 (102.103.53.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 06:48:14.854042 2026] [security2:error] [pid 6867:tid 6867] [client 34.53.103.102:37178] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.emisoni.com"] [uri "/@fs/.env"] [unique_id "apFnbkWyPceliQEMDJ_MQgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-28 09:44:29
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.53.103.102 (102.103.53.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.53.103.102 (102.103.53.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 05:44:22.469378 2026] [security2:error] [pid 7450:tid 7450] [client 34.53.103.102:30270] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.completemodular.com"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252fapp/.env"] [unique_id "apFYdkPvyTjaOeE0XWOYzQAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπ¦
URAN Publishing Service
2026-08-28 07:34:06
(15 hours ago)
[28/Aug/2026:10:34:05 +0300] -- 34.53.103.102 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET / ...
show more
[28/Aug/2026:10:34:05 +0300] -- 34.53.103.102 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET /@fs/root/.env?raw?? HTTP/1.1
show less
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-28 07:08:21
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.53.103.102 (102.103.53.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.53.103.102 (102.103.53.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 03:08:16.055413 2026] [security2:error] [pid 21249:tid 21249] [client 34.53.103.102:54734] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.patrickconklin.com"] [uri "/@fs/root/.env"] [unique_id "apEz4BIj2SpqElCpBJS0uwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack