๐ณ๐ฑ
Mangelot Hosting
2026-08-26 19:37:28
(1 hour ago)
(modsecurity) srv102 ModSecurity 34.53.91.50 (US/United States/50.91.53.34.bc.googleusercontent.com) ...
show more
(modsecurity) srv102 ModSecurity 34.53.91.50 (US/United States/50.91.53.34.bc.googleusercontent.com): 30 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
๐จ๐ญ
4server
2026-08-26 17:48:56
(2 hours ago)
[WedAug2619:48:49.9125972026][security2:error][pid1343826:tid1343953][client34.53.91.50:0]ModSecurit ...
show more
[WedAug2619:48:49.9125972026][security2:error][pid1343826:tid1343953][client34.53.91.50:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"/etc/passwd\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_rules/10_asl_rules.conf\"][line\"141\"][id\"347009\"][rev\"1\"][msg\"Atomicorp.comWAFRules:ProtectedFileaccessdenied\"][severity\"CRITICAL\"][hostname\"edilmarra.ch\"][uri\"/@fs/etc/passwd\"][unique_id\"ao8nAfEgqOtTuPCg2sSaRAAAAEE\"]
show less
Hacking
Web App Attack
๐ฉ๐ช
BlueWire Hosting
2026-08-26 17:36:41
(3 hours ago)
High-confidence malicious configuration/VCS probe
Web App Attack
Anonymous
2026-08-26 14:20:44
(6 hours ago)
34.53.91.50 - - [26/Aug/2026:16:20:44 +0200] "GET /.git-credentials HTTP/1.1" 403 153 "-" "Mozilla/5 ...
show more
34.53.91.50 - - [26/Aug/2026:16:20:44 +0200] "GET /.git-credentials HTTP/1.1" 403 153 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot)"
34.53.91.50 - - [26/Aug/2026:16:20:44 +0200] "GET /@fs/../.env?raw?? HTTP/1.1" 403 12583 "-" "Mozilla/5.0 (compatible; Twitterbot/1.0)"
34.53.91.50 - - [26/Aug/2026:16:20:44 +0200] "GET /@fs/proc/1/environ?raw?? HTTP/1.1" 403 12583 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.5506.31 Safari/537.36; compatible; Claude-User/1.0; [email protected] "
34.53.91.50 - - [26/Aug/2026:16:20:44 +0200] "GET /@fs/root/.aws/credentials?raw?? HTTP/1.1" 403 12583 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; LinkedInBot/1.0; +http://www.linkedin.com)"
34.53.91.50 - - [26/Aug/2026:16:20:44 +0200] "GET /@fs/proc/self/environ HTTP/1.1" 403 12583 "-" "Mozilla/5.0 (Linux; Android 12; Pixel 6) AppleWebKit/537.36
...
show less
Bad Web Bot
Web App Attack
๐ช๐ธ
masterguru
2026-08-26 12:48:38
(7 hours ago)
Inbound Anomaly Score Exceeded (Total Score: 5). Operator GE matched 5 at TX:anomaly_score. (949110- ...
show more
Inbound Anomaly Score Exceeded (Total Score: 5). Operator GE matched 5 at TX:anomaly_score. (949110-122)
show less
Hacking
๐บ๐ธ
WellSpring
2026-08-26 12:16:26
(8 hours ago)
env leak on odypays.org/admin/.env โ WellSpr.ing/NetSentinel civic-AI security layer
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 12:14:24
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.53.91.50 (50.91.53.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.53.91.50 (50.91.53.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 08:14:16.984878 2026] [security2:error] [pid 15647:tid 15647] [client 34.53.91.50:6584] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.fynebutts.com"] [uri "/.git/HEAD"] [unique_id "ao7YmHWBuFrNVLlu9PCdlwAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
OptimusGO
2026-08-26 11:35:15
(9 hours ago)
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Time ...
show more
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Timestamp: 2026-08-26 12:35:15 UTC
Log evidence:
08/26/2026-12:35:13.944026 [wDrop] [**] [1:7000500:1] FINSERV CRITICAL: Aggressive Port Scan [**] [Classification: Attempted Information Leak] [Priority: 2] {TCP} 34.53.91.50:60396 -> 185.127.18.66:443
08/26/2026-12:35:13.944026 [**] [1:9000060:2] AUTONOMOUS Long-term Reconnaissance [**] [Classification: (null)] [Priority: 2] {TCP} 34.53.91.50:60396 -> 185.127.18.66:443
show less
Port Scan
Brute-Force
๐ณ๐ฑ
BlueWire Hosting
2026-08-26 11:10:48
(9 hours ago)
Aggressive scanning resulting into 404
Bad Web Bot
๐ณ๐ฑ
e.fierstra
2026-08-26 11:03:10
(9 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐ฉ๐ช
DEV-DNS
2026-08-26 10:55:52
(9 hours ago)
(mod_security) mod_security triggered on hostname [redacted])
SQL Injection
๐ฌ๐ง
consul.to
2026-08-26 09:50:32
(10 hours ago)
Web attack/malicious scanning detected
Web App Attack
Anonymous
2026-08-26 08:36:51
(12 hours ago)
[server.tmg.gr] httpd-config-scan: sites=www.aidshep2024.gr; logs=/var/log/httpd/access_log,/var/log ...
show more
[server.tmg.gr] httpd-config-scan: sites=www.aidshep2024.gr; logs=/var/log/httpd/access_log,/var/log/httpd/domains/aidshep2024.gr.log; samples=/@fs/proc/self/environ?raw?? | /@fs/etc/passwd?import&raw?? | /actuator/env
show less
Hacking
Web App Attack
Anonymous
2026-08-26 07:38:12
(13 hours ago)
Bot / seems abusive / Apache connections: 30
DDoS Attack
Web Spam
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 06:21:01
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.53.91.50 (50.91.53.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.53.91.50 (50.91.53.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 02:20:56.274921 2026] [security2:error] [pid 20758:tid 20758] [client 34.53.91.50:4934] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "n4fh.com"] [uri "/static../.env"] [unique_id "ao6FyNsSQkwkKHYNwMN4ZwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack