Anonymous
2026-10-08 22:23:30
(10 hours ago)
[Mon Oct 05 05:26:51.190383 2026] [authz_core:error] [pid 254845:tid 254903] [remote 34.6.78.29:5897 ...
show more
[Mon Oct 05 05:26:51.190383 2026] [authz_core:error] [pid 254845:tid 254903] [remote 34.6.78.29:58970] AH01630: client denied by server configuration: /var/www/_live/bolt.csabazar.hu/html/.htpasswd
[Mon Oct 05 05:26:55.282301 2026] [authz_core:error] [pid 254845:tid 254894] [remote 34.6.78.29:58970] AH01630: client denied by server configuration: /var/www/_live/bolt.csabazar.hu/html/server-status
[Mon Oct 05 05:26:51.190383 2026] [authz_core:error] [pid 254845:tid 254903] [remote 34.6.78.29:58970] AH01630: client denied by server configuration: /var/www/_live/bolt.csabazar.hu/html/.htpasswd
[Mon Oct 05 05:26:55.282301 2026] [authz_core:error] [pid 254845:tid 254894] [remote 34.6.78.29:58970] AH01630: client denied by server configuration: /var/www/_live/bolt.csabazar.hu/html/server-status
[Mon Oct 05 05:26:51.190383 2026] [authz_core:error] [pid 254845:tid 254903] [remote 34.6.78.29:58970] AH01630: client denied by server configuration: /var/www/_live/bolt.csabazar.hu/html/.htpasswd
...
show less
Brute-Force
Web App Attack
๐ณ๐ฑ
Site.eu
2026-10-06 13:53:07
(2 days ago)
Excessive multi-domain requests
Brute-Force
๐ญ๐บ
kranem
2026-10-06 00:01:45
(3 days ago)
Triggered Cloudflare WAF from NL.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Protocol: HTTP/2 (GET ...
show more
Triggered Cloudflare WAF from NL.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Protocol: HTTP/2 (GET method)
Endpoint: /.env.old
Timestamp: 2026-10-05T14:11:10Z
User-Agent: DuckAssistBot/1.1 (https://duckduckgo.com/duckassistbot)
show less
Bad Web Bot
Anonymous
2026-10-05 23:29:55
(3 days ago)
http scanning for .env files
...
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 12:39:26
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.6.78.29 (29.78.6.34.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:210492) triggered by 34.6.78.29 (29.78.6.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 08:39:22.870358 2026] [security2:error] [pid 7289:tid 7289] [client 34.6.78.29:53680] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.tracybur.net"] [uri "/.htpasswd"] [unique_id "asOaesTPfqRZa0gPWiGRrAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ญ๐บ
kranem
2026-10-05 12:00:17
(3 days ago)
Triggered Cloudflare WAF from NL.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Protocol: HTTP/2 (GET ...
show more
Triggered Cloudflare WAF from NL.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Protocol: HTTP/2 (GET method)
Endpoint: /userfiles/x
Query: ?path=../../.env
Timestamp: 2026-10-05T10:47:58Z
User-Agent: Mozilla/5.0 (compatible; KimiBot/1.0; +https://kimi.ai/)
show less
Bad Web Bot
Anonymous
2026-10-05 08:24:08
(4 days ago)
GET /@fs/../.env?raw?? HTTP/1.1
...
Web App Attack
Anonymous
2026-10-05 06:32:25
(4 days ago)
GET /img../.env HTTP/1.1
...
Web App Attack
๐ฉ๐ช
reznekcs
2026-10-05 05:02:50
(4 days ago)
Blocked by UFW firewall
Brute-Force
Anonymous
2026-10-05 03:26:55
(4 days ago)
[Mon Oct 05 05:26:54.833781 2026] [proxy_fcgi:error] [pid 254845:tid 254900] [remote 34.6.78.29:5897 ...
show more
[Mon Oct 05 05:26:54.833781 2026] [proxy_fcgi:error] [pid 254845:tid 254900] [remote 34.6.78.29:58970] AH01071: Got error 'Primary script unknown'
[Mon Oct 05 05:26:54.837069 2026] [proxy_fcgi:error] [pid 254845:tid 254907] [remote 34.6.78.29:58970] AH01071: Got error 'Primary script unknown'
[Mon Oct 05 05:26:54.858091 2026] [proxy_fcgi:error] [pid 254845:tid 254909] [remote 34.6.78.29:58970] AH01071: Got error 'Primary script unknown'
...
show less
Brute-Force
Web App Attack
๐ซ๐ท
masterguru
2026-10-04 23:52:56
(4 days ago)
HTTP header is restricted by policy (/x-middleware-subrequest/). String match within "/content-encod ...
show more
HTTP header is restricted by policy (/x-middleware-subrequest/). String match within "/content-encoding/ /proxy/ /lock-token/ /content-range/ /if/ /x-http-method-override/ /x-http-method/ /x-method-override/ /x-middleware-subrequest/ /expect/" at TX:header_name_920450_x-middleware-subrequest. (920450-201)
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-04 23:33:04
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.6.78.29 (29.78.6.34.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:210492) triggered by 34.6.78.29 (29.78.6.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 19:32:57.206017 2026] [security2:error] [pid 6543:tid 6543] [client 34.6.78.29:47046] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "zavijava.net"] [uri "/.htpasswd"] [unique_id "asLiKZFhIUywe2LpuLcwbQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
gadix
2026-10-04 23:32:56
(4 days ago)
[05/Oct/2026:01:32:55.828048 +0200] asLiJz-mpHSvi_370BG3BAAAAFA 34.6.78.29 39384 127.0.0.1 7081
[05/ ...
show more
[05/Oct/2026:01:32:55.828048 +0200] asLiJz-mpHSvi_370BG3BAAAAFA 34.6.78.29 39384 127.0.0.1 7081
[05/Oct/2026:01:32:55.861702 +0200] asLiJ28iLplXtnJWypHODAAAAAE 34.6.78.29 39396 127.0.0.1 7081
[05/Oct/
...
show less
Web App Attack
๐ต๐ฑ
strefapi_com
2026-10-04 23:31:06
(4 days ago)
Brute-force, web
...
Hacking
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-04 23:16:30
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.6.78.29 (29.78.6.34.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:210492) triggered by 34.6.78.29 (29.78.6.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 19:16:23.221451 2026] [security2:error] [pid 26518:tid 26518] [client 34.6.78.29:33036] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ypsisda.net"] [uri "/.htpasswd"] [unique_id "asLeR8bjRIG9LHpzvn4NwgAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack