๐ง๐ช
taivas.nl
2026-10-10 04:32:43
(2 hours ago)
Many_bad_calls
Web App Attack
๐ง๐ท
radardatelecom
2026-10-09 22:27:03
(8 hours ago)
Blocked by Radar da Telecom firewall โ abuseipdb
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 22:12:31
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.60.32.20 (20.32.60.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.60.32.20 (20.32.60.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 18:12:28.000286 2026] [security2:error] [pid 15948:tid 15948] [client 34.60.32.20:34178] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lynetteharris.net"] [uri "/%2e%2e/.env"] [unique_id "aslmy9nNN4FKoSZA4t07zQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Andrew
2026-10-09 21:57:46
(9 hours ago)
34.60.32.20 - - [09/Oct/2026:22:57:44 +0100] "GET /static../.env HTTP/1.1" 404 18363 "-" "Mozilla/5. ...
show more
34.60.32.20 - - [09/Oct/2026:22:57:44 +0100] "GET /static../.env HTTP/1.1" 404 18363 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36; compatible; OAI-SearchBot/1.4; +https://openai.com/searchbot"
34.60.32.20 - - [09/Oct/2026:22:57:44 +0100] "GET /media../.env HTTP/1.1" 404 18362 "-" "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)"
34.60.32.20 - - [09/Oct/2026:22:57:44 +0100] "GET /files../.env HTTP/1.1" 404 18362 "-" "Mozilla/5.0 (compatible; Bravebot/1.0; +https://brave.com/search/)"
34.60.32.20 - - [09/Oct/2026:22:57:44 +0100] "GET /assets../.env HTTP/1.1" 404 18363 "-" "CCBot/2.0 (https://commoncrawl.org/faq/)"
34.60.32.20 - - [09/Oct/2026:22:57:44 +0100] "GET /images../.env HTTP/1.1" 404 18363 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Safari/605.1.15 (Applebot/0.1)"
34.60.32.20 - - [09/Oct/2026:22:57:44 +010
...
show less
Hacking
Web App Attack
๐บ๐ธ
interbiznw.com
2026-10-09 21:53:51
(9 hours ago)
fail2ban-ban
Hacking
Brute-Force
Exploited Host
Web App Attack
๐บ๐ธ
EmilGH
2026-10-09 21:18:21
(10 hours ago)
34.60.32.20 - - [09/Oct/2026:21:18:20 +0000] "GET /z9x8c7v6b5-debug-trigger-lisaragan.net HTTP/1.1" ...
show more
34.60.32.20 - - [09/Oct/2026:21:18:20 +0000] "GET /z9x8c7v6b5-debug-trigger-lisaragan.net HTTP/1.1" 404 459 "-" "Mozilla/5.0 (compatible; PanguBot/1.0; +https://www.huaweicloud.com/)"
34.60.32.20 - - [09/Oct/2026:21:18:20 +0000] "GET /manifest.json HTTP/1.1" 404 459 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36 Edg/153.0.0.0"
34.60.32.20 - - [09/Oct/2026:21:18:20 +0000] "GET /static/manifest.json HTTP/1.1" 404 4412 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36 Edg/153.0.0.0"
34.60.32.20 - - [09/Oct/2026:21:18:20 +0000] "GET /asset-manifest.json HTTP/1.1" 404 459 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36 Edg/153.0.0.0"
34.60.32.20 - - [09/Oct/2026:21:18:20 +0000] "GET /assets/manifest.json HTTP/1.1" 404 4412 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_1
...
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-10-09 20:50:13
(10 hours ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
๐ฉ๐ช
yitzhaq
2026-10-09 20:37:26
(10 hours ago)
34.60.32.20 - - [09/Oct/2026:22:37:22 +0200] "GET /css../.env HTTP/2.0" 404 43283 "-" "Mozilla/5.0 ( ...
show more
34.60.32.20 - - [09/Oct/2026:22:37:22 +0200] "GET /css../.env HTTP/2.0" 404 43283 "-" "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)"
34.60.32.20 - - [09/Oct/2026:22:37:22 +0200] "GET /static/../../../a/../../../../.env HTTP/2.0" 400 324 "-" "Mozilla/5.0 (compatible; MistralAI-User/1.0; +https://mistral.ai/)"
34.60.32.20 - - [09/Oct/2026:22:37:22 +0200] "GET /media../.env HTTP/2.0" 404 43274 "-" "Mozilla/5.0 (compatible; ChatGLM-Spider/1.0; +https://zhipuai.cn/)"
34.60.32.20 - - [09/Oct/2026:22:37:22 +0200] "GET /static../.env HTTP/2.0" 404 43283 "-" "Mozilla/5.0 (compatible; ChatGLM-Spider/1.0; +https://zhipuai.cn/)"
34.60.32.20 - - [09/Oct/2026:22:37:22 +0200] "POST /graphql HTTP/2.0" 404 43264 "https://[site]" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
34.60.32.20 - - [09/Oct/2026:22:37:22 +0200] "GET /..%2f.env HTTP/2.0" 404 294 "-" "Mozilla/5.0 (compatible; PanguBot/1
show less
Web App Attack
Hacking
๐บ๐ธ
webgobe
2026-10-09 20:30:08
(10 hours ago)
lee-17 : Block hidden directories=>/.vite/manifest.json(/)
Hacking
๐ง๐ช
cmbplf
2026-10-09 20:23:51
(10 hours ago)
1.354 requests with url.path *.env
609 requests with url.path */@fs/*
213 requests with url.path ...
show more
1.354 requests with url.path *.env
609 requests with url.path */@fs/*
213 requests with url.path */proc/*
149 requests with url.path *config.json
128 requests with url.path *.aws/*
115 requests with url.path *credentials.json
show less
Brute-Force
Bad Web Bot
๐บ๐ธ
lavnet.net
2026-10-09 20:14:33
(11 hours ago)
34.60.32.20 - - [09/Oct/2026:20:14:32 +0000] "GET /login HTTP/2.0" 404 1878 "-" "Mozilla/5.0 (Linux; ...
show more
34.60.32.20 - - [09/Oct/2026:20:14:32 +0000] "GET /login HTTP/2.0" 404 1878 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Mobile Safari/537.36 EdgA/152.0.0.0"
34.60.32.20 - - [09/Oct/2026:20:14:32 +0000] "GET /account/login HTTP/2.0" 404 1855 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Mobile Safari/537.36 EdgA/152.0.0.0"
34.60.32.20 - - [09/Oct/2026:20:14:32 +0000] "GET /auth HTTP/2.0" 404 1855 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Mobile Safari/537.36 EdgA/152.0.0.0"
34.60.32.20 - - [09/Oct/2026:20:14:32 +0000] "GET /79fyvf18h693uhomq6an HTTP/2.0" 404 1855 "-" "DuckAssistBot/1.1 (https://duckduckgo.com/duckassistbot)"
34.60.32.20 - - [09/Oct/2026:20:14:32 +0000] "GET /sign-in HTTP/2.0" 404 1855 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Mobile Safari/537.36 EdgA/152.0.0.0"
3
...
show less
Brute-Force
Anonymous
2026-10-09 19:55:46
(11 hours ago)
sensitive path probe detected by fail2ban
...
Port Scan
Web App Attack
Anonymous
2026-10-09 19:10:03
(12 hours ago)
| Multiple common web attacks from same source ip. (multiple servers)
Web App Attack
Hacking
SQL Injection
๐ฉ๐ช
Gwyneth Llewelyn
2026-10-09 19:06:19
(12 hours ago)
2026/10/09 20:06:17 [error] 4060693#4060693: *1597977 access forbidden by rule, client: 34.60.32.20, ...
show more
2026/10/09 20:06:17 [error] 4060693#4060693: *1597977 access forbidden by rule, client: 34.60.32.20, server: gwynethllewelyn.net, request: "GET /_nuxt/../.env HTTP/2.0", host: "gwynethllewelyn.net"
2026/10/09 20:06:17 [error] 4060693#4060693: *1597979 access forbidden by rule, client: 34.60.32.20, server: gwynethllewelyn.net, request: "GET /api/orders/..%2f..%2f.env HTTP/2.0", host: "gwynethllewelyn.net"
2026/10/09 20:06:18 [error] 4060693#4060693: *1597982 access forbidden by rule, client: 34.60.32.20, server: gwynethllewelyn.net, request: "GET /api/data/..%2f..%2f.env HTTP/2.0", host: "gwynethllewelyn.net"
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 18:55:00
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.60.32.20 (20.32.60.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.60.32.20 (20.32.60.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 14:54:56.170218 2026] [security2:error] [pid 5948:tid 5948] [client 34.60.32.20:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "goalsnet.net"] [uri "/.htpasswd"] [unique_id "ask4gAH_lNGHPzNYUQE2bAAAAGE"]
show less
Brute-Force
Bad Web Bot
Web App Attack