๐น๐ท
eryilmaz
2026-09-30 17:31:05
(2 days ago)
Automated attack blocked by eryilmaz WAF/defense engine (level 1, source: siem_correlation, path: /)
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-30 15:23:41
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 34.7.35.101 (101.35.7.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.7.35.101 (101.35.7.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 11:23:34.602689 2026] [security2:error] [pid 25836:tid 25857] [client 34.7.35.101:54462] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||iancaird.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "iancaird.com"] [uri "/z9x8c7v6b5-debug-trigger-iancaird.com"] [unique_id "ar0pdmWaSoqWJhCSQZz6qwAAAVM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-30 15:23:15
(2 days ago)
34.7.35.101 - - [30/Sep/2026:23:23:14 +0800] "GET /manifest.json HTTP/1.1" 404 196 "-" "Mozilla/5.0 ...
show more
34.7.35.101 - - [30/Sep/2026:23:23:14 +0800] "GET /manifest.json HTTP/1.1" 404 196 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36 Edg/153.0.0.0"
34.7.35.101 - - [30/Sep/2026:23:23:14 +0800] "GET /os13sk5qildhqv5a0kdu HTTP/1.1" 404 30479 "-" "Mozilla/5.0 (compatible; xAI-Grok/1.0; +https://x.ai/)"
34.7.35.101 - - [30/Sep/2026:23:23:14 +0800] "GET /dist/manifest.json HTTP/1.1" 404 196 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36 Edg/153.0.0.0"
34.7.35.101 - - [30/Sep/2026:23:23:14 +0800] "GET /static/manifest.json HTTP/1.1" 404 196 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36 Edg/153.0.0.0"
34.7.35.101 - - [30/Sep/2026:23:23:14 +0800] "GET /assets/manifest.json HTTP/1.1" 404 196 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0
...
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-09-30 14:58:15
(2 days ago)
Crawler ignoring refusals | ua: Mozilla/5.0 (compatible; GrokBot/1.0; +https://x.ai/), Mozilla/5.0 ( ...
show more
Crawler ignoring refusals | ua: Mozilla/5.0 (compatible; GrokBot/1.0; +https://x.ai/), Mozilla/5.0 (compatible; cohere-ai; +https://cohere.com/crawler), Mozilla/5.0 (compatible; Qwenbot/1.0; +https://qwen.alibaba.com/) (+3 more) | path: /til5htk497aiwyx2xxc9, /lib/terminal-xhr.php, /uw8a4vjensf1uugs6zrl (+4 more)
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-30 14:30:46
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.7.35.101 (101.35.7.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.7.35.101 (101.35.7.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 10:30:39.002122 2026] [security2:error] [pid 21734:tid 21734] [client 34.7.35.101:42842] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.digitalracemedia.com"] [uri "/static../.env"] [unique_id "ar0dD2QSiuh8qtE_4XaFmwAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 14:12:26
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 34.7.35.101 (101.35.7.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.7.35.101 (101.35.7.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 10:12:18.777891 2026] [security2:error] [pid 21710:tid 21710] [client 34.7.35.101:46406] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||dunnretired.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "dunnretired.com"] [uri "/z9x8c7v6b5-debug-trigger-dunnretired.com"] [unique_id "ar0Ywger2Dj7naIlZOogGwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
svr
2026-09-30 14:06:29
(2 days ago)
Abusive Automated Web Scanner
Web App Attack
๐ช๐ธ
masterguru
2026-09-30 13:49:18
(2 days ago)
BAD BOT - Detected and Blocked.. Matched phrase "bytespider" at REQUEST_HEADERS:user-agent. (1100000 ...
show more
BAD BOT - Detected and Blocked.. Matched phrase "bytespider" at REQUEST_HEADERS:user-agent. (1100000-122)
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-30 13:34:47
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.7.35.101 (101.35.7.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.7.35.101 (101.35.7.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 09:34:38.381320 2026] [security2:error] [pid 1275:tid 1275] [client 34.7.35.101:50528] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.gwdailey.com"] [uri "/.env.php.bak"] [unique_id "ar0P7nsf5j__NeD-vqiY3AAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 13:19:27
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 34.7.35.101 (101.35.7.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.7.35.101 (101.35.7.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 09:19:23.301391 2026] [security2:error] [pid 25225:tid 25225] [client 34.7.35.101:51576] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.greatchristianadventure.com|F|2"] [data ".greatchristianadventure.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.greatchristianadventure.com"] [uri "/z9x8c7v6b5-debug-trigger-www.greatchristianadventure.com"] [unique_id "ar0MWxIsPOW_InS-XhOoIgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 13:03:03
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.7.35.101 (101.35.7.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.7.35.101 (101.35.7.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 09:02:56.562401 2026] [security2:error] [pid 7780:tid 7780] [client 34.7.35.101:46694] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.grupoporvenir.com"] [uri "/__vite_rsc_findSourceMapURL"] [unique_id "ar0IgNgW18Edrh4I2nFgSgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 12:32:19
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 34.7.35.101 (101.35.7.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.7.35.101 (101.35.7.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 08:32:15.657933 2026] [security2:error] [pid 8243:tid 8243] [client 34.7.35.101:53104] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||inmosantanora.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "inmosantanora.com"] [uri "/z9x8c7v6b5-debug-trigger-inmosantanora.com"] [unique_id "ar0BTyyzj-Q8jYXiJCiIXgAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
robotstxt
2026-09-30 12:03:13
(3 days ago)
34.7.35.101 - - [30/Sep/2026:12:02:17 +0000] "GET /assets../.env HTTP/2.0" 403 49517 "https://www.ec ...
show more
34.7.35.101 - - [30/Sep/2026:12:02:17 +0000] "GET /assets../.env HTTP/2.0" 403 49517 "https://www.economipedia.com/assets../.env" "Mozilla/5.0 (compatible; xAI-Grok/1.0; +https://x.ai/)" "-"
34.7.35.101 - - [30/Sep/2026:12:02:18 +0000] "GET /css../.env HTTP/2.0" 403 49525 "https://www.economipedia.com/css../.env" "Mozilla/5.0 (compatible; Meta-ExternalAgent/1.0; +https://developers.facebook.com/docs/sharing/webmasters/crawler)" "-"
34.7.35.101 - - [30/Sep/2026:12:02:18 +0000] "GET /static/app/.env HTTP/2.0" 403 49592 "https://www.economipedia.com/static//app/.env" "Mozilla/5.0 (compatible; GrokBot/1.0; +https://x.ai/)" "-"
34.7.35.101 - - [30/Sep/2026:12:02:19 +0000] "GET /.env HTTP/2.0" 403 49591 "https://www.economipedia.com//.env" "Mozilla/5.0 (compatible; Qwenbot/1.0; +https://qwen.alibaba.com/)" "-"
34.7.35.101 - - [30/Sep/2026:12:02:20 +0000] "GET /.env.js HTTP/2.0" 403 49592 "https://www.economipedia.com/.env.js" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 11:58:38
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.7.35.101 (101.35.7.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.7.35.101 (101.35.7.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 07:58:35.450545 2026] [security2:error] [pid 9004:tid 9004] [client 34.7.35.101:49206] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.frankweyer.com"] [uri "/.htpasswd"] [unique_id "arz5awrDyRwGSrqzo9ZFRAAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
updown.io
2026-09-30 11:55:12
(3 days ago)
{"level":"info","ts":1790769311.7492187,"logger":"http.log.access.log1","msg":"handled request","req ...
show more
{"level":"info","ts":1790769311.7492187,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"34.7.35.101","remote_port":"43958","client_ip":"34.7.35.101","proto":"HTTP/2.0","method":"GET","host":"status.gptoday.com","uri":"/t0ubmsvlyloo4a0q7mfl","headers":{"Accept":["*/*"],"X-Middleware-Subrequest":["src/middleware:nowaf:src/middleware:src/middleware:src/middleware:src/middleware:middleware:middleware:nowaf:middleware:middleware:middleware:pages/_middleware"],"X-Nextjs-Data":["1"],"Accept-Encoding":["gzip"],"User-Agent":["Mozilla/5.0 (compatible; KimiBot/1.0; +https://kimi.ai/)"]},"tls":{"resumed":false,"version":772,"cipher_suite":4865,"proto":"h2","server_name":"status.gptoday.com","ech":false}},"bytes_read":0,"user_id":"","duration":0.000140007,"size":0,"status":429,"resp_headers":{"Server":["Caddy"],"Alt-Svc":["h3=\":443\"; ma=2592000"],"Retry-After":["1"]}}
{"level":"info","ts":1790769311.8651235,"logger":"http.log.access.log1","msg":"handled request","r
...
show less
DDoS Attack
Web App Attack