Anonymous
2026-10-02 04:31:52
(5 days ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
๐บ๐ธ
TPI-Abuse
2026-10-01 15:45:12
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 34.74.128.140 (140.128.74.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.74.128.140 (140.128.74.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 11:45:06.530425 2026] [security2:error] [pid 14752:tid 14752] [client 34.74.128.140:44812] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.nashes.net"] [uri "/.env.js"] [unique_id "ar6AAiLXi0x9JZWlIS4TWwAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
updown.io
2026-10-01 15:44:40
(5 days ago)
{"level":"info","ts":1790869465.2097766,"logger":"http.log.access.log1","msg":"handled request","req ...
show more
{"level":"info","ts":1790869465.2097766,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"34.74.128.140","remote_port":"54608","client_ip":"34.74.128.140","proto":"HTTP/2.0","method":"GET","host":"status.evolix.net","uri":"/assets/manifest.json","headers":{"Priority":["u=1"],"User-Agent":["Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Mobile Safari/537.36"],"Sec-Ch-Ua":["\"Chromium\";v=\"153\", \"Google Chrome\";v=\"153\", \"Not_A Brand\";v=\"8\""],"Sec-Fetch-Site":["same-origin"],"X-Middleware-Subrequest":["src/middleware:nowaf:src/middleware:src/middleware:src/middleware:src/middleware:middleware:middleware:nowaf:middleware:middleware:middleware:pages/_middleware"],"X-Nextjs-Data":["1"],"Accept-Encoding":["gzip, deflate, br, zstd"],"Sec-Fetch-Mode":["no-cors"],"Accept":["*/*"],"Sec-Ch-Ua-Mobile":["?1"],"Accept-Language":["en-US,en;q=0.9"],"Sec-Ch-Ua-Platform":["\"Android\""],"Sec-Fetch-Dest":["script"]},"tls":
...
show less
DDoS Attack
Web App Attack
๐ซ๐ท
masterguru
2026-10-01 15:37:34
(5 days ago)
BAD BOT - Detected and Blocked.. Matched phrase "baidu" at REQUEST_HEADERS:User-Agent. (1100000-196)
Bad Web Bot
๐ณ๐ฑ
debestelapp
2026-10-01 15:35:07
(5 days ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 15:12:11
(5 days ago)
(mod_security) mod_security (id:210730) triggered by 34.74.128.140 (140.128.74.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.74.128.140 (140.128.74.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 11:12:04.216599 2026] [security2:error] [pid 21307:tid 21307] [client 34.74.128.140:38278] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.daisydoesoap.com|F|2"] [data ".daisydoesoap.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.daisydoesoap.com"] [uri "/z9x8c7v6b5-debug-trigger-www.daisydoesoap.com"] [unique_id "ar54RBhaPBDMny42eahVQQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ฌ
Cloudkul Cloudkul
2026-10-01 15:06:26
(5 days ago)
Attempted Brute Force on our application
Brute-Force
Web App Attack
๐ฉ๐ช
kkw
2026-10-01 14:07:55
(5 days ago)
[REDACTED] 34.74.128.140 - - [01/Oct/2026:16:07:55 +0200] "GET /.ssh/id_rsa HTTP/2.0" 404 352 "-" "D ...
show more
[REDACTED] 34.74.128.140 - - [01/Oct/2026:16:07:55 +0200] "GET /.ssh/id_rsa HTTP/2.0" 404 352 "-" "DuckAssistBot/1.1 (https://duckduckgo.com/duckassistbot)"
... (mode: searching http-sensitive-files)
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 13:15:10
(5 days ago)
(mod_security) mod_security (id:210730) triggered by 34.74.128.140 (140.128.74.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.74.128.140 (140.128.74.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 09:15:02.769239 2026] [security2:error] [pid 15377:tid 15377] [client 34.74.128.140:40370] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.kevinfranz.com|F|2"] [data ".kevinfranz.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.kevinfranz.com"] [uri "/z9x8c7v6b5-debug-trigger-www.kevinfranz.com"] [unique_id "ar5c1hDBlKFXzDXHDsScdgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
sternwart
2026-10-01 13:00:05
(5 days ago)
Automatisch erkannt: Zugriff auf /img../.env (alpasana.ch)
Web App Attack
Bad Web Bot
Anonymous
2026-10-01 12:22:45
(5 days ago)
Portscan: TCP/8443 (3x), TCP/8080 (3x)
Port Scan
๐บ๐ธ
TPI-Abuse
2026-10-01 12:19:00
(5 days ago)
(mod_security) mod_security (id:210730) triggered by 34.74.128.140 (140.128.74.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.74.128.140 (140.128.74.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 08:18:53.171433 2026] [security2:error] [pid 15427:tid 15508] [client 34.74.128.140:49880] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||frannykingsmith.com.sloveniaflyfishing.com|F|2"] [data ".com.sloveniaflyfishing.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "frannykingsmith.com.sloveniaflyfishing.com"] [uri "/z9x8c7v6b5-debug-trigger-frannykingsmith.com.sloveniaflyfishing.com"] [unique_id "ar5PrYgpWpTqiGMU8QMZvgAAAVU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-10-01 12:18:43
(5 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 1247
Exploited Host
Web App Attack
๐ซ๐ท
guillaume illien
2026-10-01 11:40:21
(5 days ago)
34.74.128.140 - - [01/Oct/2026:11:40:15 +0000] "POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2 ...
show more
34.74.128.140 - - [01/Oct/2026:11:40:15 +0000] "POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh HTTP/1.1" 400 166 "-" "-"
34.74.128.140 - - [01/Oct/2026:11:40:20 +0000] "GET /..%2f.env HTTP/1.1" 400 166 "-" "-"
34.74.128.140 - - [01/Oct/2026:11:40:20 +0000] "GET /%2e%2e/.env HTTP/1.1" 400 166 "-" "-"
34.74.128.140 - - [01/Oct/2026:11:40:20 +0000] "GET /..%2f..%2f.env HTTP/1.1" 400 166 "-" "-"
34.74.128.140 - - [01/Oct/2026:11:40:20 +0000] "GET /icons/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/proc/self/environ HTTP/1.1" 400 166 "-" "-"
34.74.128.140 - - [01/Oct/2026:11:40:20 +0000] "GET /api/uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2fproc/self/environ HTTP/1.1" 400 166 "-" "-"
34.74.128.140 - - [01/Oct/2026:11:40:21 +0000] "GET /api/uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f.env HTTP/1.1" 400 166 "-" "-"
...
show less
Hacking
Brute-Force
Web App Attack
SSH
๐บ๐ธ
SLSLLC
2026-10-01 11:39:01
(5 days ago)
34.74.128.140 - - [01/Oct/2026:11:38:59 +0000] "GET /__env.js HTTP/2.0" 403 282 "-" "Mozilla/5.0 (co ...
show more
34.74.128.140 - - [01/Oct/2026:11:38:59 +0000] "GET /__env.js HTTP/2.0" 403 282 "-" "Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; +https://kimi.ai/)"
...
show less
Brute-Force
Web App Attack