๐บ๐ธ
julianalee.com
2026-09-22 17:57:00
(2 days ago)
21/Sep/26 12:07:32 #2237101 CRITICAL 520 34.74.243.160 GET /__vite_rsc_findSourceMapURL?file ...
show more
21/Sep/26 12:07:32 #2237101 CRITICAL 520 34.74.243.160 GET /__vite_rsc_findSourceMapURL?filename=file:///root/.aws/credentials&environmentName=rsc - Data URI scheme or PHP wrappers - [GET:filename = file:///root/.aws/credentials] - mail.atherton-ca-homes-and-real-estate.com
21/Sep/26 12:07:34 #7202336 CRITICAL 3 34.74.243.160 GET /__vite_rsc_findSourceMapURL?filename=file:///proc/self/environ&environmentName=rsc - Local file inclusion - [GET:filename = file:///proc/self/environ] - mail.atherton-ca-homes-and-real-estate.com
21/Sep/26 12:07:34 #7937153 CRITICAL 520 34.74.243.160 GET /__vite_rsc_findSourceMapURL?filename=file:///root/.ssh/id_rsa&environmentName=rsc - Data URI scheme or PHP wrappers - [GET:filename = file:///root/.ssh/id_rsa] - mail.atherton-ca-homes-and-real-estate.com
show less
Hacking
๐ฒ๐ฝ
octageeks.com
2026-09-22 04:19:30
(3 days ago)
Wordpress malicious attack:[octablocked]
Web App Attack
๐บ๐ธ
oralunal
2026-09-22 01:44:47
(3 days ago)
IP banned by Fail2Ban in jail ah-suss access.log mvfnds
...
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 00:51:45
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.74.243.160 (160.243.74.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.74.243.160 (160.243.74.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 20:51:37.664666 2026] [security2:error] [pid 4309:tid 4309] [client 34.74.243.160:59626] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.capitalacc.com"] [uri "/.env"] [unique_id "arHRGU5jqc7DYtfhD7R0iwAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 00:24:49
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 34.74.243.160 (160.243.74.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.74.243.160 (160.243.74.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 20:24:44.198895 2026] [security2:error] [pid 31891:tid 31891] [client 34.74.243.160:44770] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.armorcorp.com|F|2"] [data ".armorcorp.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.armorcorp.com"] [uri "/z9x8c7v6b5-debug-trigger-mail.armorcorp.com"] [unique_id "arHKzMUvNNxoKYMU2MbBsgAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 22:41:31
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.74.243.160 (160.243.74.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.74.243.160 (160.243.74.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 18:41:25.680510 2026] [security2:error] [pid 936:tid 936] [client 34.74.243.160:39640] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.arrowhead30.com"] [uri "/.env.bak"] [unique_id "arGylX02zO-ZBO2cDB7uXQAAADE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
updown.io
2026-09-21 21:41:35
(3 days ago)
{"level":"info","ts":1790026893.0157425,"logger":"http.log.access.log1","msg":"handled request","req ...
show more
{"level":"info","ts":1790026893.0157425,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"34.74.243.160","remote_port":"45144","client_ip":"34.74.243.160","proto":"HTTP/2.0","method":"POST","host":"status.makeplans.com","uri":"/graphql","headers":{"Sec-Ch-Ua-Mobile":["?0"],"Priority":["u=1, i"],"Sec-Ch-Ua":["\"Chromium\";v=\"152\", \"Not?A_Brand\";v=\"24\", \"Brave\";v=\"152\""],"Sec-Fetch-Dest":["empty"],"Sec-Ch-Ua-Platform":["\"Windows\""],"Accept-Encoding":["gzip, deflate, br, zstd"],"Content-Type":["application/json"],"Accept-Language":["en-US,en;q=0.9"],"Referer":["https://status.makeplans.com"],"Accept":["*/*"],"Origin":["https://status.makeplans.com"],"Sec-Fetch-Mode":["cors"],"Sec-Fetch-Site":["same-origin"],"Content-Length":["86"],"User-Agent":["Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36"]},"tls":{"resumed":false,"version":772,"cipher_suite":4865,"proto":"h2","server_name":"statu
...
show less
DDoS Attack
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 21:29:03
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.74.243.160 (160.243.74.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.74.243.160 (160.243.74.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 17:28:55.563828 2026] [security2:error] [pid 7127:tid 7127] [client 34.74.243.160:34896] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "acmax.com"] [uri "/.git/config"] [unique_id "arGhl0WHT71nkizYW5eu-QAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 20:51:46
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.74.243.160 (160.243.74.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.74.243.160 (160.243.74.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 16:51:41.111089 2026] [security2:error] [pid 22115:tid 22115] [client 34.74.243.160:39272] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.abbeygardensllandudno.com"] [uri "/services/.env"] [unique_id "arGY3V-SK5JPLsNpV0sxcgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 20:34:08
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.74.243.160 (160.243.74.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.74.243.160 (160.243.74.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 16:34:02.525480 2026] [security2:error] [pid 26338:tid 26338] [client 34.74.243.160:33108] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.ainalea.com"] [uri "/.env.save"] [unique_id "arGUutaPdgwuOeq75xx7qQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
Burayot
2026-09-21 19:36:09
(3 days ago)
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 34.74.243.160 (US/United States/160. ...
show more
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 34.74.243.160 (US/United States/160.243.74.34.bc.googleusercontent.com): 2 in the last 3600 secs
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 19:01:15
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.74.243.160 (160.243.74.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.74.243.160 (160.243.74.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 15:01:10.689575 2026] [security2:error] [pid 17261:tid 17261] [client 34.74.243.160:49006] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.aiamur.com"] [uri "/.git/HEAD"] [unique_id "arF-9qDdrpc4H780SSvB3QAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 18:33:36
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.74.243.160 (160.243.74.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.74.243.160 (160.243.74.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 14:33:31.487694 2026] [security2:error] [pid 8281:tid 8281] [client 34.74.243.160:56572] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.astrologydemo.com"] [uri "/.env.production"] [unique_id "arF4ezmT0D1M_JrpMFOKaAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 18:04:18
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.74.243.160 (160.243.74.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.74.243.160 (160.243.74.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 14:04:14.061436 2026] [security2:error] [pid 20880:tid 20880] [client 34.74.243.160:48232] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "arsenalfordemocracy.com"] [uri "/.env.bak"] [unique_id "arFxnkg1-E9zkAkzOskRfgAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 17:47:16
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.74.243.160 (160.243.74.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.74.243.160 (160.243.74.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 13:47:13.564670 2026] [security2:error] [pid 26268:tid 26268] [client 34.74.243.160:37560] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.brinkworthmodels.com"] [uri "/.git/config"] [unique_id "arFtoQYw5r2QHN5v0rvJTgAAACw"]
show less
Brute-Force
Bad Web Bot
Web App Attack