Anonymous
2026-10-08 23:42:20
(36 minutes ago)
2026/10/08 20:42:18 [error] 2526412#2526412: *18793 openat() "/var/www/vebobinas.com/web/public/admi ...
show more
2026/10/08 20:42:18 [error] 2526412#2526412: *18793 openat() "/var/www/vebobinas.com/web/public/admin/login" failed (2: No such file or directory), client: 34.75.10.244, server: vebobinas.com, request: "GET /admin/login HTTP/2.0", host: "vebobinas.com"
2026/10/08 20:42:19 [error] 2526412#2526412: *18793 rewrite or internal redirection cycle while internally redirecting to "/error/403.html", client: 34.75.10.244, server: vebobinas.com, request: "GET /files../.env HTTP/2.0", host: "vebobinas.com"
2026/10/08 20:42:19 [error] 2526412#2526412: *18793 rewrite or internal redirection cycle while internally redirecting to "/error/403.html", client: 34.75.10.244, server: vebobinas.com, request: "GET /css../.env HTTP/2.0", host: "vebobinas.com"
...
show less
Port Scan
๐ฉ๐ช
Hazzard
2026-10-08 23:31:40
(47 minutes ago)
(mod_security) mod_security triggered on hostname [redacted]): (CF_ENABLE)
SQL Injection
๐ฉ๐ช
LRob
2026-10-08 23:23:02
(55 minutes ago)
Crawler ignoring refusals | ua: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like G ...
show more
Crawler ignoring refusals | ua: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Mobile Safari/537.36 EdgA/152.0.0.0, Mozilla/5.0 (compatible; Qwenbot/1.0; +https://qwen.alibaba.com/), Mozilla/5.0 (compatible; YouBot/1.0; +https://you.com/bot) (+6 more) | path: /webpack-stats.json, /assets/manifest.json, /static/manifest.json (+17 more)
show less
Bad Web Bot
๐ณ๐ฑ
vaddilyin
2026-10-08 23:22:56
(55 minutes ago)
{"ClientAddr":"34.75.10.244:37360","ClientHost":"34.75.10.244","ClientPort":"37360","ClientUsername" ...
show more
{"ClientAddr":"34.75.10.244:37360","ClientHost":"34.75.10.244","ClientPort":"37360","ClientUsername":"-","DownstreamContentSize":1488,"DownstreamStatus":404,"Duration":101570574,"OriginContentSize":1488,"OriginDuration":101433621,"OriginStatus":404,"Overhead":136953,"RequestAddr":"vdkln.com","RequestContentSize":0,"RequestCount":137716,"RequestHost":"vdkln.com","RequestMethod":"GET","RequestPath":"/userfiles?path=../../../../.env","RequestPort":"-","RequestProtocol":"HTTP/2.0","RequestScheme":"https","RetryAttempts":0,"RouterName":"vdkln-shlink-shortlinks@file","ServiceAddr":"shlink:8080","ServiceName":"shlink-svc@file","ServiceURL":"http://shlink:8080","StartLocal":"2026-10-08T23:22:50.280428712Z","StartUTC":"2026-10-08T23:22:50.280428712Z","TLSCipher":"TLS_AES_128_GCM_SHA256","TLSVersion":"1.3","entryPointName":"websecure","level":"info","msg":"","time":"2026-10-08T23:22:50Z"}
{"ClientAddr":"34.75.10.244:37360","ClientHost":"34.75.10.244","ClientPort":"37360","ClientUsername":"-","Do
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 23:20:43
(58 minutes ago)
(mod_security) mod_security (id:949110) triggered by 34.75.10.244 (244.10.75.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:949110) triggered by 34.75.10.244 (244.10.75.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 19:20:37.223772 2026] [security2:error] [pid 18937:tid 18937] [client 34.75.10.244:36704] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "vdeweese.com"] [uri "/z9x8c7v6b5-debug-trigger-vdeweese.com"] [unique_id "asglRa01M2irxhivo-gbeQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
[email protected]
2026-10-08 23:02:28
(1 hour ago)
CrowdSec ban: crowdsecurity/http-admin-interface-probing (duration: 71h59m53s)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 22:57:34
(1 hour ago)
(mod_security) mod_security (id:210730) triggered by 34.75.10.244 (244.10.75.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.75.10.244 (244.10.75.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 18:57:31.079132 2026] [security2:error] [pid 23949:tid 23949] [client 34.75.10.244:44478] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||vc1.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "vc1.com"] [uri "/z9x8c7v6b5-debug-trigger-vc1.com"] [unique_id "asgf2_qtzv5uwU1L7dcV8gAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-08 22:56:31
(1 hour ago)
Bad Web Bot
๐ฆ๐บ
Bay13
2026-10-08 22:53:26
(1 hour ago)
CrowdSec:custom/http-probing
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 22:34:28
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.75.10.244 (244.10.75.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.75.10.244 (244.10.75.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 18:34:23.669535 2026] [security2:error] [pid 13610:tid 13620] [client 34.75.10.244:52654] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "vavryn.net"] [uri "/images../.env"] [unique_id "asgab_HVS9lQBK_gjDzL_AAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Laplus
2026-10-08 21:14:56
(3 hours ago)
34.75.10.244 - - [08/Oct/2026:23:14:53 +0200] "GET /public/plugins/text/../../../../../../../../proc ...
show more
34.75.10.244 - - [08/Oct/2026:23:14:53 +0200] "GET /public/plugins/text/../../../../../../../../proc/self/environ HTTP/1.1" 400 157 "-" "-" "-"
34.75.10.244 - - [08/Oct/2026:23:14:53 +0200] "GET /@fs/../.env?raw?? HTTP/1.1" 302 145 "-" "Mozilla/5.0 (compatible; YiBot/1.0; +https://01.ai/)" "-"
34.75.10.244 - - [08/Oct/2026:23:14:54 +0200] "GET /@fs/proc/self/cwd/.env?raw?? HTTP/1.1" 302 145 "-" "Mozilla/5.0 (compatible; Hunyuan/1.0; +https://hunyuan.tencent.com/)" "-"
34.75.10.244 - - [08/Oct/2026:23:14:54 +0200] "GET /@fs/../.env?import&raw?? HTTP/1.1" 302 145 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot)" "-"
34.75.10.244 - - [08/Oct/2026:23:14:54 +0200] "GET /__vite_rsc_findSourceMapURL?filename=file:///proc/self/environ&environmentName=rsc HTTP/1.1" 302 145 "-" "Mozilla/5.0 (compatible; KimiBot/1.0; +https://kimi.ai/)" "-"
34.75.10.244 - - [08/Oct/2026:23:14:54 +0200] "GET /@fs/proc/self/cmdline?raw?? HT
...
show less
Hacking
Web App Attack
๐ณ๐ฑ
Alt255
2026-10-08 21:14:49
(3 hours ago)
[ti-12al] Web exploit scanning: 4 suspicious requests detected by fail2ban jail <name>. Example: 34. ...
show more
[ti-12al] Web exploit scanning: 4 suspicious requests detected by fail2ban jail <name>. Example: 34.75.10.244 - - \[08/Oct/2026:23:14:36 +0200\] "GET /images../.env HTTP/2.0" 301 422 "-" "Mozilla/5.0 \(compatible\; ChatGLM-Spider/1.0\; +https://zhipuai.cn/\)"
34.75.10.244 - - \[08/Oct/2026:23:14:36 +0200\] "GET /files../.env HTTP/2.0" 301 420 "-" "Mozilla/5.0 AppleWebKit/537.36 \(KHTML, like Gecko\; compatible\; Claude-User/1.0\; [email protected] \)"
34.75.10.244 - - \[08/Oct/2026:23:14:36 +0200\] "GET /static../.env HTTP/2.0" 301 422 "-" "Mozilla/5.0 \(compatible\; KimiBot/1.0\; +https://kimi.ai/\)"
34.75.10.244 - - \[08/Oct/2026:23:14:36 +0200\] "GET /assets../.env HTTP/2.0" 301 422 "-" "Mozilla/5.0 AppleWebKit/537.36 \(KHTML, like Gecko\; compatible\; Perplexit
...
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Roderic
2026-10-08 20:51:18
(3 hours ago)
(apache-scanners) Failed apache-scanners trigger with match [redacted])
Port Scan
๐บ๐ธ
TPI-Abuse
2026-10-08 20:33:44
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.75.10.244 (244.10.75.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.75.10.244 (244.10.75.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 16:33:38.062847 2026] [security2:error] [pid 9180:tid 9180] [client 34.75.10.244:36594] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "vanmeter.us"] [uri "/assets../.env"] [unique_id "asf-Ihfts-1KGwJ45IFrHAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-10-08 20:33:26
(3 hours ago)
[ti-24al] Web exploit scanning: 2 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-24al] Web exploit scanning: 2 suspicious requests detected by fail2ban jail apache-scanner. Example: 34.75.10.244 - - [08/Oct/2026:22:33:14 +0200] "GET /media../.env HTTP/2.0" 302 1129 "-" "Mozilla/5.0 (compatible; DeepSeekBot/1.0; +https://www.deepseek.com/)"
34.75.10.244 - - [08/Oct/2026:22:33:14 +0200] "GET /static../.env HTTP/2.0" 302 1137 "-" "Mozilla/5.0 (compatible; cohere-ai; +https://cohere.com/crawler)"
...
show less
Bad Web Bot
Web App Attack