๐บ๐ธ
TPI-Abuse
2026-10-09 21:26:56
(9 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.75.100.24 (24.100.75.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.75.100.24 (24.100.75.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 17:26:50.680737 2026] [security2:error] [pid 10966:tid 10966] [client 34.75.100.24:42782] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "busoil.net"] [uri "/media../.env"] [unique_id "aslcGi_aarGbjqD8RV7hMgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-09 20:56:59
(39 minutes ago)
Banned by Fail2Ban on server
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 20:53:52
(42 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.75.100.24 (24.100.75.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.75.100.24 (24.100.75.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 16:53:45.009901 2026] [security2:error] [pid 31907:tid 31907] [client 34.75.100.24:48212] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bookguardian.net"] [uri "/assets../.env"] [unique_id "aslUWe7AIT6vvYLVgDxemAAAADI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 20:13:21
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.75.100.24 (24.100.75.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.75.100.24 (24.100.75.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 16:13:16.313722 2026] [security2:error] [pid 2116:tid 2116] [client 34.75.100.24:46308] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bigheartskitchen.net"] [uri "/assets../.env"] [unique_id "aslK3D7eynG0o1X6VxxKUQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-09 20:00:51
(1 hour ago)
[BestVouchers.net] Honeypot trap triggered | Path: /.env | Time: 2026-10-09T20:00:51.877Z | UA: Mozi ...
show more
[BestVouchers.net] Honeypot trap triggered | Path: /.env | Time: 2026-10-09T20:00:51.877Z | UA: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexitybot) | Action: Automatically blocked for 24h and reported
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
abenage
2026-10-09 19:48:41
(1 hour ago)
34.75.100.24 - - [09/Oct/2026:13:48:40 -0600] "GET /vz1qah5nuyszussdlq9r HTTP/2.0" 404 162 "-" "Duck ...
show more
34.75.100.24 - - [09/Oct/2026:13:48:40 -0600] "GET /vz1qah5nuyszussdlq9r HTTP/2.0" 404 162 "-" "DuckAssistBot/1.1 (https://duckduckgo.com/duckassistbot)"
show less
Bad Web Bot
Web App Attack
๐ฌ๐ง
bensmithurst
2026-10-09 19:36:32
(1 hour ago)
34.75.100.24 - - [09/Oct/2026:19:36:30 +0000] "GET /public/plugins/text/../../../../../../../../proc ...
show more
34.75.100.24 - - [09/Oct/2026:19:36:30 +0000] "GET /public/plugins/text/../../../../../../../../proc/self/environ HTTP/1.1" 400 150 "-" "-"
34.75.100.24 - - [09/Oct/2026:19:36:30 +0000] "GET /@fs/..%2f..%2f..%2f..%2f..%2froot/.env HTTP/1.1" 400 150 "-" "-"
34.75.100.24 - - [09/Oct/2026:19:36:30 +0000] "GET /@fs/..%2f..%2f..%2f..%2f..%2fproc/self/environ HTTP/1.1" 400 150 "-" "-"
34.75.100.24 - - [09/Oct/2026:19:36:32 +0000] "GET /%2e%2e/%2e%2e/%2e%2e/%2e%2e/.env HTTP/1.1" 400 150 "-" "-"
34.75.100.24 - - [09/Oct/2026:19:36:32 +0000] "GET /%2e%2e/%2e%2e/%2e%2e/%2e%2e/proc/self/environ HTTP/1.1" 400 150 "-" "-"
... [host=LAN***]
show less
Web App Attack
๐บ๐ธ
Lee Daniel
2026-10-09 19:25:49
(2 hours ago)
34.75.100.24 - - [09/Oct/2026:15:25:48 -0400] "GET /.htpasswd HTTP/1.1" 403 377 "-" "Mozilla/5.0 (co ...
show more
34.75.100.24 - - [09/Oct/2026:15:25:48 -0400] "GET /.htpasswd HTTP/1.1" 403 377 "-" "Mozilla/5.0 (compatible; PanguBot/1.0; +https://www.huaweicloud.com/)"
...
show less
DDoS Attack
Web Spam
Email Spam
Port Scan
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 19:25:41
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.75.100.24 (24.100.75.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.75.100.24 (24.100.75.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 15:25:34.933163 2026] [security2:error] [pid 11861:tid 11861] [client 34.75.100.24:43560] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "barabesi.net"] [uri "/media../.env"] [unique_id "ask_riDq1YJsytmZke_vDwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-09 19:15:01
(2 hours ago)
suspicious request in access.log
Web App Attack
๐บ๐ธ
kosada.com
2026-10-09 19:13:26
(2 hours ago)
Repeated requests for suspicious nonexistent URLs, for example: /assets/manifest.json (HTTP port 443 ...
show more
Repeated requests for suspicious nonexistent URLs, for example: /assets/manifest.json (HTTP port 443, user agent: "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36")
show less
Web App Attack
๐ซ๐ท
regishoussin
2026-10-09 18:55:05
(2 hours ago)
Automated web scanning detected by Wazuh (rule 100241): repeated 400/404 errors from mass probing of ...
show more
Automated web scanning detected by Wazuh (rule 100241): repeated 400/404 errors from mass probing of admin/backdoor paths (e.g. wp-login.php, known CMS shell filenames) on an Apache web server, on 2026-10-09 18:55 UTC.
show less
Bad Web Bot
Web App Attack
๐ช๐ธ
scaballe
2026-10-09 18:41:02
(2 hours ago)
Web App Attack
๐ง๐ช
cmbplf
2026-10-09 18:28:10
(3 hours ago)
2.742 requests with url.path *.env
964 requests with url.path */@fs/*
377 requests with url.path ...
show more
2.742 requests with url.path *.env
964 requests with url.path */@fs/*
377 requests with url.path */proc/*
263 requests with url.path *config.json
245 requests with url.path *credentials.json
218 requests with url.path *.aws/*
127 requests with url.path *.ssh/*
show less
Brute-Force
Bad Web Bot
๐ธ๐ช
vaia.cloud
2026-10-09 18:25:02
(3 hours ago)
crowdsecurity/grafana-cve-2021-43798
Brute-Force
Web App Attack