๐ณ๐ฑ
Alt255
2026-09-30 19:32:27
(1 week ago)
[ti-07al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-07al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 34.75.229.154 - - [30/Sep/2026:21:32:20 +0200] "GET /.env HTTP/1.1" 404 7386 "-" "Mozilla/5.0 (compatible; MoonshotBot/1.0; +https://kimi.ai/)"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
WeekendWeb
2026-09-30 18:33:24
(1 week ago)
Wordpress Vunerability attack
Web App Attack
๐ช๐ธ
robotstxt
2026-09-30 18:31:24
(1 week ago)
34.75.229.154 - - [30/Sep/2026:17:22:28 +0000] "GET /cgi-bin/php-cgi.exe?%ADd+allow_url_include%3d1+ ...
show more
34.75.229.154 - - [30/Sep/2026:17:22:28 +0000] "GET /cgi-bin/php-cgi.exe?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input HTTP/2.0" 404 16286 "https://orders.temporada-alta.com/cgi-bin/php-cgi.exe?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; [email protected] )"
34.75.229.154 - - [30/Sep/2026:17:22:29 +0000] "GET /cgi-bin/php?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input HTTP/2.0" 404 16280 "https://orders.temporada-alta.com/cgi-bin/php?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input" "Mozilla/5.0 (compatible; ChatGLM-Spider/1.0; +https://zhipuai.cn/)"
34.75.229.154 - - [30/Sep/2026:17:22:30 +0000] "GET /cgi-bin/php-cgi?-d+allow_url_include%3don+-d+auto_prepend_file%3dphp://input HTTP/2.0" 404 16280 "https://orders.temporada-alta.com/cgi-bin/php-cgi?-d+allow_url_include%3don+-d+auto_prepend_file%3dphp://input" "Mozilla/5.0 (compatib
...
show less
Bad Web Bot
๐ช๐ธ
robotstxt
2026-09-30 17:23:06
(1 week ago)
34.75.229.154 - - [30/Sep/2026:17:22:19 +0000] "GET /.env.js HTTP/2.0" 403 16238 "https://orders.tem ...
show more
34.75.229.154 - - [30/Sep/2026:17:22:19 +0000] "GET /.env.js HTTP/2.0" 403 16238 "https://orders.temporada-alta.com/.env.js" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
34.75.229.154 - - [30/Sep/2026:17:22:20 +0000] "GET /.dockerenv HTTP/2.0" 403 16239 "https://orders.temporada-alta.com/.dockerenv" "Mozilla/5.0 (compatible; cohere-ai; +https://cohere.com/crawler)"
34.75.229.154 - - [30/Sep/2026:17:22:21 +0000] "GET /cache/original/%2e%2e/.env HTTP/2.0" 403 16248 "https://orders.temporada-alta.com/cache/original/%2e%2e/.env" "Mozilla/5.0 (compatible; ChatGLM-Spider/1.0; +https://zhipuai.cn/)"
34.75.229.154 - - [30/Sep/2026:17:22:21 +0000] "GET /cache/original/%2e%2e/%2e%2e/.env HTTP/2.0" 403 16249 "https://orders.temporada-alta.com/cache/original/%2e%2e/%2e%2e/.env" "Mozilla/5.0 (compatible; xAI-Grok/1.0; +https://x.ai/)"
34.75.229.154 - - [30/Sep/2026:17:22:25 +0000] "GET /.env HTTP/2.0" 403 16235 "https://orders.temporada-alta.com/.env" "Mozilla/5.0 (com
...
show less
Web App Attack
๐บ๐ธ
masterguru
2026-09-30 16:15:58
(1 week ago)
BAD BOT - Detected and Blocked.. Matched phrase "ChatGPT-User" at REQUEST_HEADERS:user-agent. (11000 ...
show more
BAD BOT - Detected and Blocked.. Matched phrase "ChatGPT-User" at REQUEST_HEADERS:user-agent. (1100000-169)
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-30 16:07:07
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.75.229.154 (154.229.75.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.75.229.154 (154.229.75.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 12:07:03.354706 2026] [security2:error] [pid 2199:tid 2199] [client 34.75.229.154:33342] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.scifitimeline.com"] [uri "/dist../.env"] [unique_id "ar0zpzh8_Mt3NKLdYOW0MQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-30 15:54:35
(1 week ago)
[ns41.kdns.gr] httpd-config-scan: sites=www.seapraxismaritime.com; logs=/var/log/httpd/domains/seapr ...
show more
[ns41.kdns.gr] httpd-config-scan: sites=www.seapraxismaritime.com; logs=/var/log/httpd/domains/seapraxismaritime.com.log; samples=/terraform.tfstate | /.npmrc | /.ssh/id_rsa
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 14:27:41
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.75.229.154 (154.229.75.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.75.229.154 (154.229.75.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 10:27:36.174204 2026] [security2:error] [pid 16651:tid 16651] [client 34.75.229.154:32990] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.tenmenband.com"] [uri "/admin/.env"] [unique_id "ar0cWBA5TjhbWvlGgjIPAgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
VanKoh
2026-09-30 14:20:21
(1 week ago)
(cpanel) Failed cPanel login from 34.75.229.154 (US/United States/South Carolina/North Charleston/15 ...
show more
(cpanel) Failed cPanel login from 34.75.229.154 (US/United States/South Carolina/North Charleston/154.229.75.34.bc.googleusercontent.com): 5 in the last 3600 secs; IP: 34.75.229.154; Ports: *; Direction: 1; Trigger: LF_TRIGGER; Logs: [2026-09-30 08:20:18 -0600] info [cpaneld] 34.75.229.154 - - "GET /assets/manifest.json HTTP/1.1" FAILED LOGIN cpaneld: login attempt without username [2026-09-30 08:20:18 -0600] info [cpaneld] 34.75.229.154 - - "GET /model/info HTTP/1.1" FAILED LOGIN cpaneld: Authorization: type not known [2026-09-30 08:20:18 -0600] info [cpaneld] 34.75.229.154 - - "GET /api/settings HTTP/1.1" FAILED LOGIN cpaneld: login attempt without username [2026-09-30 08:20:18 -0600] info [cpaneld] 34.75.229.154 - - "GET /env.js HTTP/1.1" FAILED LOGIN cpaneld: login attempt without username [2026-09-30 08:20:18 -0600] info [cpaneld] 34.75.229.154 - - "GET /__/firebase/init.json HTTP/1.1" FAILED LOGIN cpaneld: login attempt without username
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-30 13:43:33
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.75.229.154 (154.229.75.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.75.229.154 (154.229.75.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 09:43:28.989505 2026] [security2:error] [pid 18447:tid 18447] [client 34.75.229.154:56458] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.tekbit.com"] [uri "/static../.env"] [unique_id "ar0SAI5bDgUuH7yUISGv2AAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-09-30 13:25:57
(1 week ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 13:25:13
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.75.229.154 (154.229.75.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.75.229.154 (154.229.75.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 09:25:07.171300 2026] [security2:error] [pid 552:tid 552] [client 34.75.229.154:50586] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.spiritofacorn.com"] [uri "/.htpasswd"] [unique_id "ar0Ns4Z-EwCQwOsnwmnXbwAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 12:55:54
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.75.229.154 (154.229.75.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.75.229.154 (154.229.75.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 08:55:45.175919 2026] [security2:error] [pid 29517:tid 29517] [client 34.75.229.154:51978] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.wisdomwfo.com"] [uri "/.env.dev"] [unique_id "ar0G0X3ur7dlC83bIRb9jAAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
masterguru
2026-09-30 12:50:53
(1 week ago)
BAD BOT - Detected and Blocked.. Matched phrase "GPTBot" at REQUEST_HEADERS:user-agent. (1100000-122 ...
show more
BAD BOT - Detected and Blocked.. Matched phrase "GPTBot" at REQUEST_HEADERS:user-agent. (1100000-122)
show less
Bad Web Bot
๐ฒ๐พ
Rizzy
2026-09-30 12:25:54
(1 week ago)
Multiple WAF Violations
Brute-Force
Web App Attack