๐ฉ๐ช
klaus_ph
2026-09-23 11:01:30
(14 hours ago)
2026-09-22 23:26:42,062 fail2ban.actions [535885]: NOTICE [ipblocklist] Ban 34.78.183.247
.. ...
show more
2026-09-22 23:26:42,062 fail2ban.actions [535885]: NOTICE [ipblocklist] Ban 34.78.183.247
...
show less
Bad Web Bot
๐บ๐ธ
julianalee.com
2026-09-22 18:04:00
(1 day ago)
21/Sep/26 18:22:44 #3618294 CRITICAL 520 34.78.183.247 GET /__vite_rsc_findSourceMapURL?file ...
show more
21/Sep/26 18:22:44 #3618294 CRITICAL 520 34.78.183.247 GET /__vite_rsc_findSourceMapURL?filename=file:///root/.ssh/id_rsa&environmentName=rsc - Data URI scheme or PHP wrappers - [GET:filename = file:///root/.ssh/id_rsa] - mail.pacifica-ca-real-estate-and-homes.com
21/Sep/26 18:22:45 #4431432 CRITICAL 3 34.78.183.247 GET /index.php?s=index/\think\app/invokefunction&function=call_user_func_array&vars[0]=file_get_contents&vars[1][]=/proc/self/environ - Local file inclusion - [GET:vars = file_get_contents /proc/self/environ] - mail.pacifica-ca-real-estate-and-homes.com
21/Sep/26 18:22:45 #7586220 CRITICAL 1 34.78.183.247 GET /api/console/api_server?sense_version=%40%40SENSE_VERSION&apis=../../../../../../proc/self/environ - Directory traversal #1 - [GET:apis = ../../../../../../proc/self/environ] - mail.pacifica-ca-real-estate-and-homes.com
show less
Hacking
๐ฎ๐ณ
evicky2002
2026-09-22 06:00:01
(1 day ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-09-22 01:13:51
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.78.183.247 (247.183.78.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.78.183.247 (247.183.78.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 21:13:47.429776 2026] [security2:error] [pid 25702:tid 25741] [client 34.78.183.247:38942] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "davidtung.com"] [uri "/cmd/.env"] [unique_id "arHWS2tZDWa1TqsgK4EuTQAAAMc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
dbmwebdesign
2026-09-22 01:05:36
(2 days ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
๐บ๐ธ
peaceharbor
2026-09-22 00:40:08
(2 days ago)
Swatter: score=90 intel=abuseipdb:confidence30(30) rule=critical_badpath recidivism=4/30d crit-singl ...
show more
Swatter: score=90 intel=abuseipdb:confidence30(30) rule=critical_badpath recidivism=4/30d crit-single
show less
Web App Attack
Port Scan
๐บ๐ธ
TPI-Abuse
2026-09-22 00:30:55
(2 days ago)
(mod_security) mod_security (id:949110) triggered by 34.78.183.247 (247.183.78.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:949110) triggered by 34.78.183.247 (247.183.78.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 20:30:49.589022 2026] [security2:error] [pid 13973:tid 13973] [client 34.78.183.247:51826] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "mail.armstrongenvironmental.com"] [uri "/.env_1"] [unique_id "arHMObbFd26lGsFOnNAubAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Baking333
2026-09-22 00:30:14
(2 days ago)
[redacted] 34.78.183.247 - - [22/Sep/2026:01:30:12 +0100] "GET /@fs/app/.env?raw?? HTTP/2.0" 307 114 ...
show more
[redacted] 34.78.183.247 - - [22/Sep/2026:01:30:12 +0100] "GET /@fs/app/.env?raw?? HTTP/2.0" 307 114 "-" "Mozilla/5.0 (compatible; Bravebot/1.0; +https://[redacted]/search/)" [redacted] 34.78.183.247 - - [22/Sep/2026:01:30:13 +0100] "GET /@fs/src/.env?raw?? HTTP/2.0" 307 64 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perplexity-User/1.0; +https://[redacted]/perplexitybot)"
show less
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-09-22 00:06:45
(2 days ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 22:31:44
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.78.183.247 (247.183.78.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.78.183.247 (247.183.78.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 18:31:35.505140 2026] [security2:error] [pid 30051:tid 30051] [client 34.78.183.247:45494] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.davefortier.com"] [uri "/@fs/app/.env"] [unique_id "arGwR4ajMKlIe5OP1003rgAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฏ๐ต
Tom Tamagawa
2026-09-21 22:20:00
(2 days ago)
Probing for vulnerabilities.
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 20:16:32
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.78.183.247 (247.183.78.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.78.183.247 (247.183.78.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 16:16:27.484630 2026] [security2:error] [pid 24222:tid 24222] [client 34.78.183.247:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.sportsbookcommission.com"] [uri "/.git/HEAD"] [unique_id "arGQm2mS8nxx5deHM7QnMgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
chronos
2026-09-21 19:59:54
(2 days ago)
[AUTORAVALT][[21/09/2026 - 16:59:54 -03:00 UTC]
Attack from [Google LLC]
[34.78.183.247][247.183.78. ...
show more
[AUTORAVALT][[21/09/2026 - 16:59:54 -03:00 UTC]
Attack from [Google LLC]
[34.78.183.247][247.183.78.34.bc.googleusercontent.com]
Action: BLocKed
Hacking... Unauthorized attempts to access the server.
Web App Attack -> Attempts to probe for or exploit installed web applications such as a CMS like WordPress/Drupal, e-commerce solutions, forum software, phpMyAdm]
...
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 19:41:25
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.78.183.247 (247.183.78.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.78.183.247 (247.183.78.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 15:41:18.965053 2026] [security2:error] [pid 11830:tid 11830] [client 34.78.183.247:57798] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.davehalverson.com"] [uri "/.git/HEAD"] [unique_id "arGIXvFD1hCJl6QLfUIuKAAAACs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Mundo Bueno
2026-09-21 18:34:12
(2 days ago)
[ISILIA Protection v2.3] Tentative d'accรจs: /.env.local [RATE LIMITED - 1800s quarantine] | Pays: BE ...
show more
[ISILIA Protection v2.3] Tentative d'accรจs: /.env.local [RATE LIMITED - 1800s quarantine] | Pays: BE | UA: Mozilla/5.0 (compatible; YouBot/1.0; +https://you.com/bot)
show less
Hacking
Web App Attack