๐ฟ๐ฆ
conure.sh
2026-09-21 12:13:25
(1 day ago)
csagent: score 15.2: 404 noise floor x21, secrets grab x1; 1 domain(s) in 5s
Web App Attack
๐ซ๐ท
dynamix
2026-09-20 15:12:45
(2 days ago)
Multiple WAF Violations
Web App Attack
๐ฉ๐ช
bazter.pro
2026-09-20 14:51:06
(2 days ago)
Fail2Ban: apache-ratelimit - 20 failures
Port Scan
Bad Web Bot
Web App Attack
๐ช๐ธ
robotstxt
2026-09-20 14:38:39
(2 days ago)
34.79.130.140 - - [20/Sep/2026:14:38:05 +0000] "GET /@fs/app/.env?raw?? HTTP/2.0" 403 49646 "-" "Moz ...
show more
34.79.130.140 - - [20/Sep/2026:14:38:05 +0000] "GET /@fs/app/.env?raw?? HTTP/2.0" 403 49646 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot" "-"
34.79.130.140 - - [20/Sep/2026:14:38:05 +0000] "GET /.profile HTTP/2.0" 403 49647 "-" "Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; +https://kimi.ai/)" "-"
34.79.130.140 - - [20/Sep/2026:14:38:06 +0000] "GET /@fs/../.env?raw?? HTTP/2.0" 403 49647 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; [email protected] )" "-"
34.79.130.140 - - [20/Sep/2026:14:38:06 +0000] "GET /@fs/src/.env?raw?? HTTP/2.0" 403 49648 "-" "Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; +https://kimi.ai/)" "-"
34.79.130.140 - - [20/Sep/2026:14:38:06 +0000] "GET /@fs/..%252f..%252f..%252f..%252f..%252froot/.env?raw?? HTTP/2.0" 403 49644 "-" "Mozilla/5.0 (compatible; Meta-ExternalAgent/1.0; +https://developers.facebook.com/docs/sharing/webmasters/crawler)" "-"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 14:38:13
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 34.79.130.140 (140.130.79.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.79.130.140 (140.130.79.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 10:38:09.759338 2026] [security2:error] [pid 32330:tid 32330] [client 34.79.130.140:45920] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||economy-cleaners.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "economy-cleaners.com"] [uri "/z9x8c7v6b5-debug-trigger-economy-cleaners.com"] [unique_id "aq_v0aDIxrZYbuRERHSmzAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-09-20 14:35:44
(2 days ago)
HTTP header is restricted by policy (/x-middleware-subrequest/). String match within "/content-encod ...
show more
HTTP header is restricted by policy (/x-middleware-subrequest/). String match within "/content-encoding/ /proxy/ /lock-token/ /content-range/ /if/ /x-http-method-override/ /x-http-method/ /x-method-override/ /x-middleware-subrequest/ /expect/" at TX:header_name_920450_x-middleware-subrequest. (920450-197)
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-20 14:22:43
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.79.130.140 (140.130.79.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.79.130.140 (140.130.79.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 10:22:40.188472 2026] [security2:error] [pid 6977:tid 6997] [client 34.79.130.140:49026] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "eadweb.com"] [uri "/.env_sample"] [unique_id "aq_sMI_oISGLDgzVDGlYYQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฟ๐ฆ
conure.sh
2026-09-20 14:05:43
(2 days ago)
csagent: score 24.8: 404 noise floor x20, secrets grab x1, spoofed crawler UA x1; 1 domain(s) in 6s
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 14:03:54
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 34.79.130.140 (140.130.79.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.79.130.140 (140.130.79.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 10:03:51.154499 2026] [security2:error] [pid 10845:tid 10845] [client 34.79.130.140:45110] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||drxcontent.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "drxcontent.com"] [uri "/z9x8c7v6b5-debug-trigger-drxcontent.com"] [unique_id "aq_nx01s-TsjNrBmJczvDgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 13:36:15
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 34.79.130.140 (140.130.79.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.79.130.140 (140.130.79.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 09:36:10.781288 2026] [security2:error] [pid 19653:tid 19653] [client 34.79.130.140:59584] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||doreenkimura.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "doreenkimura.com"] [uri "/rclone.conf"] [unique_id "aq_hSjkPnoYroXsYmXJgWAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
paulshipley.com.au
2026-09-20 13:17:32
(2 days ago)
[Sun Sep 20 23:17:32.002468 2026] [security2:error] [pid 866486] [client 34.79.130.140:33358] [clien ...
show more
[Sun Sep 20 23:17:32.002468 2026] [security2:error] [pid 866486] [client 34.79.130.140:33358] [client 34.79.130.140] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "dlcarterauthor.com"] [uri "/.profile"] [unique_id "aq_c7OSxC2UOaGwBBTM9pwAAAAo"]
...
show less
Web App Attack
๐ซ๐ท
ELYAZ
2026-09-20 13:15:47
(2 days ago)
(y3) Failed access -byebye- from 34.79.130.140 (BE/Belgium/140.130.79.34.bc.googleusercontent.com): ...
show more
(y3) Failed access -byebye- from 34.79.130.140 (BE/Belgium/140.130.79.34.bc.googleusercontent.com): (CF_ENABLE)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-20 13:07:09
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.79.130.140 (140.130.79.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.79.130.140 (140.130.79.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 09:07:02.594206 2026] [security2:error] [pid 18201:tid 18201] [client 34.79.130.140:35970] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "diselet.com"] [uri "/.env.local"] [unique_id "aq_admKNzkMM6hH5yxpj4gAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
cloudmax
2026-09-20 13:02:27
(2 days ago)
Cloudmax Protect [BOT BLOCK] - Suspicious User-Agent. Possible resource abuse, excessive requests, o ...
show more
Cloudmax Protect [BOT BLOCK] - Suspicious User-Agent. Possible resource abuse, excessive requests, or hacking attempt
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-20 12:46:07
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.79.130.140 (140.130.79.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.79.130.140 (140.130.79.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 08:46:02.270397 2026] [security2:error] [pid 14640:tid 14640] [client 34.79.130.140:44824] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "diarrheawolves.com"] [uri "/@fs/app/.env"] [unique_id "aq_VijO09R8FEi-pKtQvJQAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack