Anonymous
2026-09-23 15:10:14
(1 hour ago)
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: BE, Attack patterns: Back ...
show more
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: BE, Attack patterns: Backup file probing, Cloud secrets probing, Directory traversal
show less
Bad Web Bot
Web App Attack
Anonymous
2026-09-23 11:16:54
(4 hours ago)
34.79.172.254 - - [22/Sep/2026:17:42:15 -0500] "GET /.env HTTP/1.1" 301 252 "-" "Mozilla/5.0 (Macint ...
show more
34.79.172.254 - - [22/Sep/2026:17:42:15 -0500] "GET /.env HTTP/1.1" 301 252 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Safari/605.1.15 (Applebot/0.1)" 172.71.122.194
34.79.172.254 - - [22/Sep/2026:17:42:15 -0500] "GET /.env.local HTTP/1.1" 301 258 "-" "Mozilla/5.0 (compatible; cohere-ai; +https://cohere.com/crawler)" 141.101.95.20
34.79.172.254 - - [22/Sep/2026:17:42:15 -0500] "GET /.env.backup HTTP/1.1" 301 259 "-" "Mozilla/5.0 (compatible; Bravebot/1.0; +https://brave.com/search/)" 172.71.122.195
34.79.172.254 - - [22/Sep/2026:17:42:15 -0500] "GET /.env.bak HTTP/1.1" 301 256 "-" "Mozilla/5.0 (compatible; xAI-Grok/1.0; +https://x.ai/)" 141.101.95.21
34.79.172.254 - - [22/Sep/2026:17:42:15 -0500] "GET /.env.production HTTP/1.1" 301 263 "-" "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)" 172.71.122.194
34.79.172.254 - - [22/Sep/2026:17:42:15 -0500] "GET /.env.example HTTP/1.1" 301 260 "
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ณ
evicky2002
2026-09-23 06:00:01
(10 hours ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐ง๐ช
taivas.nl
2026-09-23 04:33:23
(11 hours ago)
Many_bad_calls
Web App Attack
๐ฒ๐ฝ
octageeks.com
2026-09-23 04:12:58
(11 hours ago)
Wordpress malicious attack:[octablocked]
Web App Attack
๐ฉ๐ช
itsolon
2026-09-23 01:44:35
(14 hours ago)
[23/Sep/2026:03:44:33 +0200] 179012787356.728717 34.79.172.254 40308 217.154.7.177 443
[23/Sep/2026: ...
show more
[23/Sep/2026:03:44:33 +0200] 179012787356.728717 34.79.172.254 40308 217.154.7.177 443
[23/Sep/2026:03:44:33 +0200] 179012787327.300253 34.79.172.254 40308 217.154.7.177 443
[23/Sep/2026:03:44:33 +0200] 179012787399.352927 34.79.172.254 40308 217.154.7.177 443
[23/Sep/2026:03:44:34 +0200] 179012787413.530128 34.79.172.254 40308 217.154.7.177 443
[23/Sep/2026:03:44:34 +0200] 179012787426.599430 34.79.172.254 40308 217.154.7.177 443
...
show less
Port Scan
Hacking
Brute-Force
Web App Attack
Anonymous
2026-09-23 00:20:28
(15 hours ago)
"GET /%2e%2e/.env HTTP/1.1"
Hacking
Web App Attack
๐บ๐ธ
n2nguyenn2nguyen
2026-09-22 23:49:51
(16 hours ago)
Blocked by YFC Security on https://brixzly.com โ type: rapid_scan_attempts
Web App Attack
๐ง๐ช
taivas.nl
2026-09-22 23:02:17
(17 hours ago)
Bad_requests
Bad Web Bot
Anonymous
2026-09-22 20:14:36
(19 hours ago)
malicious scanning tool activity
Web App Attack
Anonymous
2026-09-22 19:49:11
(20 hours ago)
Bot / seems abusive / Apache connections: 20
DDoS Attack
Web Spam
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 18:15:21
(21 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.79.172.254 (254.172.79.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.79.172.254 (254.172.79.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 14:15:13.474513 2026] [security2:error] [pid 26436:tid 26436] [client 34.79.172.254:44362] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||batesstrategygroup.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "batesstrategygroup.com"] [uri "/z9x8c7v6b5-debug-trigger-batesstrategygroup.com"] [unique_id "arLFsai8OekASgi7vbbSgwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 17:47:59
(22 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.79.172.254 (254.172.79.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.79.172.254 (254.172.79.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 13:47:53.299963 2026] [security2:error] [pid 30457:tid 30457] [client 34.79.172.254:45342] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||boxfactorylofts.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "boxfactorylofts.com"] [uri "/z9x8c7v6b5-debug-trigger-boxfactorylofts.com"] [unique_id "arK_SaUNUvUjWTlCUZ0flAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
sc user
2026-09-22 17:26:27
(22 hours ago)
Fail2Ban nginx: repeated suspicious HTTP requests consistent with automated probing, scanning or bad ...
show more
Fail2Ban nginx: repeated suspicious HTTP requests consistent with automated probing, scanning or bad bot behaviour. Technical log details and local server identifiers intentionally omitted for privacy.
show less
Bad Web Bot
Web App Attack
Port Scan
๐ณ๐ฑ
Site.eu
2026-09-22 16:31:57
(23 hours ago)
Excessive 404/403 errors
Brute-Force