๐ท๐ธ
pexodelic
2026-09-21 11:37:52
(9 hours ago)
Automated report from web, SSH and FTP server logs: 938 requests probing for exposed secrets (.env, ...
show more
Automated report from web, SSH and FTP server logs: 938 requests probing for exposed secrets (.env, .git, config files); 397 distinct non-existent paths requested (wordlist scanning); 2738 HTTP 4xx responses. Reported by our automated log scan at 2026-09-21 11:32 UTC; counts cover the current log rotation window.
show less
Hacking
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-21 03:51:24
(16 hours ago)
Excessive 404/403 errors
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-21 02:26:06
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.80.174.160 (160.174.80.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.174.160 (160.174.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 22:26:01.507966 2026] [security2:error] [pid 27815:tid 27815] [client 34.80.174.160:52344] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bernescobar.com"] [uri "/web/.env"] [unique_id "arCVuR7CWSqS0XXPoSRS8gAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 02:01:06
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.80.174.160 (160.174.80.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.174.160 (160.174.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 22:01:02.250235 2026] [security2:error] [pid 22718:tid 22727] [client 34.80.174.160:48264] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "besfixedwireless.exede-sales.com"] [uri "/.git/HEAD"] [unique_id "arCP3vvsD4R7ArMTCrnUnAAAAQc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 23:09:52
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.80.174.160 (160.174.80.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.174.160 (160.174.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 19:09:47.464411 2026] [security2:error] [pid 29088:tid 29088] [client 34.80.174.160:34150] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.bestprostate.com"] [uri "/.env.production"] [unique_id "arBnu1t4UPT5od9ZS4eKbwAAACY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-09-20 23:00:07
(21 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐ฉ๐ช
LRob
2026-09-20 21:56:01
(22 hours ago)
Declared crawler ignoring robots.txt and the refusals it is given | ua: Mozilla/5.0 AppleWebKit/537. ...
show more
Declared crawler ignoring robots.txt and the refusals it is given | ua: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; [email protected] ) (+2 more) | path: /.env.backup (+13 more) | 2026-09-20 21:56 UTC
show less
Bad Web Bot
๐ฉ๐ช
updown.io
2026-09-20 21:27:21
(23 hours ago)
{"level":"info","ts":1789939635.185409,"logger":"http.log.access.log1","msg":"handled request","requ ...
show more
{"level":"info","ts":1789939635.185409,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"34.80.174.160","remote_port":"52314","client_ip":"34.80.174.160","proto":"HTTP/2.0","method":"POST","host":"status.raovat321.com","uri":"/graphql","headers":{"Accept-Encoding":["gzip, deflate, br, zstd"],"User-Agent":["Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36 Edg/153.0.0.0"],"Content-Type":["application/json"],"Sec-Ch-Ua":["\"Chromium\";v=\"153\", \"Microsoft Edge\";v=\"153\", \"Not_A Brand\";v=\"8\""],"Sec-Fetch-Mode":["cors"],"Cookie":["REDACTED"],"Sec-Fetch-Dest":["empty"],"Priority":["u=1, i"],"Sec-Ch-Ua-Platform":["\"Windows\""],"Accept":["*/*"],"Content-Length":["86"],"Sec-Ch-Ua-Mobile":["?0"],"Sec-Fetch-Site":["same-origin"],"Origin":["https://status.raovat321.com"],"Referer":["https://status.raovat321.com"],"Accept-Language":["en-US,en;q=0.9"]},"tls":{"resumed":false,"version":772,"cipher_su
...
show less
DDoS Attack
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 20:23:29
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.80.174.160 (160.174.80.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.174.160 (160.174.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 16:23:22.907280 2026] [security2:error] [pid 11463:tid 11463] [client 34.80.174.160:54502] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mmldesign.com"] [uri "/.env.local"] [unique_id "arBAun8OOnhhdTWHVKaXPgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 20:04:15
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.80.174.160 (160.174.80.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.80.174.160 (160.174.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 16:04:10.836672 2026] [security2:error] [pid 5506:tid 5506] [client 34.80.174.160:34588] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||web.cruisingforsex.com|F|2"] [data ".cruisingforsex.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "web.cruisingforsex.com"] [uri "/z9x8c7v6b5-debug-trigger-web.cruisingforsex.com"] [unique_id "arA8OvYnDF252lRG-PSKkgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-09-20 19:51:32
(1 day ago)
Multiple WAF Violations
Web App Attack