๐ฉ๐ช
Leon A
2026-09-22 09:01:00
(1 week ago)
Brute-Force
Bad Web Bot
Web App Attack
Web Spam
Port Scan
SQL Injection
๐ฉ๐ช
raph
2026-09-22 02:04:09
(1 week ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 23:23:46
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 34.80.180.105 (105.180.80.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.80.180.105 (105.180.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 19:23:42.566353 2026] [security2:error] [pid 24593:tid 24593] [client 34.80.180.105:59278] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||www.ejnes.com|F|2"] [data ".ejnes.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.ejnes.com"] [uri "/z9x8c7v6b5-debug-trigger-www.ejnes.com"] [unique_id "arG8fkoc6Y01inAaOlPm6wAAAEQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-21 22:32:44
(1 week ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐ช๐ธ
robotstxt
2026-09-21 20:24:25
(1 week ago)
34.80.180.105 - - [21/Sep/2026:20:23:23 +0000] "GET /.git/HEAD HTTP/2.0" 403 20 "https://outcomes10. ...
show more
34.80.180.105 - - [21/Sep/2026:20:23:23 +0000] "GET /.git/HEAD HTTP/2.0" 403 20 "https://outcomes10.com/.git/HEAD" "Mozilla/5.0 (compatible; Meta-ExternalAgent/1.0; +https://developers.facebook.com/docs/sharing/webmasters/crawler)" "-" edge="34.80.180.105"
34.80.180.105 - - [21/Sep/2026:20:23:23 +0000] "GET /.git/config HTTP/2.0" 403 36719 "https://outcomes10.com/.git/config" "Mozilla/5.0 (compatible; Bravebot/1.0; +https://brave.com/search/)" "-" edge="34.80.180.105"
34.80.180.105 - - [21/Sep/2026:20:23:23 +0000] "GET / HTTP/2.0" 403 60814 "https://outcomes10.com/" "Mozilla/5.0 (compatible; KimiBot/1.0; +https://kimi.ai/)" "-" edge="34.80.180.105"
34.80.180.105 - - [21/Sep/2026:20:23:23 +0000] "GET /.git-credentials HTTP/2.0" 403 36719 "https://outcomes10.com/.git-credentials" "Mozilla/5.0 (compatible; Hunyuan/1.0; +https://hunyuan.tencent.com/)" "-" edge="34.80.180.105"
34.80.180.105 - - [21/Sep/2026:20:23:23 +0000] "GET /z9x8c7v6b5-debug-trigger-outcomes10.com HTTP/2.0" 403 36719 "h
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 20:16:41
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 34.80.180.105 (105.180.80.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.80.180.105 (105.180.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 16:16:33.424791 2026] [security2:error] [pid 9772:tid 9772] [client 34.80.180.105:44058] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||electric-meat-grinder.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "electric-meat-grinder.com"] [uri "/z9x8c7v6b5-debug-trigger-electric-meat-grinder.com"] [unique_id "arGQoXFeqZRwUt6kpNiPfAAAADc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 18:57:08
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.80.180.105 (105.180.80.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.180.105 (105.180.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 14:57:02.986068 2026] [security2:error] [pid 22692:tid 22692] [client 34.80.180.105:35172] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "elkesmuesli.systemcapacityoptimization.com"] [uri "/server/.env"] [unique_id "arF9_htn2BQp-QfGQnTZaAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-09-21 17:23:43
(1 week ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 17:18:55
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.80.180.105 (105.180.80.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.180.105 (105.180.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 13:18:51.173969 2026] [security2:error] [pid 5208:tid 5208] [client 34.80.180.105:41254] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.electra-shield.com"] [uri "/server/.env"] [unique_id "arFm-4Xwqno9tnLH_cmfjAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
konseptit
2026-09-21 15:39:43
(1 week ago)
(mod_security) mod_security triggered on hostname [redacted] 34.80.180.105 (TW/Taiwan/105.180.80.34. ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.80.180.105 (TW/Taiwan/105.180.80.34.bc.googleusercontent.com)
show less
SQL Injection
๐ฑ๐น
Evag Touf
2026-09-21 15:00:18
(1 week ago)
(mod_security) mod_security triggered on hostname [redacted] 34.80.180.105 (TW/Taiwan/105.180.80.34. ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.80.180.105 (TW/Taiwan/105.180.80.34.bc.googleusercontent.com)
show less
SQL Injection
๐ฉ๐ช
updown.io
2026-09-21 14:47:31
(1 week ago)
{"level":"info","ts":1790002044.4305193,"logger":"http.log.access.log1","msg":"handled request","req ...
show more
{"level":"info","ts":1790002044.4305193,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"34.80.180.105","remote_port":"43396","client_ip":"34.80.180.105","proto":"HTTP/2.0","method":"GET","host":"status.heikomat.com","uri":"/.env.backup","headers":{"X-Nextjs-Data":["1"],"User-Agent":["Mozilla/5.0 (compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot)"],"Accept":["*/*"],"X-Middleware-Subrequest":["src/middleware:nowaf:src/middleware:src/middleware:src/middleware:src/middleware:middleware:middleware:nowaf:middleware:middleware:middleware:pages/_middleware"],"Accept-Encoding":["gzip"]},"tls":{"resumed":false,"version":772,"cipher_suite":4865,"proto":"h2","server_name":"status.heikomat.com","ech":false}},"bytes_read":0,"user_id":"","duration":0.000132222,"size":0,"status":429,"resp_headers":{"Retry-After":["1"],"Server":["Caddy"],"Alt-Svc":["h3=\":443\"; ma=2592000"]}}
{"level":"info","ts":1790002044.4427674,"logger":"http.log.access.log
...
show less
DDoS Attack
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 14:33:39
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.80.180.105 (105.180.80.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.180.105 (105.180.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 10:33:31.707094 2026] [security2:error] [pid 16132:tid 16132] [client 34.80.180.105:44168] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wholesalelivelobsters.com"] [uri "/lib/.env"] [unique_id "arFAO3EQar17FAQ1pJMejQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-21 14:32:03
(1 week ago)
Malicious activity detected
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 13:54:33
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 34.80.180.105 (105.180.80.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.80.180.105 (105.180.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 09:54:29.808592 2026] [security2:error] [pid 15463:tid 15463] [client 34.80.180.105:50884] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.eissenstat.com|F|2"] [data ".eissenstat.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.eissenstat.com"] [uri "/z9x8c7v6b5-debug-trigger-mail.eissenstat.com"] [unique_id "arE3FcP4r01t_lb3q1OLlwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack