๐บ๐ธ
snappic
2026-10-11 16:04:20
(2 hours ago)
Scanning for .env files [GET /api/fs/read?allowOutsideWorkspace=true&path=/app/.env] [Mozilla/5.0 (c ...
show more
Scanning for .env files [GET /api/fs/read?allowOutsideWorkspace=true&path=/app/.env] [Mozilla/5.0 (compatible; Meta-ExternalFetcher/1.0; +https://developers.facebook.com/docs/sharing/webmasters/crawler)]
show less
Bad Web Bot
Web App Attack
๐ช๐ธ
robotstxt
2026-10-11 14:46:44
(4 hours ago)
34.80.2.174 - - [11/Oct/2026:14:46:42 +0000] "GET /appearance/../../.env HTTP/1.1" 400 193 "-" "-" " ...
show more
34.80.2.174 - - [11/Oct/2026:14:46:42 +0000] "GET /appearance/../../.env HTTP/1.1" 400 193 "-" "-" "-" edge="34.80.2.174"
34.80.2.174 - - [11/Oct/2026:14:46:42 +0000] "GET /appearance/../../proc/self/environ HTTP/1.1" 400 193 "-" "-" "-" edge="34.80.2.174"
34.80.2.174 - - [11/Oct/2026:14:46:42 +0000] "GET /api/attachments/img/avatar/..%2F..%2F..%2F..%2F..%2Fproc%2Fself%2Fenviron HTTP/1.1" 400 193 "-" "-" "-" edge="34.80.2.174"
34.80.2.174 - - [11/Oct/2026:14:46:42 +0000] "GET /static/../../../a/../../../../.env HTTP/1.1" 400 193 "-" "-" "-" edge="34.80.2.174"
34.80.2.174 - - [11/Oct/2026:14:46:42 +0000] "GET /static/../../../a/../../../../proc/self/environ HTTP/1.1" 400 193 "-" "-" "-" edge="34.80.2.174"
...
show less
Web Spam
Web App Attack
๐ธ๐ฌ
mypatricks
2026-10-11 08:45:42
(10 hours ago)
34.80.2.174 | Port: 13583 | DNS: 174.2.80.34.bc.googleusercontent.com 2026-10-11T16:45:41+08:00 Asia ...
show more
34.80.2.174 | Port: 13583 | DNS: 174.2.80.34.bc.googleusercontent.com 2026-10-11T16:45:41+08:00 Asia/Taipei | Un-authorized bots or crawlers | UA: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; [email protected] ) HTTP/1.1 443 GET | URL: /go025ct8geqxiix67nlo | Ref: - | Country: TW/Taiwan/+08:00 IP City: Taipei a48c970adfb16b86-TPE/Taipei 1 hits/0 secs Robots 1
show less
Brute-Force
Web App Attack
Blog Spam
Web Spam
Exploited Host
๐ธ๐ฌ
simpeg-adm.bandung.go.id
2026-10-11 04:16:56
(14 hours ago)
11/Oct/2026:04:16:55 +0000;34.80.2.174;"/dist/manifest.json"
11/Oct/2026:04:16:55 +0000;34.80.2.174; ...
show more
11/Oct/2026:04:16:55 +0000;34.80.2.174;"/dist/manifest.json"
11/Oct/2026:04:16:55 +0000;34.80.2.174;"/z9x8c7v6b5-debug-trigger-app.peggysaas.com"
11/Oct/2026:04:16:55 +0000;34.80.2.174;"/7edjwr42w8gbviqndrp8"
11/Oct/2026:04:16:55 +0000;34.80.2.174;"/.vite/manifest.json"
11/Oct/2026:04:16:55 +0000;34.80.2.174;"/dist/.vite/manifest.json"
11/Oct/2026:04:16:55 +0000;34.80.2.174;"/vqucb8r8vtcim63jyn3e"
11/Oct/2026:04:16:55 +0000;34.80.2.174;"/js/-B9tpd-J2.js"
...
show less
Web Spam
Brute-Force
Web App Attack
๐บ๐ธ
Shouddy Tarano
2026-10-11 03:27:20
(15 hours ago)
[Sat Oct 10 21:27:18.901074 2026] [authz_core:error] [pid 290036:tid 139792293476096] [client 34.80. ...
show more
[Sat Oct 10 21:27:18.901074 2026] [authz_core:error] [pid 290036:tid 139792293476096] [client 34.80.2.174:44608] AH01630: client denied by server configuration: /var/www/ccmApi/public/
[Sat Oct 10 21:27:18.904469 2026] [authz_core:error] [pid 290036:tid 139792293476096] [client 34.80.2.174:44608] AH01630: client denied by server configuration: /usr/share/httpd/noindex/index.html
[Sat Oct 10 21:27:19.050183 2026] [authz_core:error] [pid 290036:tid 139792377403136] [client 34.80.2.174:44608] AH01630: client denied by server configuration: /var/www/ccmApi/public/dashboard
[Sat Oct 10 21:27:19.361632 2026] [authz_core:error] [pid 262928:tid 139792461330176] [client 34.80.2.174:44638] AH01630: client denied by server configuration: /var/www/ccmApi/public/1yqpm9rz7pzoxkaxfuar
[Sat Oct 10 21:27:19.367364 2026] [authz_core:error] [pid 262928:tid 139791496627968] [client 34.80.2.174:44676] AH01630: client denied by server configuration: /var/www/ccmApi/public/signup
...
show less
DDoS Attack
Web Spam
Brute-Force
Web App Attack
๐ซ๐ท
CaduVet
2026-10-11 03:25:15
(15 hours ago)
2026-10-10 20:44:01,016 fail2ban.actions \[2606\]: NOTICE \[http-overflows\] Ban 34.80.2.174 ...
show more
2026-10-10 20:44:01,016 fail2ban.actions \[2606\]: NOTICE \[http-overflows\] Ban 34.80.2.174
2026-10-11 04:30:36,850 fail2ban.actions \[2606\]: NOTICE \[http-overflows\] Ban 34.80.2.174
2026-10-11 05:25:12,351 fail2ban.actions \[2606\]: NOTICE \[http-overflows\] Ban 34.80.2.174
...
show less
Brute-Force
๐ฉ๐ช
Bedios GmbH
2026-10-11 03:14:11
(15 hours ago)
Login credentials theft attempt
Hacking
๐ณ๐ฑ
Savvii
2026-10-11 02:42:46
(16 hours ago)
20 attempts against mh-misbehave-ban on lunar
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-11 02:07:17
(16 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.80.2.174 (174.2.80.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.80.2.174 (174.2.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 22:07:12.367918 2026] [security2:error] [pid 20670:tid 20670] [client 34.80.2.174:44036] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||spyasociados.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "spyasociados.com"] [uri "/z9x8c7v6b5-debug-trigger-spyasociados.com"] [unique_id "asrvUEGBnxeU12UhkUFh3AAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Apache
2026-10-11 01:58:38
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.80.2.174 (TW/Taiwan/174.2.80.34.bc.googleuse ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.2.174 (TW/Taiwan/174.2.80.34.bc.googleusercontent.com): 5 in the last 300 secs (CF_ENABLE)
show less
Brute-Force
Web App Attack
๐ช๐ธ
robotstxt
2026-10-11 01:56:20
(17 hours ago)
34.80.2.174 - - [11/Oct/2026:01:55:19 +0000] "GET /z9x8c7v6b5-debug-trigger-outcomes10.com HTTP/2.0" ...
show more
34.80.2.174 - - [11/Oct/2026:01:55:19 +0000] "GET /z9x8c7v6b5-debug-trigger-outcomes10.com HTTP/2.0" 403 36699 "https://outcomes10.com/z9x8c7v6b5-debug-trigger-outcomes10.com" "Mozilla/5.0 (compatible; Qwenbot/1.0; +https://qwen.alibaba.com/)" "-" edge="34.80.2.174"
34.80.2.174 - - [11/Oct/2026:01:55:19 +0000] "GET /dist/manifest.json HTTP/2.0" 403 35004 "https://outcomes10.com/dist/manifest.json" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36" "-" edge="34.80.2.174"
34.80.2.174 - - [11/Oct/2026:01:55:19 +0000] "GET /.vite/manifest.json HTTP/2.0" 403 35004 "https://outcomes10.com/.vite/manifest.json" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36" "-" edge="34.80.2.174"
34.80.2.174 - - [11/Oct/2026:01:55:19 +0000] "GET /dist/.vite/manifest.json HTTP/2.0" 403 34982 "https://outcomes10.com/dist/.vite/manifest.json" "Mozilla/5.0 (Windows NT 10.0; Win64; x64)
...
show less
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-10-11 01:51:59
(17 hours ago)
excessive HTTP 404 errors
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-11 01:47:20
(17 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.80.2.174 (174.2.80.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.80.2.174 (174.2.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 21:47:13.735833 2026] [security2:error] [pid 14772:tid 14772] [client 34.80.2.174:53616] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mapleleaf-marketing.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mapleleaf-marketing.com"] [uri "/z9x8c7v6b5-debug-trigger-mapleleaf-marketing.com"] [unique_id "asrqoV9UJqW2ZOVUqVDQOAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
zUnlegit
2026-10-11 01:42:35
(17 hours ago)
Automated web scanner requested sensitive path: /@fs/.env
Web App Attack
๐บ๐ธ
daytonajrw
2026-10-11 01:41:17
(17 hours ago)
Exploit attempts and vulnerability scanning: 192 requests (GETx189, POSTx3) in 14s (parallel), rotat ...
show more
Exploit attempts and vulnerability scanning: 192 requests (GETx189, POSTx3) in 14s (parallel), rotating spoofed crawler User-Agents (Amazonbot, Applebot, Baiduspider, Bytespider), status 200x1, 403x96, 404x95. Exploits attempted: CVE-2025-30208. Also probed: credential/secret files, path traversal, scanner fingerprint paths. Paths incl. /user/login, /@fs/home/ubuntu/.aws/credentials, /@fs/home/ec2-user/.aws/credentials, /@fs/root/.aws/credentials, /@fs/app/.env, /@fs/../.env, /@fs/src/.env, /@fs/..%2f..%2f..%2f..%2f..%2fproc/self/environ
show less
Web App Attack
Bad Web Bot
Hacking