Anonymous
2026-10-11 03:24:19
(2 hours ago)
Aggressive web scan
Web App Attack
๐ฉ๐ช
mravb
2026-10-11 03:16:24
(2 hours ago)
34.80.210.81 - - [11/Oct/2026:06:16:23 +0300] "GET /static//home/user/.env HTTP/2.0" 444 0 "-" "Mozi ...
show more
34.80.210.81 - - [11/Oct/2026:06:16:23 +0300] "GET /static//home/user/.env HTTP/2.0" 444 0 "-" "Mozilla/5.0 (compatible; Qwenbot/1.0; +https://qwen.alibaba.com/)"
...
show less
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-10-11 03:09:27
(2 hours ago)
(mod_security) mod_security (id:210580) triggered by 34.80.210.81 (81.210.80.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210580) triggered by 34.80.210.81 (81.210.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 23:09:19.504744 2026] [security2:error] [pid 6428:tid 6428] [client 34.80.210.81:60408] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "proc/self/environ" at ARGS:apis. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/08_Global_Other.conf"] [line "57"] [id "210580"] [rev "2"] [msg "COMODO WAF: OS File Access Attempt||api.chinookdrivingschoolcalgary.com|F|2"] [data "Matched Data: proc/self/environ found within ARGS:apis: ../../../../../../proc/self/environ"] [severity "CRITICAL"] [tag "CWAF"] [tag "Other"] [hostname "api.chinookdrivingschoolcalgary.com"] [uri "/api/console/api_server"] [unique_id "asr934qOPfZLFPlmZjd-WAAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-11 01:43:16
(3 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.80.210.81 (81.210.80.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.80.210.81 (81.210.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 21:43:08.965414 2026] [security2:error] [pid 29417:tid 29470] [client 34.80.210.81:0] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||raytbrown.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "raytbrown.com"] [uri "/z9x8c7v6b5-debug-trigger-raytbrown.com"] [unique_id "asrprFUrSO5xH_maNbkvWAAAARY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
masterguru
2026-10-11 01:41:42
(3 hours ago)
BAD BOT - Detected and Blocked.. Matched phrase "baidu" at REQUEST_HEADERS:user-agent. (1100000-169)
Bad Web Bot
Anonymous
2026-10-11 01:18:13
(4 hours ago)
(mod_security) mod_security triggered on hostname [redacted])
SQL Injection
๐จ๐ฆ
john doe
2026-10-11 00:28:35
(5 hours ago)
SentinelBot: Env File Hunting (score: 74)
Bad Web Bot
๐บ๐ธ
IndigoRidge
2026-10-11 00:06:19
(5 hours ago)
34.80.210.81 - - [10/Oct/2026:20:06:18 -0400] "GET /@fs/var/task/.env?raw?? HTTP/1.1" 404 5753 "http ...
show more
34.80.210.81 - - [10/Oct/2026:20:06:18 -0400] "GET /@fs/var/task/.env?raw?? HTTP/1.1" 404 5753 "https://clampautosales.com/@fs/var/task/.env?raw??" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot"
34.80.210.81 - - [10/Oct/2026:20:06:18 -0400] "GET /@fs/home/ec2-user/.aws/credentials?raw?? HTTP/1.1" 404 5753 "https://clampautosales.com/@fs/home/ec2-user/.aws/credentials?raw??" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
34.80.210.81 - - [10/Oct/2026:20:06:18 -0400] "GET /@fs/src/.env?import&raw?? HTTP/1.1" 404 5753 "https://clampautosales.com/@fs/src/.env?import&raw??" "Mozilla/5.0 (compatible; DeepSeekBot/1.0; +https://www.deepseek.com/)"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-11 00:04:22
(5 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.80.210.81 (81.210.80.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.80.210.81 (81.210.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 20:04:16.170969 2026] [security2:error] [pid 18148:tid 18148] [client 34.80.210.81:48398] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||claireashtoncounseling.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "claireashtoncounseling.com"] [uri "/z9x8c7v6b5-debug-trigger-claireashtoncounseling.com"] [unique_id "asrSgIDGPmyPVcsxSlGq2wAAAFc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
EmilGH
2026-10-11 00:03:47
(5 hours ago)
34.80.210.81 - - [11/Oct/2026:00:03:43 +0000] "GET /z9x8c7v6b5-debug-trigger-claimtariffrefunds.com ...
show more
34.80.210.81 - - [11/Oct/2026:00:03:43 +0000] "GET /z9x8c7v6b5-debug-trigger-claimtariffrefunds.com HTTP/1.1" 404 38530 "-" "Mozilla/5.0 (compatible; ChatGLM-Spider/1.0; +https://zhipuai.cn/)"
34.80.210.81 - - [11/Oct/2026:00:03:44 +0000] "GET /webpack-stats.json HTTP/1.1" 404 38530 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36"
34.80.210.81 - - [11/Oct/2026:00:03:44 +0000] "GET /h98rc75fwb60xxwly9zc HTTP/1.1" 404 38530 "-" "Mozilla/5.0 (compatible; Meta-WebIndexer/1.0; +https://developers.facebook.com/docs/sharing/webmasters/crawler)"
34.80.210.81 - - [11/Oct/2026:00:03:44 +0000] "GET /assets/manifest.json HTTP/1.1" 404 38530 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36"
34.80.210.81 - - [11/Oct/2026:00:03:44 +0000] "GET /asset-manifest.json HTTP/1.1" 404 38530 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-10 23:29:29
(6 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.80.210.81 (81.210.80.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.80.210.81 (81.210.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 19:29:22.772318 2026] [security2:error] [pid 3292:tid 3292] [client 34.80.210.81:55828] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||circlethreefl.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "circlethreefl.com"] [uri "/z9x8c7v6b5-debug-trigger-circlethreefl.com"] [unique_id "asrKUr50gDSMzouZ8gmuoQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-10 23:07:13
(6 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.80.210.81 (81.210.80.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.80.210.81 (81.210.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 19:07:09.108733 2026] [security2:error] [pid 10805:tid 10805] [client 34.80.210.81:48672] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||cielocr.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "cielocr.com"] [uri "/z9x8c7v6b5-debug-trigger-cielocr.com"] [unique_id "asrFHcJWIs_2zw7p07ljhgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-10 22:48:18
(6 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.80.210.81 (81.210.80.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.80.210.81 (81.210.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 18:48:15.345927 2026] [security2:error] [pid 21096:tid 21096] [client 34.80.210.81:56236] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||chuckbellmusic.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "chuckbellmusic.com"] [uri "/z9x8c7v6b5-debug-trigger-chuckbellmusic.com"] [unique_id "asrAr8Am8eVUPQ52ubOCDwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-10 22:17:55
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.80.210.81 (81.210.80.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.210.81 (81.210.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 18:17:50.427389 2026] [security2:error] [pid 22235:tid 22235] [client 34.80.210.81:60968] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "chrismcc.com"] [uri "/.htpasswd"] [unique_id "asq5jlIqCfwE7H5_J5JXnwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-10-10 21:59:41
(7 hours ago)
Web attack/malicious scanning detected
Web App Attack