๐บ๐ธ
TPI-Abuse
2026-10-02 12:37:51
(39 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.81.218.9 (9.218.81.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.81.218.9 (9.218.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 08:37:46.044224 2026] [security2:error] [pid 27482:tid 27484] [client 34.81.218.9:39772] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.n2play.net"] [uri "/.env.js"] [unique_id "ar-lmsHYHRnCX8oT87TGTAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฏ๐ต
bokumin.org
2026-10-02 12:33:01
(44 minutes ago)
[id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [uri "/"] [id "949110"] [msg " ...
show more
[id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [uri "/"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"]
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 12:06:24
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.81.218.9 (9.218.81.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.81.218.9 (9.218.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 08:06:17.939277 2026] [security2:error] [pid 15896:tid 15896] [client 34.81.218.9:46308] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "network22.net"] [uri "/media../.env"] [unique_id "ar-eOUsYRubCOf5p2iP9FQAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
yitzhaq
2026-10-02 10:09:54
(3 hours ago)
34.81.218.9 - - [02/Oct/2026:12:09:52 +0200] "GET /wp-config.php.old HTTP/2.0" 403 297 "-" "Mozilla/ ...
show more
34.81.218.9 - - [02/Oct/2026:12:09:52 +0200] "GET /wp-config.php.old HTTP/2.0" 403 297 "-" "Mozilla/5.0 (compatible; YouBot/1.0; +https://you.com/bot)"
34.81.218.9 - - [02/Oct/2026:12:09:52 +0200] "GET /.aws/config HTTP/2.0" 404 43270 "-" "Mozilla/5.0 (compatible; YiBot/1.0; +https://01.ai/)"
34.81.218.9 - - [02/Oct/2026:12:09:52 +0200] "GET /.env.save HTTP/2.0" 404 43270 "-" "Mozilla/5.0 (compatible; Hunyuan/1.0; +https://hunyuan.tencent.com/)"
34.81.218.9 - - [02/Oct/2026:12:09:52 +0200] "GET /.env.prod HTTP/2.0" 404 43270 "-" "Mozilla/5.0 (compatible; Hunyuan/1.0; +https://hunyuan.tencent.com/)"
34.81.218.9 - - [02/Oct/2026:12:09:52 +0200] "GET /api/.env HTTP/2.0" 404 43270 "-" "CCBot/2.0 (https://commoncrawl.org/faq/)"
34.81.218.9 - - [02/Oct/2026:12:09:52 +0200] "GET /.zshrc HTTP/2.0" 404 43270 "-" "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)"
34.81.218.9 - - [02/Oct/2026:12:09:52 +0200] "GET /admin/.env HTTP/2.0" 403 297 "-" "Mozilla/5.0 Ap
show less
Web App Attack
Brute-Force
๐บ๐ธ
dot.mg
2026-10-02 09:32:02
(3 hours ago)
Bad behaviour
Web Spam
Anonymous
2026-10-02 09:03:09
(4 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
๐ฌ๐ง
adnscom.net
2026-10-02 08:47:31
(4 hours ago)
IPS trigger: Brute force WebApp/CMS scanning/attack
Brute-Force
Web App Attack
๐บ๐ธ
slay3r9903
2026-10-02 08:07:26
(5 hours ago)
IP address blocked by Cloudflare security rules due to suspicious activity and security violations.
Hacking
Bad Web Bot
๐ฉ๐ช
s@ch@
2026-10-02 08:00:02
(5 hours ago)
Jail: plesk-modsecurity | Web application attack (Plesk ModSecurity)
Web App Attack
๐ฉ๐ช
raph
2026-10-02 07:23:46
(5 hours ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 07:02:01
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.81.218.9 (9.218.81.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.81.218.9 (9.218.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 03:01:55.169320 2026] [security2:error] [pid 21082:tid 21082] [client 34.81.218.9:47348] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nigunensemble.net"] [uri "/uploads../.env"] [unique_id "ar9W43Hly_oI3je9eGKWpwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 06:33:52
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.81.218.9 (9.218.81.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.81.218.9 (9.218.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 02:33:47.152126 2026] [security2:error] [pid 21959:tid 21959] [client 34.81.218.9:49010] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "terazon.net"] [uri "/files../.env"] [unique_id "ar9QSyLbozNKs7e4uD_teQAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
updown.io
2026-10-02 06:28:58
(6 hours ago)
{"level":"info","ts":1790922532.3768668,"logger":"http.log.access.log1","msg":"handled request","req ...
show more
{"level":"info","ts":1790922532.3768668,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"34.81.218.9","remote_port":"58880","client_ip":"34.81.218.9","proto":"HTTP/2.0","method":"GET","host":"status.yhkang.net","uri":"/__/firebase/init.json","headers":{"X-Nextjs-Data":["1"],"User-Agent":["Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36; compatible; OAI-SearchBot/1.4; +https://openai.com/searchbot"],"Accept":["*/*"],"Cookie":["REDACTED"],"Accept-Encoding":["gzip"],"X-Middleware-Subrequest":["src/middleware:nowaf:src/middleware:src/middleware:src/middleware:src/middleware:middleware:middleware:nowaf:middleware:middleware:middleware:pages/_middleware"]},"tls":{"resumed":false,"version":772,"cipher_suite":4865,"proto":"h2","server_name":"status.yhkang.net","ech":false}},"bytes_read":0,"user_id":"","duration":0.000381578,"size":0,"status":429,"resp_headers":{"Server":["Caddy"],"Alt-Svc":["h3
...
show less
DDoS Attack
Web App Attack
๐ฉ๐ช
zumbo.net
2026-10-02 05:38:46
(7 hours ago)
[Fri Oct 02 08:38:44.521844 2026] [proxy_fcgi:error] [pid 213039:tid 213055] [client 34.81.218.9:0] ...
show more
[Fri Oct 02 08:38:44.521844 2026] [proxy_fcgi:error] [pid 213039:tid 213055] [client 34.81.218.9:0] AH01071: Got error 'Primary script unknown'
[Fri Oct 02 08:38:44.953871 2026] [proxy_fcgi:error] [pid 213278:tid 213288] [client 34.81.218.9:0] AH01071: Got error 'Primary script unknown'
[Fri Oct 02 08:38:44.961225 2026] [proxy_fcgi:error] [pid 213039:tid 213064] [client 34.81.218.9:0] AH01071: Got error 'Primary script unknown'
[Fri Oct 02 08:38:45.409992 2026] [proxy_fcgi:error] [pid 213278:tid 213291] [client 34.81.218.9:0] AH01071: Got error 'Primary script unknown'
[Fri Oct 02 08:38:45.623728 2026] [proxy_fcgi:error] [pid 213039:tid 213047] [client 34.81.218.9:0] AH01071: Got error 'Primary script unknown'
...
show less
Brute-Force
Web App Attack
๐ซ๐ท
dynamix
2026-10-02 05:11:03
(8 hours ago)
Multiple WAF Violations
Web App Attack