๐บ๐ธ
TPI-Abuse
2026-08-29 04:48:40
(33 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.87.112.246 (246.112.87.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.87.112.246 (246.112.87.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 00:48:33.161228 2026] [security2:error] [pid 23461:tid 23461] [client 34.87.112.246:63508] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.darkcodedesign.net"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252fapp/.env"] [unique_id "apJkoUjH-cy-y1MkmPVFlgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
mediarama.com
2026-08-29 04:43:33
(38 minutes ago)
Banned by Fail2Ban
Web App Attack
Anonymous
2026-08-29 04:32:33
(49 minutes ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
๐บ๐ธ
TPI-Abuse
2026-08-29 04:30:00
(52 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.87.112.246 (246.112.87.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.87.112.246 (246.112.87.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 00:29:57.518374 2026] [security2:error] [pid 451993:tid 452007] [client 34.87.112.246:1838] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.ellicottville.net"] [uri "/@fs/root/.env"] [unique_id "apJgRRgo5CbSk_adxSg-4QAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 04:09:23
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.87.112.246 (246.112.87.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.87.112.246 (246.112.87.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 00:09:19.239587 2026] [security2:error] [pid 17340:tid 17340] [client 34.87.112.246:3078] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "keltingnet.scothart.com"] [uri "/@fs/.env.production"] [unique_id "apJbb8DXkuv6dRkBG9pyvQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ฎ
extremevital
2026-08-29 03:35:44
(1 hour ago)
34.87.112.246 [29/Aug/2026:05:35:43 +0200] RATELIMIT: "GET /@fs/app/service-account.json?raw?? HTTP/ ...
show more
34.87.112.246 [29/Aug/2026:05:35:43 +0200] RATELIMIT: "GET /@fs/app/service-account.json?raw?? HTTP/1.1" 401 172 0.000 "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot)"
...
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-08-29 02:58:11
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.87.112.246 (246.112.87.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.87.112.246 (246.112.87.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 22:58:03.494486 2026] [security2:error] [pid 3413:tid 3413] [client 34.87.112.246:10100] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.leahandtone.com"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252fapp/.env"] [unique_id "apJKuxcVgXFwAFCOqeLBpQAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-29 02:34:50
(2 hours ago)
Aggressive web scan
Web App Attack
๐ณ๐ฑ
Site.eu
2026-08-29 02:02:35
(3 hours ago)
Excessive multi-domain requests
Brute-Force
๐ช๐ธ
masterguru
2026-08-29 01:59:11
(3 hours ago)
BAD BOT - Detected and Blocked.. Matched phrase "claudebot" at REQUEST_HEADERS:User-Agent. (1100000- ...
show more
BAD BOT - Detected and Blocked.. Matched phrase "claudebot" at REQUEST_HEADERS:User-Agent. (1100000-122)
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-08-29 01:54:38
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.87.112.246 (246.112.87.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.87.112.246 (246.112.87.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 21:54:34.261407 2026] [security2:error] [pid 27342:tid 27342] [client 34.87.112.246:57844] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.gatheringsattheschool.com"] [uri "/@fs/../.env"] [unique_id "apI72tYB0XrjGZaivfEoOAAAADk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Apache
2026-08-29 01:07:27
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.87.112.246 (SG/Singapore/246.112.87.34.bc.go ...
show more
(mod_security) mod_security (id:210492) triggered by 34.87.112.246 (SG/Singapore/246.112.87.34.bc.googleusercontent.com): 5 in the last 300 secs (CF_ENABLE)
show less
Brute-Force
Web App Attack
๐ฆ๐บ
aranguren.org
2026-08-29 00:57:52
(4 hours ago)
34.87.112.246 - - [29/Aug/2026:10:57:52 +1000] "GET /@fs/.env.staging?raw?? HTTP/1.1" 404 1176 "http ...
show more
34.87.112.246 - - [29/Aug/2026:10:57:52 +1000] "GET /@fs/.env.staging?raw?? HTTP/1.1" 404 1176 "https://zm.aranguren.org/@fs/.env.staging?raw??" "Mozilla/5.0 (compatible; Claude-SearchBot/1.0; +https://www.anthropic.com/claude-searchbot)"
34.87.112.246 - - [29/Aug/2026:10:57:52 +1000] "GET /@fs/..%252f..%252f..%252f..%252f..%252froot/.env?raw?? HTTP/1.1" 404 1260 "https://zm.aranguren.org/@fs/..%252f..%252f..%252f..%252f..%252froot/.env?raw??" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; LinkedInBot/1.0; +http://www.linkedin.com"
34.87.112.246 - - [29/Aug/2026:10:57:52 +1000] "GET /@fs/root/.aws/credentials.backup?raw?? HTTP/1.1" 404 1208 "https://zm.aranguren.org/@fs/root/.aws/credentials.backup?raw??" "Mozilla/5.0 (Windows NT 10.0; rv:128.14) Gecko/20100101 Firefox/128.14; compatible; Applebot/0.1; +http://www.apple.com/go/applebot"
34.87.112.246 - - [29/Aug/2026:10:57:52 +1000] "GET /@fs/proc/self/environ?raw?? HTTP/1.1" 404 1186 "https://zm.aranguren.org/@fs/pro
...
show less
Bad Web Bot
Anonymous
2026-08-29 00:39:11
(4 hours ago)
Bot / seems abusive / Apache connections: 103
DDoS Attack
Web Spam
Bad Web Bot
Web App Attack
๐ฟ๐ฆ
conure.sh
2026-08-29 00:38:49
(4 hours ago)
csagent: score 20.5: secrets grab x2, 404 noise floor x2; 2 domain(s) in 7s
Web App Attack