๐ฉ๐ช
macrob
2026-10-09 09:11:04
(1 hour ago)
2026/10/09 09:11:03 [error] 1534325#1534325: *33064833 access forbidden by rule, client: 34.90.77.24 ...
show more
2026/10/09 09:11:03 [error] 1534325#1534325: *33064833 access forbidden by rule, client: 34.90.77.246, server: wn.binixo.mx, request: "GET /static../.env HTTP/2.0", host: "wn.binixo.mx"
2026/10/09 09:11:03 [error] 1534325#1534325: *33064833 access forbidden by rule, client: 34.90.77.246, server: wn.binixo.mx, request: "GET /media../.env HTTP/2.0", host: "wn.binixo.mx"
2026/10/09 09:11:03 [error] 1534325#1534325: *33064825 access forbidden by rule, client: 34.90.77.246, server: wn.binixo.mx, request: "GET /files../.env HTTP/2.0", host: "wn.binixo.mx"
...
show less
Web App Attack
๐ฉ๐ช
todix
2026-10-09 06:42:30
(4 hours ago)
"GET /@fs/../.env?raw?? HTTP/1.1" 403 6510 "-" "Mozilla/5.0 (compatible; YiBot/1.0; +/)"
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 01:48:27
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.90.77.246 (246.77.90.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.90.77.246 (246.77.90.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 21:48:20.414288 2026] [security2:error] [pid 7833:tid 7833] [client 34.90.77.246:42136] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.ultratecnologia.com.mx"] [uri "/.htpasswd"] [unique_id "ashH5L-SRWv0gcG0fmGD0QAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 01:28:25
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.90.77.246 (246.77.90.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.90.77.246 (246.77.90.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 21:28:18.746606 2026] [security2:error] [pid 29411:tid 29411] [client 34.90.77.246:35758] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.mympizzas.com.mx"] [uri "/.htpasswd"] [unique_id "ashDMiIh6jkxCVuSHWewBgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-09 00:15:16
(10 hours ago)
34.90.77.246 - - [09/Oct/2026:01:15:14 +0100] "POST /cgi-bin/php-cgi.exe?%ADd+allow_url_include%3d1+ ...
show more
34.90.77.246 - - [09/Oct/2026:01:15:14 +0100] "POST /cgi-bin/php-cgi.exe?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input HTTP/1.1" 404 118 "-" "Mozilla/5.0 (compatible; GrokBot/1.0; +https://x.ai/)"
34.90.77.246 - - [09/Oct/2026:01:15:14 +0100] "POST /cgi-bin/php?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input HTTP/1.1" 404 118 "-" "Mozilla/5.0 (compatible; MistralAI-User/1.0; +https://mistral.ai/)"
34.90.77.246 - - [09/Oct/2026:01:15:14 +0100] "POST /cgi-bin/php-cgi?-d+allow_url_include%3don+-d+auto_prepend_file%3dphp://input HTTP/1.1" 404 118 "-" "Mozilla/5.0 (compatible; KimiBot/1.0; +https://kimi.ai/)"
34.90.77.246 - - [09/Oct/2026:01:15:14 +0100] "POST /cgi-bin/php?-d+allow_url_include%3don+-d+auto_prepend_file%3dphp://input HTTP/1.1" 404 118 "-" "Mozilla/5.0 (compatible; MoonshotBot/1.0; +https://kimi.ai/)"
...
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
updown.io
2026-10-09 00:00:33
(10 hours ago)
{"level":"info","ts":1791504028.7619865,"logger":"http.log.access.log1","msg":"handled request","req ...
show more
{"level":"info","ts":1791504028.7619865,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"34.90.77.246","remote_port":"34722","client_ip":"34.90.77.246","proto":"HTTP/2.0","method":"GET","host":"info.ecolana.com.mx","uri":"/static/manifest.json","headers":{"Sec-Fetch-User":["?1"],"Sec-Fetch-Mode":["navigate"],"Sec-Fetch-Site":["none"],"Sec-Fetch-Dest":["document"],"Sec-Ch-Ua-Mobile":["?0"],"X-Middleware-Subrequest":["src/middleware:nowaf:src/middleware:src/middleware:src/middleware:src/middleware:middleware:middleware:nowaf:middleware:middleware:middleware:pages/_middleware"],"Priority":["u=0, i"],"Accept":["text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8"],"User-Agent":["Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36"],"Cookie":["REDACTED"],"X-Nextjs-Data":["1"],"Sec-Ch-Ua-Platform":["\"Linux\""],"Upgrade-Insecure-Requests":["1"],"Sec-Ch-Ua":["\"Chromium\";v=\"153
...
show less
DDoS Attack
Web App Attack
๐บ๐ธ
Vano Ganzzz
2026-10-08 22:58:53
(11 hours ago)
Triggered Cloudflare WAF (firewallCustom) from NL.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Prot ...
show more
Triggered Cloudflare WAF (firewallCustom) from NL.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Protocol: HTTP/2 (GET method)
Endpoint: /userfiles/x
Timestamp: 2026-10-08T22:58:53Z
Ray ID: a478c0bb28fa7aa7
UA: Mozilla/5.0 (compatible; ChatGLM-Spider/1.0; +https://zhipuai.cn/)
show less
Bad Web Bot
๐ซ๐ท
SpaceHost-Server
2026-10-08 22:22:03
(12 hours ago)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 21:57:10
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.90.77.246 (246.77.90.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.90.77.246 (246.77.90.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 17:57:03.823002 2026] [security2:error] [pid 3720:tid 3720] [client 34.90.77.246:36624] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.slc.com.gt"] [uri "/.htpasswd"] [unique_id "asgRr_05D0o-pgVr9GrtlwAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 20:30:26
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.90.77.246 (246.77.90.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.90.77.246 (246.77.90.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 16:30:21.881345 2026] [security2:error] [pid 25533:tid 25533] [client 34.90.77.246:47050] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.tritec.com.gt"] [uri "/.env.js"] [unique_id "asf9XfpXnpDOJ4ZtQ5dTyQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-10-08 19:36:16
(15 hours ago)
Excessive multi-domain requests
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-10-08 19:21:22
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.90.77.246 (246.77.90.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.90.77.246 (246.77.90.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 15:21:17.711247 2026] [security2:error] [pid 4860:tid 4860] [client 34.90.77.246:36658] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "trucksystems.com.mx"] [uri "/.htpasswd"] [unique_id "asftLbCHo91KGPIPjiyPcQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-08 19:12:41
(15 hours ago)
34.90.77.246 - - [08/Oct/2026:14:12:38 -0500] "GET /.env?import&url&inline HTTP/1.1" 403 199 "-" "Mo ...
show more
34.90.77.246 - - [08/Oct/2026:14:12:38 -0500] "GET /.env?import&url&inline HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; Qwenbot/1.0; +https://qwen.alibaba.com/)" 141.101.69.83
34.90.77.246 - - [08/Oct/2026:14:12:39 -0500] "GET /.env?raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; PanguBot/1.0; +https://www.huaweicloud.com/)" 141.101.69.84
34.90.77.246 - - [08/Oct/2026:14:12:39 -0500] "GET /.env?import&raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)" 141.101.68.251
34.90.77.246 - - [08/Oct/2026:14:12:39 -0500] "GET /.env.local?raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Safari/605.1.15 (Applebot/0.1)" 141.101.69.83
34.90.77.246 - - [08/Oct/2026:14:12:39 -0500] "GET /.env.development?raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; Bravebot/1.0; +https://brave.com/search/)" 141.101.69.84
34.90.77.246 - - [08/Oct/2026:14:12:39 -0500]
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 18:44:22
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.90.77.246 (246.77.90.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.90.77.246 (246.77.90.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 14:44:14.132906 2026] [security2:error] [pid 18186:tid 18186] [client 34.90.77.246:48436] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "radiofamilia.com.mx"] [uri "/media../.env"] [unique_id "asfkfvyM07J0PxT9nfPJ4wAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-10-08 18:43:06
(16 hours ago)
Excessive 404/403 errors
Brute-Force