๐ซ๐ฎ
KTSTechnology
2026-10-05 23:19:54
(57 minutes ago)
Web vulnerability scanning detected by our ISP firewall
Web App Attack
Anonymous
2026-10-05 20:20:24
(3 hours ago)
34.91.90.49 - - [05/Oct/2026:15:20:23 -0500] "GET /.env?raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 (comp ...
show more
34.91.90.49 - - [05/Oct/2026:15:20:23 -0500] "GET /.env?raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; MoonshotBot/1.0; +https://kimi.ai/)" 34.91.90.49
34.91.90.49 - - [05/Oct/2026:15:20:23 -0500] "GET /.env?import&raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexitybot)" 34.91.90.49
34.91.90.49 - - [05/Oct/2026:15:20:23 -0500] "GET /.env?import&url&inline HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; ChatGLM-Spider/1.0; +https://zhipuai.cn/)" 34.91.90.49
34.91.90.49 - - [05/Oct/2026:15:20:23 -0500] "GET /.env.local?import&raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; PanguBot/1.0; +https://www.huaweicloud.com/)" 34.91.90.49
34.91.90.49 - - [05/Oct/2026:15:20:23 -0500] "GET /.env.production?import&raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; [email protected] )" 34.91.90.49
34.91.90.49 - - [05/Oct/2026:15:20:23 -0500]
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ฌ
Cloudkul Cloudkul
2026-10-05 10:36:29
(13 hours ago)
Attempted Brute Force on our application
Brute-Force
Web App Attack
๐ง๐ช
boxed-it
2026-10-05 08:14:43
(16 hours ago)
GET /%2eenv (Tarpitted for 16m50s, wasted 59.3kB)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 05:53:15
(18 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.91.90.49 (49.90.91.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.91.90.49 (49.90.91.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 01:53:11.762672 2026] [security2:error] [pid 25629:tid 25629] [client 34.91.90.49:46742] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||windisfun.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "windisfun.com"] [uri "/z9x8c7v6b5-debug-trigger-windisfun.com"] [unique_id "asM7R4A1JjRCjUuI3-ZUTAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
clapper
2026-10-05 05:53:00
(18 hours ago)
(mod_security) mod_security (id:980001) triggered by 34.91.90.49 (49.90.91.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:980001) triggered by 34.91.90.49 (49.90.91.34.bc.googleusercontent.com): 5 in the last 3600 secs; ID: Clar
show less
Brute-Force
Bad Web Bot
๐บ๐ธ
[email protected]
2026-10-05 05:41:28
(18 hours ago)
CrowdSec ban: crowdsecurity/http-crawl-non_statics (duration: 71h59m58s)
Web App Attack
๐ณ๐ฑ
debestelapp
2026-10-05 05:00:09
(19 hours ago)
Web App Attack
๐บ๐ธ
www.nomadomia.com
2026-10-05 03:59:44
(20 hours ago)
Hack attack .env
Port Scan
Hacking
Bad Web Bot
Web App Attack
๐ณ๐ฑ
MyGlobalFlowers
2026-10-05 03:50:57
(20 hours ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
pachec
2026-10-05 03:18:59
(20 hours ago)
Automated vulnerability scanning blocked by fail2ban
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-10-05 03:04:56
(21 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.91.90.49 (49.90.91.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.91.90.49 (49.90.91.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 23:04:49.632909 2026] [security2:error] [pid 2953:tid 2953] [client 34.91.90.49:35804] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||jaglady.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "jaglady.com"] [uri "/z9x8c7v6b5-debug-trigger-jaglady.com"] [unique_id "asMT0dx1KOa_PdzblA1HiQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
itsolon
2026-10-05 03:03:47
(21 hours ago)
[05/Oct/2026:05:03:45 +0200] 179116942571.886379 34.91.90.49 40818 217.154.7.177 443
[05/Oct/2026:05 ...
show more
[05/Oct/2026:05:03:45 +0200] 179116942571.886379 34.91.90.49 40818 217.154.7.177 443
[05/Oct/2026:05:03:45 +0200] 179116942558.654100 34.91.90.49 40818 217.154.7.177 443
[05/Oct/2026:05:03:46 +0200] 179116942693.131319 34.91.90.49 40802 217.154.7.177 443
[05/Oct/2026:05:03:46 +0200] 179116942644.639889 34.91.90.49 40818 217.154.7.177 443
[05/Oct/2026:05:03:46 +0200] 179116942615.615674 34.91.90.49 40802 217.154.7.177 443
...
show less
Port Scan
Hacking
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 02:11:41
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.91.90.49 (49.90.91.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.91.90.49 (49.90.91.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 22:11:34.571152 2026] [security2:error] [pid 14198:tid 14198] [client 34.91.90.49:50660] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dragoldio.com"] [uri "/.htpasswd"] [unique_id "asMHViP83b8zafvaP-k_mwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 01:37:44
(22 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.91.90.49 (49.90.91.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.91.90.49 (49.90.91.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 21:37:39.684460 2026] [security2:error] [pid 22181:tid 22181] [client 34.91.90.49:44932] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||blockdredge.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "blockdredge.com"] [uri "/z9x8c7v6b5-debug-trigger-blockdredge.com"] [unique_id "asL_Y6Kdc6H3WWtbukM9wAAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack