๐บ๐ธ
rsa
2026-09-30 18:21:00
(6 days ago)
GET /settings%2F.env HTTP/2.0
DDoS Attack
Exploited Host
Web App Attack
๐ฉ๐ช
itsolon
2026-09-30 17:02:54
(6 days ago)
[30/Sep/2026:19:02:52 +0200] 179078777278.543361 34.95.199.18 59490 217.154.7.177 443
[30/Sep/2026:1 ...
show more
[30/Sep/2026:19:02:52 +0200] 179078777278.543361 34.95.199.18 59490 217.154.7.177 443
[30/Sep/2026:19:02:52 +0200] 179078777235.245521 34.95.199.18 59490 217.154.7.177 443
[30/Sep/2026:19:02:53 +0200] 179078777366.329277 34.95.199.18 59490 217.154.7.177 443
[30/Sep/2026:19:02:53 +0200] 179078777373.540274 34.95.199.18 59474 217.154.7.177 443
[30/Sep/2026:19:02:53 +0200] 179078777390.078850 34.95.199.18 59490 217.154.7.177 443
...
show less
Port Scan
Hacking
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 16:16:05
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 34.95.199.18 (18.199.95.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.95.199.18 (18.199.95.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 12:16:01.661077 2026] [security2:error] [pid 14685:tid 14685] [client 34.95.199.18:43742] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.sandersonpropertyimprovements.com"] [uri "/@fs/app/.env"] [unique_id "ar01wbL5vXpRHK0YIDdmHQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
factor1
2026-09-30 15:09:46
(6 days ago)
CrowdSec at saturn Reports Abuse
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 15:00:23
(6 days ago)
(mod_security) mod_security (id:210730) triggered by 34.95.199.18 (18.199.95.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.95.199.18 (18.199.95.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 11:00:19.815428 2026] [security2:error] [pid 3142:tid 3142] [client 34.95.199.18:60950] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.sawyerwest.com|F|2"] [data ".sawyerwest.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.sawyerwest.com"] [uri "/z9x8c7v6b5-debug-trigger-www.sawyerwest.com"] [unique_id "ar0kA7n0UcPbIR1ogdTHZwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 14:02:38
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 34.95.199.18 (18.199.95.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.95.199.18 (18.199.95.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 10:02:30.484269 2026] [security2:error] [pid 16003:tid 16003] [client 34.95.199.18:43614] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.needtoorder.com"] [uri "/@fs/proc/self/cwd/.env"] [unique_id "ar0WdjgFhi8ZUGsUNwP9VAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-09-30 14:00:00
(6 days ago)
Web attack/malicious scanning detected
Web App Attack
๐ฉ๐ช
updown.io
2026-09-30 13:49:58
(6 days ago)
{"level":"info","ts":1790776191.9046183,"logger":"http.log.access.log1","msg":"handled request","req ...
show more
{"level":"info","ts":1790776191.9046183,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"34.95.199.18","remote_port":"49354","client_ip":"34.95.199.18","proto":"HTTP/2.0","method":"GET","host":"status.titanarmor.com","uri":"/jbzgpj3b96oa29fk31od","headers":{"X-Nextjs-Data":["1"],"User-Agent":["Mozilla/5.0 (compatible; Bravebot/1.0; +https://brave.com/search/)"],"Accept":["*/*"],"Accept-Encoding":["gzip"],"X-Middleware-Subrequest":["src/middleware:nowaf:src/middleware:src/middleware:src/middleware:src/middleware:middleware:middleware:nowaf:middleware:middleware:middleware:pages/_middleware"]},"tls":{"resumed":false,"version":772,"cipher_suite":4865,"proto":"h2","server_name":"status.titanarmor.com","ech":false}},"bytes_read":0,"user_id":"","duration":0.000454809,"size":0,"status":429,"resp_headers":{"Server":["Caddy"],"Alt-Svc":["h3=\":443\"; ma=2592000"],"Retry-After":["1"]}}
{"level":"info","ts":1790776192.2579126,"logger":"http.log.access.log1","msg":"h
...
show less
DDoS Attack
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 12:51:04
(6 days ago)
(mod_security) mod_security (id:210730) triggered by 34.95.199.18 (18.199.95.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.95.199.18 (18.199.95.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 08:50:56.384868 2026] [security2:error] [pid 2384:tid 2407] [client 34.95.199.18:37822] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||saltflowlogistics.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "saltflowlogistics.com"] [uri "/z9x8c7v6b5-debug-trigger-saltflowlogistics.com"] [unique_id "ar0FsH4ySs98-d2MmCGcWAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-30 12:45:40
(6 days ago)
Automatically blocked after 68 security events. Observed sensitive configuration-file probes. Source ...
show more
Automatically blocked after 68 security events. Observed sensitive configuration-file probes. Source: Cloudflare security controls.
show less
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 12:30:57
(6 days ago)
(mod_security) mod_security (id:210730) triggered by 34.95.199.18 (18.199.95.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.95.199.18 (18.199.95.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 08:30:51.147442 2026] [security2:error] [pid 8819:tid 8819] [client 34.95.199.18:45058] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.savingspools.com|F|2"] [data ".savingspools.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.savingspools.com"] [uri "/z9x8c7v6b5-debug-trigger-www.savingspools.com"] [unique_id "ar0A-1PtAaOj0VFHasIi3wAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 12:08:59
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 34.95.199.18 (18.199.95.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.95.199.18 (18.199.95.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 08:08:51.007286 2026] [security2:error] [pid 22785:tid 22785] [client 34.95.199.18:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.demondomain.com"] [uri "/.env.dev"] [unique_id "arz707xUJIrQhFDzrW3itgAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
rh24
2026-09-30 11:45:52
(6 days ago)
(badbots) Bad bot user-agent [redacted] from 34.95.199.18 (BR/Brazil/18.199.95.34.bc.googleuserconte ...
show more
(badbots) Bad bot user-agent [redacted] from 34.95.199.18 (BR/Brazil/18.199.95.34.bc.googleusercontent.com)
show less
Hacking
๐ฎ๐น
VHosting
2026-09-30 11:30:04
(6 days ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐ฉ๐ช
LRob
2026-09-30 11:26:10
(6 days ago)
Wordlist path sweep | method: GET, POST | path: /model/info, /assets/manifest.json, /nti11zc9dqm9917 ...
show more
Wordlist path sweep | method: GET, POST | path: /model/info, /assets/manifest.json, /nti11zc9dqm99179mnnt (+3 more) | ua: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; GPTBot/1.4; +https://openai.com/gptbot, Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36, Mozilla/5.0 (compatible; DeepSeekBot/1.0; +https://www.deepseek.com/) (+1 more)
show less
Port Scan
Web App Attack