๐ณ๐ฑ
SchorelWeb
2026-09-30 03:32:40
(2 days ago)
Cluster member (Omitted) (US/United States/-) said, TEMPDENY 34.118.161.58, Reason:[(Suspicious) Sus ...
show more
Cluster member (Omitted) (US/United States/-) said, TEMPDENY 34.118.161.58, Reason:[(Suspicious) Suspicious activity detected 34.118.161.58 (CA/Canada/58.161.118.34.bc.googleusercontent.com): 10 in the last 3600 secs]
show less
Brute-Force
SSH
๐บ๐ธ
dot.mg
2026-09-30 02:47:01
(2 days ago)
Bad behaviour
Web Spam
๐บ๐ธ
TPI-Abuse
2026-09-30 02:25:35
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 34.118.161.58 (58.161.118.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.118.161.58 (58.161.118.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 22:25:29.327603 2026] [security2:error] [pid 22897:tid 22897] [client 34.118.161.58:32908] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||cgi-city.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "cgi-city.com"] [uri "/z9x8c7v6b5-debug-trigger-cgi-city.com"] [unique_id "arxzGfiXY36deVIMbHhXHAAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
ipoac.nl
2026-09-30 01:10:40
(2 days ago)
ipoac.nl:443 34.118.161.58 - - [30/Sep/2026:03:10:39 +0200] ipoac.nl "GET /.gitlab-ci.yml HTTP/2.0" ...
show more
ipoac.nl:443 34.118.161.58 - - [30/Sep/2026:03:10:39 +0200] ipoac.nl "GET /.gitlab-ci.yml HTTP/2.0" 404 2305 "-" "Mozilla/5.0 (compatible; DeepSeekBot/1.0; +https://www.deepseek.com/)"
show less
Bad Web Bot
๐ณ๐ฑ
Roderic
2026-09-30 00:24:40
(2 days ago)
(apache-scanners) Failed apache-scanners trigger with match [redacted])
Port Scan
๐ณ๐ฑ
Site.eu
2026-09-29 23:37:57
(2 days ago)
Excessive multi-domain requests
Brute-Force
๐ฟ๐ฆ
vanderhost
2026-09-29 23:28:00
(2 days ago)
[Laravel HoneypotPlus] Automated report - Honeypot access detected on path: /config/gcp-credentials. ...
show more
[Laravel HoneypotPlus] Automated report - Honeypot access detected on path: /config/gcp-credentials.json via rule: /config
show less
Web App Attack
Bad Web Bot
๐ฎ๐ฉ
Burayot
2026-09-29 23:02:42
(2 days ago)
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 34.118.161.58 (CA/Canada/58.161.118. ...
show more
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 34.118.161.58 (CA/Canada/58.161.118.34.bc.googleusercontent.com): 2 in the last 3600 secs
show less
Web App Attack
Anonymous
2026-09-29 22:30:51
(2 days ago)
34.118.161.58 detected on srv01
Brute-Force
๐ช๐ธ
robotstxt
2026-09-29 22:03:08
(2 days ago)
34.118.161.58 - - [29/Sep/2026:22:03:05 +0000] "GET /..%2f..%2f.env HTTP/1.1" 400 193 "-" "-" "-" ed ...
show more
34.118.161.58 - - [29/Sep/2026:22:03:05 +0000] "GET /..%2f..%2f.env HTTP/1.1" 400 193 "-" "-" "-" edge="34.118.161.58"
34.118.161.58 - - [29/Sep/2026:22:03:05 +0000] "GET /icons/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/proc/self/environ HTTP/1.1" 400 193 "-" "-" "-" edge="34.118.161.58"
34.118.161.58 - - [29/Sep/2026:22:03:05 +0000] "GET /icons/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/proc/self/environ HTTP/1.1" 400 193 "-" "-" "-" edge="34.118.161.58"
34.118.161.58 - - [29/Sep/2026:22:03:06 +0000] "GET /api/uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2fproc/self/environ HTTP/1.1" 400 193 "-" "-" "-" edge="34.118.161.58"
34.118.161.58 - - [29/Sep/2026:22:03:06 +0000] "GET /api/uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2fproc/self/environ HTTP/1.1" 400 193 "-" "-" "-" edge="34.118.161.58"
...
show less
Web Spam
Web App Attack
๐ณ๐ฑ
Savvii
2026-09-29 22:01:52
(2 days ago)
20 attempts against mh-misbehave-ban on nobletest
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
aranguren.org
2026-09-29 21:15:56
(2 days ago)
34.118.161.58 - - [30/Sep/2026:07:15:38 +1000] "GET /.git/config HTTP/2.0" 301 281 "-" "Mozilla/5.0 ...
show more
34.118.161.58 - - [30/Sep/2026:07:15:38 +1000] "GET /.git/config HTTP/2.0" 301 281 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Safari/605.1.15 (Applebot/0.1)"
34.118.161.58 - - [30/Sep/2026:07:15:55 +1000] "POST /cgi-bin/php-cgi.exe?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input HTTP/2.0" 301 353 "-" "Mozilla/5.0 (compatible; MistralAI-User/1.0; +https://mistral.ai/)"
34.118.161.58 - - [30/Sep/2026:07:15:56 +1000] "POST /cgi-bin/php?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input HTTP/2.0" 301 345 "-" "Mozilla/5.0 (compatible; Bravebot/1.0; +https://brave.com/search/)"
...
show less
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-29 21:14:35
(2 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
Anonymous
2026-09-29 21:06:40
(2 days ago)
[da.kdns.gr] httpd-config-scan: sites=www.monitor.kdns.gr; logs=/var/log/httpd/domains/monitor.kdns. ...
show more
[da.kdns.gr] httpd-config-scan: sites=www.monitor.kdns.gr; logs=/var/log/httpd/domains/monitor.kdns.gr.log; samples=/docker/.env | /.env.save | /api/.env
show less
Hacking
Web App Attack
๐ช๐ธ
robotstxt
2026-09-29 20:55:50
(2 days ago)
34.118.161.58 - - [29/Sep/2026:20:30:02 +0000] "POST /cgi-bin/php-cgi.exe?%ADd+allow_url_include%3d1 ...
show more
34.118.161.58 - - [29/Sep/2026:20:30:02 +0000] "POST /cgi-bin/php-cgi.exe?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input HTTP/1.1" 404 189 "-" "Mozilla/5.0 (compatible; Google-Extended; +http://www.google.com/bot.html)" "-" edge="34.118.161.58"
34.118.161.58 - - [29/Sep/2026:20:30:02 +0000] "POST /cgi-bin/php?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input HTTP/1.1" 404 189 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; [email protected] )" "-" edge="34.118.161.58"
34.118.161.58 - - [29/Sep/2026:20:30:02 +0000] "POST /cgi-bin/php-cgi?-d+allow_url_include%3don+-d+auto_prepend_file%3dphp://input HTTP/1.1" 404 189 "-" "Mozilla/5.0 (compatible; MistralAI-User/1.0; +https://mistral.ai/)" "-" edge="34.118.161.58"
34.118.161.58 - - [29/Sep/2026:20:30:02 +0000] "POST /cgi-bin/php?-d+allow_url_include%3don+-d+auto_prepend_file%3dphp://input HTTP/1.1" 404 210 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKi
...
show less
Bad Web Bot