🇭🇺
NyaljBe
2026-08-13 07:05:00
(4 weeks ago)
34.124.135.93 - - [07/Aug/2026:19:37:19 +0200] "GET /login HTTP/1.1" 404 555 "-" "Mozilla/5.0 (Linux ...
show more
34.124.135.93 - - [07/Aug/2026:19:37:19 +0200] "GET /login HTTP/1.1" 404 555 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Mobile Safari/537.36"
34.124.135.93 - - [07/Aug/2026:19:37:19 +0200] "POST /graphql HTTP/1.1" 404 555 "https://rdn.hu" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Mobile Safari/537.36"
34.124.135.93 - - [07/Aug/2026:19:37:19 +0200] "GET /rclone.conf HTTP/1.1" 404 153 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; GPTBot/1.3; +https://openai.com/gptbot)"
34.124.135.93 - - [07/Aug/2026:19:37:19 +0200] "GET /webpack-stats.json HTTP/1.1" 404 555 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Mobile Safari/537.36"
34.124.135.93 - - [07/Aug/2026:19:37:19 +0200] "GET /static/manifest.json HTTP/1.1" 404 555 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Mobile Safari/537
show less
Web App Attack
🇭🇺
DumaNet
2026-08-08 20:23:00
(1 month ago)
Web app attack attempts, scanning for vulnerability.
Date: 2026 Aug 07. 19:18:31
Source IP: 34.124 ...
show more
Web app attack attempts, scanning for vulnerability.
Date: 2026 Aug 07. 19:18:31
Source IP: 34.124.135.93
Portion of the log(s):
34.124.135.93 - [07/Aug/2026:19:18:31 +0200] "GET /api/.env HTTP/1.1" 404 153 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; GPTBot/1.3; +https://openai.com/gptbot)"
34.124.135.93 - [07/Aug/2026:19:18:31 +0200] "GET /.env.local HTTP/1.1" 404 153 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; GPTBot/1.3; +https://openai.com/gptbot)"
34.124.135.93 - [07/Aug/2026:19:18:31 +0200] "GET /.env.old HTTP/1.1" 404 153 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; GPTBot/1.3; +https://openai.com/gptbot)"
34.124.135.93 - [07/Aug/2026:19:18:31 +0200] "GET /.env.backup HTTP/1.1" 404 153 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; GPTBot/1.3; +https://openai.com/gptbot)"
34.124.135.93 - [07/Aug/2026:19:18:31 +0200] "GET /.env.example HTTP/1.1" 404 153 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like
show less
Web App Attack
🇭🇺
DumaNet
2026-08-08 19:30:00
(1 month ago)
Web app attack attempts, scanning for vulnerability.
Date: 2026 Aug 07. 17:43:33
Source IP: 34.124 ...
show more
Web app attack attempts, scanning for vulnerability.
Date: 2026 Aug 07. 17:43:33
Source IP: 34.124.135.93
Portion of the log(s):
34.124.135.93 - [07/Aug/2026:17:43:33 +0200] "GET /.svn/entries HTTP/1.1" 404 153 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; GPTBot/1.3; +https://openai.com/gptbot)"
34.124.135.93 - [07/Aug/2026:17:43:33 +0200] "GET /terraform.tfstate HTTP/1.1" 404 153 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; GPTBot/1.3; +https://openai.com/gptbot)"
34.124.135.93 - [07/Aug/2026:17:43:33 +0200] "GET /.htpasswd HTTP/1.1" 404 153 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; GPTBot/1.3; +https://openai.com/gptbot)"
34.124.135.93 - [07/Aug/2026:17:43:33 +0200] "GET /docker-compose.yaml HTTP/1.1" 404 153 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; GPTBot/1.3; +https://openai.com/gptbot)"
34.124.135.93 - [07/Aug/2026:17:43:33 +0200] "GET /.boto HTTP/1.1" 404 153 "-" "Mozilla/5.0 AppleWebKit/537
show less
Web App Attack
🇩🇪
klaus_ph
2026-08-08 11:34:20
(1 month ago)
...
Bad Web Bot
🇭🇺
szasa
2026-08-08 04:19:37
(1 month ago)
2026/08/08 06:19:36 [error] 1363129#1363129: *2723261 access forbidden by rule, client: 34.124.135.9 ...
show more
2026/08/08 06:19:36 [error] 1363129#1363129: *2723261 access forbidden by rule, client: 34.124.135.93, server: datamentor.hu, request: "GET /.git/HEAD HTTP/2.0", host: "datamentor.hu"
...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-08-08 03:48:15
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 34.124.135.93 (93.135.124.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.124.135.93 (93.135.124.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 07 23:48:08.822497 2026] [security2:error] [pid 29593:tid 29593] [client 34.124.135.93:53680] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ypsisda.net|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ypsisda.net"] [uri "/rclone.conf"] [unique_id "anam-LpxvHnI5Zg0KJZDBQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇪
voormedia
2026-08-08 03:16:45
(1 month ago)
Accessed trap at '/.aws/credentials'
Web App Attack
🇭🇺
szasa
2026-08-08 02:48:15
(1 month ago)
2026/08/08 04:48:14 [error] 1363129#1363129: *2721672 access forbidden by rule, client: 34.124.135.9 ...
show more
2026/08/08 04:48:14 [error] 1363129#1363129: *2721672 access forbidden by rule, client: 34.124.135.93, server: datamentor.hu, request: "GET /.git/config HTTP/2.0", host: "www.beszerzokozpont.hu"
2026/08/08 04:48:14 [error] 1363129#1363129: *2721672 access forbidden by rule, client: 34.124.135.93, server: datamentor.hu, request: "GET /.git/HEAD HTTP/2.0", host: "www.beszerzokozpont.hu"
...
show less
Web App Attack
🇺🇸
slay3r9903
2026-08-08 01:55:16
(1 month ago)
IP address blocked by Cloudflare security rules due to suspicious activity and security violations.
Hacking
Bad Web Bot
🇳🇱
i-turnradio.nl
2026-08-08 01:17:41
(1 month ago)
2026-08-08 @ 03:17:40 (CET) ~ Blocked for trying to access: /.aws/config
Web App Attack
🇧🇪
cmbplf
2026-08-08 01:09:46
(1 month ago)
3.356 requests from abuseipdb.com blacklisted IP (3mos3w1d)
Brute-Force
Bad Web Bot
🇫🇮
oh.mg
2026-08-08 00:57:18
(1 month ago)
34.124.135.93 - - [08/Aug/2026:02:57:18 +0200] "GET /.aws/config HTTP/1.1" 403 499 "-" "Mozilla/5.0 ...
show more
34.124.135.93 - - [08/Aug/2026:02:57:18 +0200] "GET /.aws/config HTTP/1.1" 403 499 "-" "Mozilla/5.0 (compatible; Applebot/0.1; +http://www.apple.com/go/applebot)"
34.124.135.93 - - [08/Aug/2026:02:57:18 +0200] "GET /.git/config HTTP/1.1" 403 499 "-" "Mozilla/5.0 (compatible; Applebot/0.1; +http://www.apple.com/go/applebot)"
34.124.135.93 - - [08/Aug/2026:02:57:18 +0200] "GET /.aws/credentials HTTP/1.1" 403 2176 "-" "Mozilla/5.0 (compatible; Applebot/0.1; +http://www.apple.com/go/applebot)"
34.124.135.93 - - [08/Aug/2026:02:57:18 +0200] "GET /rclone.conf HTTP/1.1" 403 2176 "-" "Mozilla/5.0 (compatible; Applebot/0.1; +http://www.apple.com/go/applebot)"
34.124.135.93 - - [08/Aug/2026:02:57:18 +0200] "GET /.git/HEAD HTTP/1.1" 403 2176 "-" "Mozilla/5.0 (compatible; Applebot/0.1; +http://www.apple.com/go/applebot)"
...
show less
Bad Web Bot
Web App Attack
🇳🇱
i-turnradio.nl
2026-08-08 00:52:00
(1 month ago)
2026-08-08 @ 02:51:59 (CET) ~ Blocked for trying to access: /.aws/credentials
Web App Attack
🇺🇸
TPI-Abuse
2026-08-08 00:33:54
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 34.124.135.93 (93.135.124.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.124.135.93 (93.135.124.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 07 20:33:49.954316 2026] [security2:error] [pid 4160795:tid 4160795] [client 34.124.135.93:50904] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.xn--lyngr-yua.net"] [uri "/.git/config"] [unique_id "anZ5bcDy6b46HAoPEi0LsQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇸🇪
vaia.cloud
2026-08-08 00:10:01
(1 month ago)
crowdsecurity/http-admin-interface-probing
Brute-Force
Web App Attack