๐ง๐ช
cmbplf
2026-09-21 19:49:55
(11 minutes ago)
323 requests with url.path */@fs/*
Brute-Force
Bad Web Bot
๐ณ๐ฑ
Savvii
2026-09-21 17:33:02
(2 hours ago)
20 attempts against mh-misbehave-ban on frost
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Savvii
2026-09-21 17:16:14
(2 hours ago)
20 attempts against mh-misbehave-ban on solar
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
robotstxt
2026-09-21 16:31:41
(3 hours ago)
34.138.151.106 - - [21/Sep/2026:16:30:38 +0000] "GET / HTTP/2.0" 403 6530 "-" "Mozilla/5.0 (Windows ...
show more
34.138.151.106 - - [21/Sep/2026:16:30:38 +0000] "GET / HTTP/2.0" 403 6530 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36 Edg/153.0.0.0" "-" edge="34.138.151.106"
34.138.151.106 - - [21/Sep/2026:16:30:38 +0000] "POST / HTTP/2.0" 403 6952 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36; compatible; OAI-SearchBot/1.4; +https://openai.com/searchbot" "-" edge="34.138.151.106"
34.138.151.106 - - [21/Sep/2026:16:30:38 +0000] "GET /.git/config HTTP/2.0" 403 5778 "-" "Mozilla/5.0 (compatible; Meta-ExternalAgent/1.0; +https://developers.facebook.com/docs/sharing/webmasters/crawler)" "-" edge="34.138.151.106"
34.138.151.106 - - [21/Sep/2026:16:30:38 +0000] "GET /.aws/credentials HTTP/2.0" 403 5778 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; GPTBot/1.4; +https://openai.com/gptbot" "-" edge="34.138.151.106"
34.138.151.106 - - [21/S
...
show less
Web App Attack
๐ช๐ธ
elcruzado.es
2026-09-21 16:26:50
(3 hours ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 34.138.151.106 (US/U ...
show more
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 34.138.151.106 (US/United States/106.151.138.34.bc.googleusercontent.com)
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-21 15:30:21
(4 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.138.151.106 (106.151.138.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 34.138.151.106 (106.151.138.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 11:30:17.576735 2026] [security2:error] [pid 6973:tid 7225] [client 34.138.151.106:49410] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.nesso.es|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.nesso.es"] [uri "/rclone.conf"] [unique_id "arFNienGAoDSm12nz2RkPQAAAZg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
Francisco Vallejo
2026-09-21 15:29:29
(4 hours ago)
[Mon Sep 21 17:29:26.298879 2026] [core:info] [pid 3385638:tid 133531590186688] [client 34.138.151.1 ...
show more
[Mon Sep 21 17:29:26.298879 2026] [core:info] [pid 3385638:tid 133531590186688] [client 34.138.151.106:52540] AH00128: File does not exist: /var/www/franvallejo/0ivzpfhavklqou9q5f0u
[Mon Sep 21 17:29:26.666022 2026] [core:info] [pid 3385638:tid 133530919098048] [client 34.138.151.106:52540] AH00128: File does not exist: /var/www/franvallejo/023t8hudfksrl4k6duv9
[Mon Sep 21 17:29:28.244556 2026] [core:info] [pid 3385638:tid 133531724404416] [client 34.138.151.106:52540] AH00128: File does not exist: /var/www/franvallejo/z9x8c7v6b5-debug-trigger-ai.franvallejo.es
[Mon Sep 21 17:29:28.607144 2026] [core:info] [pid 3385638:tid 133530935883456] [client 34.138.151.106:52542] AH00128: File does not exist: /var/www/franvallejo/public../.env
[Mon Sep 21 17:29:28.607202 2026] [core:info] [pid 3385638:tid 133531732797120] [client 34.138.151.106:52540] AH00128: File does not exist: /var/www/franvallejo/rclone.conf
...
show less
Brute-Force
SSH
Anonymous
2026-09-21 15:13:04
(4 hours ago)
Fail2Ban Log Report 34.138.151.106 - - [21/Sep/2026:17:13:01 +0200] "GET /rv2ag7pcuerk29vu826z HTTP/ ...
show more
Fail2Ban Log Report 34.138.151.106 - - [21/Sep/2026:17:13:01 +0200] "GET /rv2ag7pcuerk29vu826z HTTP/2.0" 404 1823 "-" "Mozilla/5.0 (compatible; MistralAI-User/1.0; +https://mistral.ai/)" "34.138.151.106"
34.138.151.106 - [21/Sep/2026:17:13:01 +0200] "GET /rv2ag7pcuerk29vu826z HTTP/2.0" 404 1823 "-" "Mozilla/5.0 (compatible; MistralAI-User/1.0; +https://mistral.ai/)" "2.51" "34.138.151.106"
34.138.151.106 - - [21/Sep/2026:17:13:01 +0200] "GET /id_ecdsa HTTP/2.0" 404 1823 "-" "Mozilla/5.0 (compatible; DeepSeekBot/1.0; +https://www.deepseek.com/)" "34.138.151.106"
34.138.151.106 - - [21/Sep/2026:17:13:01 +0200] "GET /key.pem HTTP/2.0" 404 1823 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" "34.138.151.106"
...
show less
Hacking
Brute-Force
Web App Attack
๐ช๐ธ
netfactotum
2026-09-21 15:08:52
(4 hours ago)
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 15:04:27
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.138.151.106 (106.151.138.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.138.151.106 (106.151.138.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 11:04:22.042287 2026] [security2:error] [pid 21246:tid 21246] [client 34.138.151.106:34624] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.totenclaus.es"] [uri "/assets../.env"] [unique_id "arFHdg3T_mm1zUBDiWbCmQAAACY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Savvii
2026-09-21 14:49:19
(5 hours ago)
20 attempts against mh-misbehave-ban on eris
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-21 14:26:07
(5 hours ago)
Excessive multi-domain requests
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-21 14:07:30
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.138.151.106 (106.151.138.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.138.151.106 (106.151.138.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 10:07:27.029892 2026] [security2:error] [pid 21189:tid 21189] [client 34.138.151.106:33864] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.zeet.es"] [uri "/wp-config.php.bak"] [unique_id "arE6H_ml4veTrPo4sLBeswAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
robotstxt
2026-09-21 14:04:31
(5 hours ago)
34.138.151.106 - - [21/Sep/2026:14:03:48 +0000] "GET / HTTP/2.0" 403 30211 "https://www.paulinas.es/ ...
show more
34.138.151.106 - - [21/Sep/2026:14:03:48 +0000] "GET / HTTP/2.0" 403 30211 "https://www.paulinas.es/" "Mozilla/5.0 (compatible; Google-Extended; +http://www.google.com/bot.html)" "-" edge="34.138.151.106"
34.138.151.106 - - [21/Sep/2026:14:03:48 +0000] "GET /z9x8c7v6b5-debug-trigger-www.paulinas.es HTTP/2.0" 403 27078 "https://www.paulinas.es/z9x8c7v6b5-debug-trigger-www.paulinas.es" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexitybot)" "-" edge="34.138.151.106"
34.138.151.106 - - [21/Sep/2026:14:03:48 +0000] "GET /iy3fz3kwyrrapsf7waw4/ HTTP/2.0" 403 27048 "https://paulinas.es/iy3fz3kwyrrapsf7waw4" "Mozilla/5.0 (compatible; DeepSeekBot/1.0; +https://www.deepseek.com/)" "-" edge="34.138.151.106"
34.138.151.106 - - [21/Sep/2026:14:03:48 +0000] "GET /aghv0bzqwp4wbcrjx6i3/ HTTP/2.0" 403 27045 "https://paulinas.es/aghv0bzqwp4wbcrjx6i3" "Mozilla/5.0 (compatible; YiBot/1.0; +https://01.ai/)" "-" edge="34.138.151.106"
34.138
...
show less
Web App Attack
Anonymous
2026-09-21 14:00:07
(6 hours ago)
| Multiple common web attacks from same source ip. (multiple servers)
Web App Attack
Hacking
SQL Injection