๐ซ๐ท
GoodOldTOS
2026-08-24 03:56:00
(4 hours ago)
Highly suspect IP
Hacking
Web App Attack
๐ซ๐ท
hghosting
2026-08-23 17:53:20
(14 hours ago)
CrowdSec auto-report: crowdsecurity/http-admin-interface-probing โ 3 events
Brute-Force
SSH
๐ฉ๐ช
Zydzy
2026-08-23 16:31:17
(15 hours ago)
Automated attack detected. Server: 95.140.154.181. Jail: nginx-scanner.
Web App Attack
๐ฉ๐ช
updown.io
2026-08-23 11:21:08
(20 hours ago)
{"level":"info","ts":1787484065.771116,"logger":"http.log.access.log1","msg":"handled request","requ ...
show more
{"level":"info","ts":1787484065.771116,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"34.138.207.192","remote_port":"40178","client_ip":"34.138.207.192","proto":"HTTP/2.0","method":"GET","host":"status.hypercode.de","uri":"/manifest.json","headers":{"Upgrade-Insecure-Requests":["1"],"Sec-Ch-Ua-Platform":["\"Windows\""],"Accept-Encoding":["gzip, deflate, br, zstd"],"Priority":["u=0, i"],"Sec-Fetch-Dest":["document"],"Sec-Ch-Ua-Mobile":["?0"],"Sec-Fetch-User":["?1"],"Accept":["text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8"],"Sec-Fetch-Mode":["navigate"],"Sec-Fetch-Site":["none"],"User-Agent":["Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/148.0.0.0 Safari/537.36 Edg/148.0.0.0"],"Sec-Ch-Ua":["\"Microsoft Edge\";v=\"148\", \"Not/A)Brand\";v=\"99\", \"Chromium\";v=\"148\""],"Accept-Language":["en-US,en;q=0.9"]},"tls":{"resumed":false,"version":772,"cipher_suite":4865,"proto":"h
...
show less
DDoS Attack
Web App Attack
๐ซ๐ท
hghosting
2026-08-23 09:37:02
(22 hours ago)
CrowdSec auto-report: crowdsecurity/http-probing โ 11 events
Brute-Force
SSH
Anonymous
2026-08-21 17:43:15
(2 days ago)
34.138.207.192 - - [21/Aug/2026:19:43:11 +0200] "GET /assets/manifest.json HTTP/2.0" 404 287
34.138. ...
show more
34.138.207.192 - - [21/Aug/2026:19:43:11 +0200] "GET /assets/manifest.json HTTP/2.0" 404 287
34.138.207.192 - - [21/Aug/2026:19:43:11 +0200] "GET /signin HTTP/2.0" 404 329
34.138.207.192 - - [21/Aug/2026:19:43:11 +0200] "GET /z9x8c7v6b5-debug-trigger-static.veracash.com HTTP/2.0" 404 265
34.138.207.192 - - [21/Aug/2026:19:43:11 +0200] "GET /manage HTTP/2.0" 404 265
34.138.207.192 - - [21/Aug/2026:19:43:11 +0200] "GET /auth/login HTTP/2.0" 404 265
34.138.207.192 - - [21/Aug/2026:19:43:11 +0200] "GET /api/settings HTTP/2.0" 404 265
34.138.207.192 - - [21/Aug/2026:19:43:11 +0200] "GET /admin/login HTTP/2.0" 404 265
34.138.207.192 - - [21/Aug/2026:19:43:11 +0200] "GET /admin HTTP/2.0" 404 329
34.138.207.192 - - [21/Aug/2026:19:43:11 +0200] "GET /login HTTP/2.0" 404 265
34.138.207.192 - - [21/Aug/2026:19:43:11 +0200] "GET /dashboard HTTP/2.0" 404 265
34.138.207.192 - - [21/Aug/2026:19:43:12 +0200] "POST /graphql HTTP/2.0" 404 288
34.138.207.192 - - [21/Aug/2026:19:43:12 +0200] "GET /__/fire
...
show less
Web Spam
Web App Attack
๐ฌ๐ท
setupgr
2026-08-21 16:39:55
(2 days ago)
(mod_security) mod_security (id:990005) triggered by 34.138.207.192 (US/United States/South Carolina ...
show more
(mod_security) mod_security (id:990005) triggered by 34.138.207.192 (US/United States/South Carolina/North Charleston/-/[AS396982 GOOGLE-CLOUD-PLATFORM]): 1 in the last 86400 secs (CF_ENABLE); Ports: *; Direction: inout; Trigger: LF_MODSEC; Logs: [Fri Aug 21 19:39:51.481990 2026] [security2:error] [pid 219472:tid 219564] [remote 34.138.207.192:60566] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "gptbot" at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec/modsec2.user.conf"] [line "159"] [id "990005"] [msg "Blocked AI Scraper from Google Cloud Platform"] [hostname "mail.setworldup365.com"] [uri "/service_account.json"] [unique_id "aoh_V0zwl-fY36M--43UNAABFRU"]
show less
Port Scan
๐น๐ญ
thaizone.com
2026-08-21 16:11:10
(2 days ago)
Hacking attempts against websites (D1) #1
Web App Attack
Hacking
Anonymous
2026-08-21 13:15:09
(2 days ago)
34.138.207.192 - - [21/Aug/2026:15:15:06 +0200] "GET /z9x8c7v6b5-debug-trigger-static.veracash.com H ...
show more
34.138.207.192 - - [21/Aug/2026:15:15:06 +0200] "GET /z9x8c7v6b5-debug-trigger-static.veracash.com HTTP/2.0" 404 287
34.138.207.192 - - [21/Aug/2026:15:15:06 +0200] "GET /login HTTP/2.0" 404 329
34.138.207.192 - - [21/Aug/2026:15:15:06 +0200] "GET /auth/login HTTP/2.0" 404 329
34.138.207.192 - - [21/Aug/2026:15:15:06 +0200] "GET /signin HTTP/2.0" 404 329
34.138.207.192 - - [21/Aug/2026:15:15:06 +0200] "GET /assets/manifest.json HTTP/2.0" 404 329
34.138.207.192 - - [21/Aug/2026:15:15:06 +0200] "GET /admin/login HTTP/2.0" 404 329
34.138.207.192 - - [21/Aug/2026:15:15:06 +0200] "GET /admin HTTP/2.0" 404 329
34.138.207.192 - - [21/Aug/2026:15:15:06 +0200] "POST /graphql HTTP/2.0" 404 265
34.138.207.192 - - [21/Aug/2026:15:15:06 +0200] "GET /console HTTP/2.0" 404 265
34.138.207.192 - - [21/Aug/2026:15:15:06 +0200] "GET /portal HTTP/2.0" 404 265
34.138.207.192 - - [21/Aug/2026:15:15:06 +0200] "GET /manage HTTP/2.0" 404 265
34.138.207.192 - - [21/Aug/2026:15:15:06 +0200] "GET /account HTTP/2.
...
show less
Web Spam
Web App Attack
๐ฉ๐ช
maxpower
2026-08-21 12:50:25
(2 days ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 34.138.207.192 (US/United States/192.207 ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 34.138.207.192 (US/United States/192.207.138.34.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 34.138.207.192 - - [21/Aug/2026:14:50:20 +0200] "GET /.aws/credentials HTTP/2.0" 429 41 "-" "Mozilla/5.0 (compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot)" "-" host=www.spacehosting.ovh
show less
Port Scan
๐น๐ท
pashait
2026-08-21 11:57:55
(2 days ago)
Auto-blocked by Seczar SecureOps โ IPS Web Attack Signature (3 events in 5min) at 2026-08-21 11:57
Web App Attack
Bad Web Bot
๐ฑ๐น
Evag Touf
2026-08-21 11:21:38
(2 days ago)
(mod_security) mod_security triggered on hostname [redacted] 34.138.207.192 (US/United States/192.20 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.138.207.192 (US/United States/192.207.138.34.bc.googleusercontent.com)
show less
SQL Injection
๐บ๐ธ
KayCee
2026-08-21 10:49:40
(2 days ago)
34.138.207.192 - - [21/Aug/2026:06:49:39 -0400] "GET /rclone.conf HTTP/2.0" 404 1649 "-" "Mozilla/5. ...
show more
34.138.207.192 - - [21/Aug/2026:06:49:39 -0400] "GET /rclone.conf HTTP/2.0" 404 1649 "-" "Mozilla/5.0 (compatible; Amzn-SearchBot/1.0; +https://developer.amazon.com/support/amazonbot)" "-"
34.138.207.192 - - [21/Aug/2026:06:49:39 -0400] "GET /dashboard HTTP/2.0" 404 1649 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36" "-"
34.138.207.192 - - [21/Aug/2026:06:49:39 -0400] "GET /signin HTTP/2.0" 404 1649 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36" "-"
34.138.207.192 - - [21/Aug/2026:06:49:39 -0400] "GET /console HTTP/2.0" 404 1649 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36" "-"
34.138.207.192 - - [21/Aug/2026:06:49:39 -0400] "GET /manage HTTP/2.0" 404 1649 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36" "-"
...
show less
Web App Attack
๐ฉ๐ช
LRob
2026-08-21 10:34:59
(2 days ago)
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: ...
show more
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: /asset-manifest.json (+1 more)
show less
Hacking
Web App Attack
๐ฌ๐ง
consul.to
2026-08-21 09:13:18
(2 days ago)
Web attack/malicious scanning detected
Web App Attack