๐ฉ๐ช
updown.io
2026-09-16 06:40:05
(4 days ago)
{"level":"info","ts":1789540801.1816025,"logger":"http.log.access.log0","msg":"handled request","req ...
show more
{"level":"info","ts":1789540801.1816025,"logger":"http.log.access.log0","msg":"handled request","request":{"remote_ip":"34.139.176.229","remote_port":"59298","client_ip":"34.139.176.229","proto":"HTTP/2.0","method":"GET","host":"ahda.status.updown.io","uri":"/.gitlab-ci.yml","headers":{"X-Nextjs-Data":["1"],"User-Agent":["Mozilla/5.0 (compatible; Bytespider; [email protected] ) AppleWebKit/537.36"],"Accept":["*/*"],"Cookie":["REDACTED"],"Accept-Encoding":["gzip"],"X-Middleware-Subrequest":["src/middleware:nowaf:src/middleware:src/middleware:src/middleware:src/middleware:middleware:middleware:nowaf:middleware:middleware:middleware:pages/_middleware"]},"tls":{"resumed":false,"version":772,"cipher_suite":4865,"proto":"h2","server_name":"ahda.status.updown.io","ech":false}},"bytes_read":0,"user_id":"","duration":0.000909678,"size":0,"status":429,"resp_headers":{"Server":["Caddy"],"Alt-Svc":["h3=\":443\"; ma=2592000"],"Retry-After":["1"]}}
{"level":"info","ts":1789540801.1829648,
...
show less
DDoS Attack
Web App Attack
๐ฉ๐ช
EGP Abuse Dept
2026-09-16 03:31:42
(4 days ago)
Scanning for web/db/file exploits on agenda.delangewei.nl
SQL Injection
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-09-16 03:14:46
(4 days ago)
[16/Sep/2026:06:14:46 +0300] -- 34.139.176.229 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET ...
show more
[16/Sep/2026:06:14:46 +0300] -- 34.139.176.229 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET /%2e%2e/%2e%2e/%2e%2e/%2e%2e/.env HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
rh24
2026-09-15 18:29:12
(4 days ago)
(badbots) Bad bot user-agent [redacted] from 34.139.176.229 (US/United States/229.176.139.34.bc.goog ...
show more
(badbots) Bad bot user-agent [redacted] from 34.139.176.229 (US/United States/229.176.139.34.bc.googleusercontent.com)
show less
Hacking
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-15 18:05:33
(4 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐ช๐ธ
robotstxt
2026-09-15 17:55:40
(4 days ago)
34.139.176.229 - - [15/Sep/2026:17:55:08 +0000] "GET /wp-content/cache/autoptimize/js/autoptimize_35 ...
show more
34.139.176.229 - - [15/Sep/2026:17:55:08 +0000] "GET /wp-content/cache/autoptimize/js/autoptimize_35defa136bac878503da6272bb32cf5d.js HTTP/2.0" 403 165 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36 Edg/152.0.0.0" "-" edge="34.139.176.229"
34.139.176.229 - - [15/Sep/2026:17:55:08 +0000] "GET /build/manifest.json HTTP/2.0" 403 15500 "https://robotstxt.es/build/manifest.json" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36 Edg/152.0.0.0" "-" edge="34.139.176.229"
34.139.176.229 - - [15/Sep/2026:17:55:08 +0000] "GET /dist/manifest.json HTTP/2.0" 403 15485 "https://robotstxt.es/dist/manifest.json" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36 Edg/152.0.0.0" "-" edge="34.139.176.229"
34.139.176.229 - - [15/Sep/2026:17:55:08 +0000] "GET /.aws/config HTTP/2.0" 403 15928 "https
...
show less
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-09-15 17:43:37
(4 days ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 17:25:39
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.139.176.229 (229.176.139.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.139.176.229 (229.176.139.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 13:25:31.639416 2026] [security2:error] [pid 3456:tid 3456] [client 34.139.176.229:43406] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "menagri.com"] [uri "/@fs/.env"] [unique_id "aql_i0hJn_45efVN7FGmEwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
Olexiy Backend
2026-09-15 17:23:30
(4 days ago)
34.139.176.229
...
Bad Web Bot
Web App Attack
Anonymous
2026-09-15 17:22:56
(4 days ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
๐ณ๐ฑ
Savvii
2026-09-15 16:22:09
(4 days ago)
20 attempts against mh-misbehave-ban on redirect
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-15 16:14:38
(4 days ago)
Aggressive web scan
Web App Attack
๐ช๐ธ
robotstxt
2026-09-15 16:12:43
(4 days ago)
34.139.176.229 - - [15/Sep/2026:16:12:08 +0000] "GET /.env?import&raw HTTP/2.0" 403 33526 "https://c ...
show more
34.139.176.229 - - [15/Sep/2026:16:12:08 +0000] "GET /.env?import&raw HTTP/2.0" 403 33526 "https://ccoo.cat/.env?import&raw" "Mozilla/5.0 (compatible; Qwenbot/1.0; +https://qwen.alibaba.com/)" "34.139.176.229"
34.139.176.229 - - [15/Sep/2026:16:12:08 +0000] "GET /@fs/app/.env?import&raw?? HTTP/2.0" 403 2 "https://ccoo.cat/@fs/app/.env?import&raw??" "Mozilla/5.0 (compatible; MoonshotBot/1.0; +https://kimi.ai/)" "34.139.176.229"
34.139.176.229 - - [15/Sep/2026:16:12:08 +0000] "GET /.env.local?raw HTTP/2.0" 403 33609 "https://ccoo.cat/.env.local?raw" "Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; +https://kimi.ai/)" "34.139.176.229"
34.139.176.229 - - [15/Sep/2026:16:12:09 +0000] "GET /.env.production?raw HTTP/2.0" 403 33547 "https://ccoo.cat/.env.production?raw" "Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; +https://kimi.ai/)" "34.139.176.229"
34.139.176.229 - - [15/Sep/2026:16:12:09 +0000] "GET /@fs/src/.env?import&raw?? HTTP/2.0" 403 2 "https://ccoo.cat/@fs/src/.env?import&raw??" "Mozil
...
show less
Web App Attack
Anonymous
2026-09-15 16:09:48
(4 days ago)
(mod_security) mod_security triggered on hostname [redacted] 34.139.176.229 (US/United States/229.17 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.139.176.229 (US/United States/229.176.139.34.bc.googleusercontent.com)
show less
SQL Injection
๐บ๐ธ
mnsf
2026-09-15 16:05:45
(4 days ago)
Scanning/Probing (13)
Brute-Force
Web App Attack