๐ฌ๐ง
consul.to
2026-09-29 08:18:36
(2 days ago)
Web attack/malicious scanning detected
Web App Attack
๐ง๐ฌ
Stoyko Stoykov
2026-09-29 05:38:39
(2 days ago)
34.139.95.142 - - [29/Sep/2026:08:38:38 +0300] "GET /public/.env HTTP/2.0" 404 0 "-" "Mozilla/5.0 (c ...
show more
34.139.95.142 - - [29/Sep/2026:08:38:38 +0300] "GET /public/.env HTTP/2.0" 404 0 "-" "Mozilla/5.0 (compatible; Meta-ExternalAgent/1.0; +https://developers.facebook.com/docs/sharing/webmasters/crawler)"
...
show less
Hacking
Web App Attack
๐ฌ๐ง
consul.to
2026-09-27 19:31:23
(4 days ago)
Web attack/malicious scanning detected
Web App Attack
๐ง๐ฌ
Stoyko Stoykov
2026-09-27 19:07:34
(4 days ago)
34.139.95.142 - - [27/Sep/2026:22:07:34 +0300] "GET /api/w/default/jobs_u/get_log_file/../../../../p ...
show more
34.139.95.142 - - [27/Sep/2026:22:07:34 +0300] "GET /api/w/default/jobs_u/get_log_file/../../../../proc/self/environ HTTP/2.0" 404 0 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; GPTBot/1.4; +https://openai.com/gptbot"
...
show less
Hacking
Web App Attack
๐บ๐ธ
ruusvuu
2026-09-27 18:03:35
(4 days ago)
Automated abuse report: 25 attack/probe requests from Google LLC / US.
Targeted paths: /wp-json, /co ...
show more
Automated abuse report: 25 attack/probe requests from Google LLC / US.
Targeted paths: /wp-json, /config.json, /env.json, /firebase-config.json, /credentials.json.
Sample log lines:
[fyxit] 34.139.95.142 - - [09/27/2026, 11:03:32] "GET /docker-compose.yml HTTP/1.1" 404 3495 referer:"-" ua:"Mozilla/5.0 (compatible; DeepSeekBot/1.0; +https://www.deepseek.com/)"
[fyxit] 34.139.95.142 - - [09/27/2026, 11:03:33] "GET /credentials.js HTTP/1.1" 404 3495 referer:"-" ua:"Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; +claudebot@antโฆ
[fyxit] 34.139.95.142 - - [09/27/2026, 11:03:33] "GET /config.json.js HTTP/1.1" 404 3495 referer:"-" ua:"Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/โฆ
Detected by an automated web-server log monitor.
show less
Web App Attack
Anonymous
2026-09-27 15:44:19
(4 days ago)
Aggressive web scan
Web App Attack
Anonymous
2026-09-26 01:16:42
(6 days ago)
suspicious behavior
Blog Spam
Brute-Force
Web App Attack
๐ฉ๐ช
jbcrn
2026-09-25 19:43:25
(6 days ago)
Blocked by iocaine (nam-shub-of-enki) tarpit. Classified as: Other, ruleset: bad-browser. Requested ...
show more
Blocked by iocaine (nam-shub-of-enki) tarpit. Classified as: Other, ruleset: bad-browser. Requested honeypot path: /. User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36
show less
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2026-09-25 19:39:56
(6 days ago)
147 requests with url.path */@fs/*
Brute-Force
Bad Web Bot
๐ฐ๐ท
ZEROVOX
2026-09-25 19:16:08
(6 days ago)
CrowdSec: crowdsecurity/http-probing detected
Web App Attack
๐ง๐ฌ
Stoyko Stoykov
2026-09-25 18:47:53
(6 days ago)
34.139.95.142 - - [25/Sep/2026:21:47:52 +0300] "GET /config/env/aws_credentials.env HTTP/2.0" 404 0 ...
show more
34.139.95.142 - - [25/Sep/2026:21:47:52 +0300] "GET /config/env/aws_credentials.env HTTP/2.0" 404 0 "-" "Mozilla/5.0 (compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot)"
...
show less
Hacking
Web App Attack
๐บ๐ธ
ruusvuu
2026-09-25 17:42:26
(6 days ago)
Automated abuse report: 25 attack/probe requests from Google LLC / US.
Targeted paths: /wp-json, /co ...
show more
Automated abuse report: 25 attack/probe requests from Google LLC / US.
Targeted paths: /wp-json, /config.json, /env.json, /firebase-config.json.
Sample log lines:
[fyxit] 34.139.95.142 - - [09/25/2026, 10:42:24] "GET /config.json HTTP/1.1" 404 3495 referer:"-" ua:"Mozilla/5.0 (compatible; MoonshotBot/1.0; +https://kimi.ai/)"
[fyxit] 34.139.95.142 - - [09/25/2026, 10:42:25] "GET /env.json HTTP/1.1" 404 3495 referer:"-" ua:"DuckAssistBot/1.1 (https://duckduckgo.com/duckassistbot)"
[fyxit] 34.139.95.142 - - [09/25/2026, 10:42:25] "GET /firebase-config.json HTTP/1.1" 404 3495 referer:"-" ua:"Mozilla/5.0 (compatible; PanguBot/1.0; +https://www.huaweicloud.com/)"
Detected by an automated web-server log monitor.
show less
Web App Attack
๐ฌ๐ง
consul.to
2026-09-25 17:29:36
(6 days ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-25 17:08:04
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 34.139.95.142 (142.95.139.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.139.95.142 (142.95.139.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 25 13:08:00.022946 2026] [security2:error] [pid 24175:tid 24175] [client 34.139.95.142:55238] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dolapdere.click"] [uri "/images../.env"] [unique_id "araqcICLjPij3c0Fnd6ZdgAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-25 15:36:51
(6 days ago)
Excessive 404/403 errors
Brute-Force