๐ฌ๐ง
MrTumnus
2026-10-02 00:49:51
(9 minutes ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐ณ๐ฑ
Josh S.
2026-10-02 00:03:13
(56 minutes ago)
{"level":"info","ts":1790899392.8981593,"logger":"http.log.access.log0","msg":"handled request","req ...
show more
{"level":"info","ts":1790899392.8981593,"logger":"http.log.access.log0","msg":"handled request","request":{"remote_ip":"34.141.202.234","remote_port":"41658","client_ip":"34.141.202.234","proto":"HTTP/2.0","method":"GET","host":"git.joshseveros.cloud","uri":"/.github/workflows/deploy.yml","headers":{"Accept":["*/*"],"X-Middleware-Subrequest":["src/middleware:nowaf:src/middleware:src/middleware:src/middleware:src/middleware:middleware:middleware:nowaf:middleware:middleware:middleware:pages/_middleware"],"X-Nextjs-Data":["1"],"User-Agent":["Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexitybot)"],"Accept-Encoding":["gzip"]},"tls":{"resumed":false,"version":772,"cipher_suite":4865,"proto":"h2","server_name":"git.joshseveros.cloud"}},"bytes_read":0,"user_id":"","duration":0.000846617,"size":11,"status":404,"resp_headers":{"Alt-Svc":["h3=\":443\"; ma=2592000"],"Cache-Control":["max-age=0, private, must-revalidate, no-transfo
...
show less
Web App Attack
๐ง๐ช
cmbplf
2026-10-01 23:39:26
(1 hour ago)
1.562 requests with url.path *.env
467 requests with url.path */@fs/*
167 requests with url.path ...
show more
1.562 requests with url.path *.env
467 requests with url.path */@fs/*
167 requests with url.path */proc/*
117 requests with url.path *credentials.json
105 requests with url.path *.ssh/*
103 requests with url.path *config.json
100 requests with url.path *.aws/*
show less
Brute-Force
Bad Web Bot
๐ณ๐ฑ
Alt255
2026-10-01 22:34:06
(2 hours ago)
[ti-07al] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail apac ...
show more
[ti-07al] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail apache-404. Example: 34.141.202.234 - - [02/Oct/2026:00:34:05 +0200] "GET /webpack-stats.json HTTP/1.1" 404 363 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36"
34.141.202.234 - - [02/Oct/2026:00:34:05 +0200] "GET /asset-manifest.json HTTP/1.1" 404 363 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36"
34.141.202.234 - - [02/Oct/2026:00:34:05 +0200] "GET /dist/manifest.json HTTP/1.1" 404 5686 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36"
34.141.202.234 - - [02/Oct/2026:00:34:05 +0200] "GET /z9x8c7v6b5-debug-trigger-jeremyhelpt.nl H
...
show less
Bad Web Bot
Web App Attack
๐ธ๐ช
vaia.cloud
2026-10-01 22:30:01
(2 hours ago)
crowdsecurity/grafana-cve-2021-43798
Brute-Force
Web App Attack
๐ณ๐ฑ
Savvii
2026-10-01 21:52:23
(3 hours ago)
20 attempts against mh-misbehave-ban on melon
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
kkw
2026-10-01 21:47:49
(3 hours ago)
[REDACTED] 34.141.202.234 - - [01/Oct/2026:23:47:48 +0200] "GET /cache/original/%2e%2e/%2e%2e/.env H ...
show more
[REDACTED] 34.141.202.234 - - [01/Oct/2026:23:47:48 +0200] "GET /cache/original/%2e%2e/%2e%2e/.env HTTP/2.0" 404 343 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Safari/605.1.15 (Applebot/0.1)"
... (mode: searching http-sensitive-files)
show less
Bad Web Bot
Web App Attack
Anonymous
2026-10-01 21:43:43
(3 hours ago)
34.141.202.234 - - [01/Oct/2026:22:43:40 +0100] "POST /cgi-bin/php-cgi.exe?%ADd+allow_url_include%3d ...
show more
34.141.202.234 - - [01/Oct/2026:22:43:40 +0100] "POST /cgi-bin/php-cgi.exe?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input HTTP/1.1" 404 118 "-" "Mozilla/5.0 (compatible; Qwenbot/1.0; +https://qwen.alibaba.com/)"
34.141.202.234 - - [01/Oct/2026:22:43:40 +0100] "POST /cgi-bin/php?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input HTTP/1.1" 404 181 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36; compatible; OAI-SearchBot/1.4; +https://openai.com/searchbot"
34.141.202.234 - - [01/Oct/2026:22:43:40 +0100] "POST /cgi-bin/php-cgi?-d+allow_url_include%3don+-d+auto_prepend_file%3dphp://input HTTP/1.1" 404 118 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot"
34.141.202.234 - - [01/Oct/2026:22:43:41 +0100] "POST /cgi-bin/php?-d+allow_url_include%3don+-d+auto_prepend_file%3dphp://input HTTP/1.1" 404 118 "-" "Mozilla/5.0 AppleWebKit
...
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
ConsulHosting
2026-10-01 21:35:08
(3 hours ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack
๐ซ๐ท
masterguru
2026-10-01 21:01:41
(3 hours ago)
URL file extension is restricted by policy. String match within ".ani/ .asa/ .asax/ .ascx/ .backup/ ...
show more
URL file extension is restricted by policy. String match within ".ani/ .asa/ .asax/ .ascx/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .compositefont/ .config/ .conf/ .crt/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dist/ .dll/ .dos/ .dpkg-dist/ .drv/ .gadget/ .hta/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .inf/ .ini/ .jse/ .key/ .licx/ .lnk/ .log/ .mdb/ .msc/ .ocx/ .old/ .pass/ .pdb/ .pfx/ .pif/ .pem/ .pol/ .prf/ .printer/ .pwd/ .rdb/ .rdp/ .reg/ .resources/ .resx/ .scr/ .sct/ .shs/ .sql/ .swp/ .sys/ .tlb/ .tmp/ .url/ .vb/ .vbe/ .vbs/ .vbproj/ .vsdisco/ .vxd/ .webinfo/ .ws/ .wsc/ .wsf/ .wsh/ .xsd/ .xsx/" at TX:extension. (920440-196)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-10-01 20:27:29
(4 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.141.202.234 (234.202.141.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 34.141.202.234 (234.202.141.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 16:27:21.910219 2026] [security2:error] [pid 18575:tid 18575] [client 34.141.202.234:46352] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||jen-eric.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "jen-eric.com"] [uri "/z9x8c7v6b5-debug-trigger-jen-eric.com"] [unique_id "ar7CKZX2esq4uPJ3pGyUFAAAACo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-10-01 18:46:46
(6 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 18:17:55
(6 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.141.202.234 (234.202.141.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 34.141.202.234 (234.202.141.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 14:17:47.845622 2026] [security2:error] [pid 19579:tid 19579] [client 34.141.202.234:49546] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||jeremy-olson.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "jeremy-olson.com"] [uri "/z9x8c7v6b5-debug-trigger-jeremy-olson.com"] [unique_id "ar6jy4DCAOJVah4f7p5nkAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Charlesiv
2026-10-01 18:01:04
(6 hours ago)
Triggered Cloudflare WAF (firewallCustom) from NL.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Prot ...
show more
Triggered Cloudflare WAF (firewallCustom) from NL.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Protocol: HTTP/2 (GET method)
Endpoint: /phpinfo.php
Timestamp: 2026-10-01T16:21:05Z
Ray ID: a43ccc662fe27638
UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36; compatible; OAI-SearchBot/1.4; +https://openai.com/searchbot
show less
Bad Web Bot
๐ฉ๐ช
sternwart
2026-10-01 17:46:54
(7 hours ago)
Automatisch erkannt: Zugriff auf /@fs/../.env?raw?? (my-coach.ch)
Web App Attack
Bad Web Bot