๐ซ๐ฎ
oh.mg
2026-08-18 18:56:06
(6 days ago)
34.142.229.96 - - [18/Aug/2026:20:56:03 +0200] "GET /sw.js HTTP/1.1" 403 2462 "-" "Mozilla/5.0 Apple ...
show more
34.142.229.96 - - [18/Aug/2026:20:56:03 +0200] "GET /sw.js HTTP/1.1" 403 2462 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot"
34.142.229.96 - - [18/Aug/2026:20:56:03 +0200] "GET /public/env.js HTTP/1.1" 403 2462 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot"
34.142.229.96 - - [18/Aug/2026:20:56:04 +0200] "GET /env.js HTTP/1.1" 403 543 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot"
34.142.229.96 - - [18/Aug/2026:20:56:04 +0200] "GET /service-worker.js HTTP/1.1" 403 543 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot"
34.142.229.96 - - [18/Aug/2026:20:56:05 +0200] "GET /.well-known/jwks.json HTTP/1.1" 403 2462 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot"
...
show less
Bad Web Bot
Web App Attack
Anonymous
2026-08-18 18:01:10
(6 days ago)
2026-08-16 10:50:58,922 fail2ban.actions [626]: NOTICE [apache-noscript] Ban 34.142.229.96
2 ...
show more
2026-08-16 10:50:58,922 fail2ban.actions [626]: NOTICE [apache-noscript] Ban 34.142.229.96
2026-08-18 20:01:09,591 fail2ban.actions [626]: NOTICE [apache-noscript] Ban 34.142.229.96
...
show less
Brute-Force
๐ฎ๐น
VHosting
2026-08-18 16:45:04
(6 days ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐ฎ๐น
ciccio diddo
2026-08-18 15:36:17
(6 days ago)
High Burst multiple 40X port:Tcp/80,443
Brute-Force
Web App Attack
๐ณ๐ฟ
realstuffie
2026-08-17 10:09:06
(1 week ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐ง๐พ
lns.bz
2026-08-17 09:30:48
(1 week ago)
.env scanning [BY]
Web App Attack
Anonymous
2026-08-17 09:06:50
(1 week ago)
34.142.229.96 - - [17/Aug/2026:11:06:48 +0200] "GET /pi.php HTTP/2.0" 429 162 "-" "Mozilla/5.0 (comp ...
show more
34.142.229.96 - - [17/Aug/2026:11:06:48 +0200] "GET /pi.php HTTP/2.0" 429 162 "-" "Mozilla/5.0 (compatible; Diffbot/1.0; +https://diffbot.com)" "-" "X"
34.142.229.96 - - [17/Aug/2026:11:06:48 +0200] "GET /test.php HTTP/2.0" 429 162 "-" "Mozilla/5.0 (compatible; Diffbot/1.0; +https://diffbot.com)" "-" "X"
34.142.229.96 - - [17/Aug/2026:11:06:49 +0200] "GET /i.php HTTP/2.0" 429 162 "-" "Mozilla/5.0 (compatible; Diffbot/1.0; +https://diffbot.com)" "-" "X"
34.142.229.96 - - [17/Aug/2026:11:06:49 +0200] "GET /info.php HTTP/2.0" 429 162 "-" "Mozilla/5.0 (compatible; Diffbot/1.0; +https://diffbot.com)" "-" "X"
34.142.229.96 - - [17/Aug/2026:11:06:49 +0200] "GET /phpinfo.php HTTP/2.0" 429 162 "-" "Mozilla/5.0 (compatible; Diffbot/1.0; +https://diffbot.com)" "-" "X"
34.142.229.96 - - [17/Aug/2026:11:06:49 +0200] "GET /app_dev.php HTTP/2.0" 429 162 "-" "Mozilla/5.0 (compatible; Diffbot/1.0; +https://diffbot.com)" "-" "X"
show less
Brute-Force
๐จ๐ฆ
alexbfr
2026-08-17 07:38:15
(1 week ago)
Fail2Ban report from nginx-bot-trap; automated HTTP honeypot detection.
Web App Attack
๐ณ๐ฑ
Site.eu
2026-08-16 22:34:28
(1 week ago)
Excessive multi-domain requests
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-08-16 22:13:06
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.142.229.96 (96.229.142.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.142.229.96 (96.229.142.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 18:13:02.664875 2026] [security2:error] [pid 25726:tid 25726] [client 34.142.229.96:50674] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kentweakley.com"] [uri "/.git/config"] [unique_id "aoI17pp48--zCr7eN4otegAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
paissangroup
2026-08-16 21:43:59
(1 week ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-16 20:47:00
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 34.142.229.96 (96.229.142.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.142.229.96 (96.229.142.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 16:46:52.545291 2026] [security2:error] [pid 8980:tid 8980] [client 34.142.229.96:54098] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||marcedinc.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "marcedinc.com"] [uri "/rclone.conf"] [unique_id "aoIhvNGrSDSOAD5JVO5lEAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-08-16 20:44:43
(1 week ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
Major Hostility
2026-08-16 19:39:04
(1 week ago)
"GET /api/v1/settings HTTP/1.1" 404
"GET /config.js HTTP/1.1" 404
"GET /static/manifest.json HTTP/1. ...
show more
"GET /api/v1/settings HTTP/1.1" 404
"GET /config.js HTTP/1.1" 404
"GET /static/manifest.json HTTP/1.1" 404
"GET /asset-manifest.json HTTP/1.1" 404
"GET /z9x8c7v6b5-debug-trigger-mx.[DOMAIN].com HTTP/1.1" 404
"GET /assets/manifest.json HTTP/1.1" 404
"GET /api/settings HTTP/1.1" 404
"GET /__/firebase/init.json HTTP/1.1" 404
"GET /api/config HTTP/1.1" 404
"GET /webpack-stats.json HTTP/1.1" 404
"GET /dist/manifest.json HTTP/1.1" 404
"GET /manifest.json HTTP/1.1" 404
"GET /user/login HTTP/1.1" 404
"GET /console HTTP/1.1" 404
"GET /manage HTTP/1.1" 404
"GET /portal HTTP/1.1" 404
"POST /graphql HTTP/1.1" 404
"GET /login HTTP/1.1" 404
"GET /my HTTP/1.1" 404
"GET /si
show less
Web App Attack
๐ฉ๐ช
0x44
2026-08-16 19:05:54
(1 week ago)
Abusive host detected - Attempt to access sensitive files
Web App Attack
Hacking