๐ฉ๐ช
klaus_ph
2026-09-23 13:16:52
(1 day ago)
2026-09-23 00:35:05,548 fail2ban.actions [535885]: NOTICE [ipblocklist] Ban 34.143.210.212
. ...
show more
2026-09-23 00:35:05,548 fail2ban.actions [535885]: NOTICE [ipblocklist] Ban 34.143.210.212
...
show less
Bad Web Bot
๐ฎ๐ณ
evicky2002
2026-09-22 06:00:01
(2 days ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐ช๐ธ
el-brujo
2026-09-22 00:56:55
(2 days ago)
34.143.210.212 - - [22/Sep/2026:02:56:55 +0200] "GET /__/firebase/init.json HTTP/2.0" 404 15875 "-" ...
show more
34.143.210.212 - - [22/Sep/2026:02:56:55 +0200] "GET /__/firebase/init.json HTTP/2.0" 404 15875 "-" "Mozilla/5.0 (compatible; DeepSeekBot/1.0; +https://www.deepseek.com/)"
34.143.210.212 - - [22/Sep/2026:02:56:55 +0200] "GET /api/v1/config HTTP/2.0" 404 15875 "-" "Mozilla/5.0 (compatible; Bytespider; [email protected] ) AppleWebKit/537.36"
34.143.210.212 - - [22/Sep/2026:02:56:55 +0200] "GET /api/config HTTP/2.0" 404 15875 "-" "Mozilla/5.0 (compatible; MistralAI-User/1.0; +https://mistral.ai/)"
34.143.210.212 - - [22/Sep/2026:02:56:55 +0200] "GET /config.json HTTP/2.0" 404 15875 "-" "Mozilla/5.0 (compatible; Qwenbot/1.0; +https://qwen.alibaba.com/)"
...
show less
Web App Attack
Hacking
๐ช๐ธ
robotstxt
2026-09-21 23:03:41
(2 days ago)
34.143.210.212 - - [21/Sep/2026:23:02:52 +0000] "GET / HTTP/2.0" 403 17024 "-" "Mozilla/5.0 (Windows ...
show more
34.143.210.212 - - [21/Sep/2026:23:02:52 +0000] "GET / HTTP/2.0" 403 17024 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36" "-" edge="34.143.210.212"
34.143.210.212 - - [21/Sep/2026:23:02:52 +0000] "POST / HTTP/2.0" 403 15273 "-" "Mozilla/5.0 (compatible; xAI-Grok/1.0; +https://x.ai/)" "-" edge="34.143.210.212"
34.143.210.212 - - [21/Sep/2026:23:02:52 +0000] "GET /config.json HTTP/2.0" 403 11746 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexitybot)" "-" edge="34.143.210.212"
34.143.210.212 - - [21/Sep/2026:23:02:52 +0000] "GET /__env.js HTTP/2.0" 403 11746 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; [email protected] )" "-" edge="34.143.210.212"
34.143.210.212 - - [21/Sep/2026:23:02:52 +0000] "GET /__/firebase/init.json HTTP/2.0" 403 11746 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compat
...
show less
Web App Attack
๐บ๐ธ
Charlesiv
2026-09-21 22:06:21
(2 days ago)
Triggered Cloudflare WAF (firewallCustom) from SG.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Prot ...
show more
Triggered Cloudflare WAF (firewallCustom) from SG.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Protocol: HTTP/2 (POST method)
Endpoint: /functionRouter
Timestamp: 2026-09-21T21:49:36Z
Ray ID: a3ec47dcd9a940f7
UA: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; [email protected] )
show less
Bad Web Bot
๐บ๐ธ
Secure Gatewayยฎ๏ธ
2026-09-21 22:00:28
(2 days ago)
Report By Secure Gateway Security Team: Brute Force Login Attempt
Hacking
๐บ๐ธ
ALSCOยฎ๏ธ
2026-09-21 22:00:28
(2 days ago)
Report By ALSCO Security Team: Suspicious File Upload Attempt
SQL Injection
๐ฌ๐ง
pinguin
2026-09-21 21:55:33
(2 days ago)
Triggered Cloudflare WAF (firewallManaged) from SG.
Action taken: BLOCK
Protocol: HTTP/2 (POST metho ...
show more
Triggered Cloudflare WAF (firewallManaged) from SG.
Action taken: BLOCK
Protocol: HTTP/2 (POST method)
Endpoint: /
UA: Mozilla/5.0 (compatible; Meta-ExternalAgent/1.0; +https://developers.facebook.com/docs/sharing/webmasters/crawler)
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ฉ๐ช
AetherFox
2026-09-21 21:33:03
(2 days ago)
AetherFox VoidGuard detected: [Mon Sep 21 21:33:01.990842 2026] [authz_core:error] [pid 3389096:tid ...
show more
AetherFox VoidGuard detected: [Mon Sep 21 21:33:01.990842 2026] [authz_core:error] [pid 3389096:tid 3389125] [client 34.143.210.212:49312] AH01630: client denied by server configuration: proxy:https://[MASKED]/
[Mon Sep 21 21:33:02.330480 2026] [authz_core:error] [pid 3389096:tid 3389148] [client 34.143.210.212:49312] AH01630: client denied by server configuration: proxy:https://[MASKED]/.aws/credentials
[Mon Sep 21 21:33:02.490731 2026] [authz_core:error] [pid 3389096:tid 3389133] [client 34.143.210.212:49312] AH01630: client denied by server configuration: proxy:https://[MASKED]/z9x8c7v6b5-debug-trigger-www.draconigen.net
[Mon Sep 21 21:33:02.651246 2026] [authz_core:error] [pid 3389096:tid 3389131] [client 34.143.210.212:49312] AH01630: client denied by server configuration: proxy:https://[MASKED]/src/.env
[Mon Sep 21 21:33:02.657119 2026] [authz_core:error] [pid 3389096:tid 3389128] [client 34.143.210.212:49324] AH01630: client denied by server confi
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 20:52:49
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.143.210.212 (212.210.143.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.143.210.212 (212.210.143.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 16:52:42.594207 2026] [security2:error] [pid 14583:tid 14583] [client 34.143.210.212:35466] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.answeringamerica.net"] [uri "/.env.local"] [unique_id "arGZGoOVL2iGfm_ca3kcGAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
raph
2026-09-21 20:20:35
(2 days ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Savvii
2026-09-21 19:50:43
(2 days ago)
20 attempts against mh-misbehave-ban on redirect
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-09-21 19:40:40
(2 days ago)
Web attack/malicious scanning detected
Web App Attack
๐จ๐ฆ
Tanados
2026-09-21 18:27:02
(2 days ago)
Blocked by UFW [8080/tcp]
Source port: 39652
TTL: 54
Packet length: 60
TOS: 0x00
This report was ge ...
show more
Blocked by UFW [8080/tcp]
Source port: 39652
TTL: 54
Packet length: 60
TOS: 0x00
This report was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
๐ฉ๐ช
ghostwarriors
2026-09-21 18:20:14
(2 days ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack