๐จ๐ฑ
Fernando Soto
2026-10-01 03:05:19
(1 day ago)
WAF propio vps1 (CL): sensx202 score 20 en 1h. sondeo rutas sensibles.
Web App Attack
๐ฆ๐บ
Klaverstyn
2026-09-30 23:41:35
(1 day ago)
Persistent attacker, repeat offender
Hacking
๐ณ๐ฑ
Alt255
2026-09-30 04:51:18
(2 days ago)
[ti-02ra] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail apac ...
show more
[ti-02ra] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail apache-404. Example: 34.146.7.108 - - [30/Sep/2026:06:51:15 +0200] "GET /dist/manifest.json HTTP/2.0" 404 1878 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Mobile Safari/537.36 EdgA/152.0.0.0"
34.146.7.108 - - [30/Sep/2026:06:51:15 +0200] "GET /.vite/manifest.json HTTP/2.0" 404 1855 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Mobile Safari/537.36 EdgA/152.0.0.0"
34.146.7.108 - - [30/Sep/2026:06:51:16 +0200] "GET /aq0csdtz3800b6wtyvt8 HTTP/2.0" 404 1920 "-" "Mozilla/5.0 (compatible; ChatGLM-Spider/1.0; +https://zhipuai.cn/)"
34.146.7.108 - - [30/Sep/2026:06:51:16 +0200] "GET /dist/.vite/manifest.json HTTP/2.0" 404 1920
...
show less
Bad Web Bot
Web App Attack
๐ช๐ธ
robotstxt
2026-09-30 03:29:43
(2 days ago)
34.146.7.108 - - [30/Sep/2026:03:29:40 +0000] "GET /..%2f..%2f.env HTTP/1.1" 400 193 "-" "-" "-" edg ...
show more
34.146.7.108 - - [30/Sep/2026:03:29:40 +0000] "GET /..%2f..%2f.env HTTP/1.1" 400 193 "-" "-" "-" edge="34.146.7.108"
34.146.7.108 - - [30/Sep/2026:03:29:40 +0000] "GET /icons/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/proc/self/environ HTTP/1.1" 400 193 "-" "-" "-" edge="34.146.7.108"
34.146.7.108 - - [30/Sep/2026:03:29:40 +0000] "GET /uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f.env HTTP/1.1" 400 193 "-" "-" "-" edge="34.146.7.108"
34.146.7.108 - - [30/Sep/2026:03:29:41 +0000] "GET /static/../../../a/../../../../.env HTTP/1.1" 400 193 "-" "-" "-" edge="34.146.7.108"
34.146.7.108 - - [30/Sep/2026:03:29:41 +0000] "GET /static/../../../a/../../../../proc/self/environ HTTP/1.1" 400 193 "-" "-" "-" edge="34.146.7.108"
...
show less
Web Spam
Web App Attack
Anonymous
2026-09-30 03:18:15
(2 days ago)
Portscan: TCP/8080 (4x), TCP/8443 (4x), TCP/443, TCP/80
Port Scan
Anonymous
2026-09-30 02:51:12
(2 days ago)
34.146.7.108 - - [29/Sep/2026:21:51:09 -0500] "GET /.env.local HTTP/1.1" 403 199 "-" "Mozilla/5.0 (c ...
show more
34.146.7.108 - - [29/Sep/2026:21:51:09 -0500] "GET /.env.local HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; DeepSeekBot/1.0; +https://www.deepseek.com/)" 34.146.7.108
34.146.7.108 - - [29/Sep/2026:21:51:09 -0500] "GET /.env.example HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)" 34.146.7.108
34.146.7.108 - - [29/Sep/2026:21:51:09 -0500] "GET /.env.production HTTP/1.1" 403 199 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-SearchBot/1.0; [email protected] )" 34.146.7.108
34.146.7.108 - - [29/Sep/2026:21:51:09 -0500] "GET /.env HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" 34.146.7.108
34.146.7.108 - - [29/Sep/2026:21:51:10 -0500] "GET /.env.backup HTTP/1.1" 403 199 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexitybot)" 34.146.7.108
34.146.7.108 - - [29/Sep/2026:21:51:10
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
Klaverstyn
2026-09-30 02:38:37
(2 days ago)
Excessive HTTP request rate
Web App Attack
๐ฉ๐ช
sdos.es
2026-09-30 01:17:21
(2 days ago)
"OS File Access Attempt - Matched Data: proc/self/environ found within ARGS:0: {\x22then\x22:\x22$1: ...
show more
"OS File Access Attempt - Matched Data: proc/self/environ found within ARGS:0: {\x22then\x22:\x22$1:__proto__:then\x22,\x22status\x22:\x22resolved_model\x22,\x22reason\x22:-1,\x22value\x22:\x22{/\x22then/\x22:/\x22$b1337/\x22}\x22,\x22_response\x22:{\x22_prefix\x22:\x22process.mainmodule.require('child_process').execsync('env 2>/dev/null || cat /proc/self/environ 2>/dev/null');\x22,\x22_formdata\x22:{\x22get\x22:\x22$1:constructor:constructor\x22}}}"
show less
Web App Attack
Anonymous
2026-09-30 00:39:57
(2 days ago)
Aggressive web scan
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-29 21:28:27
(2 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-29 20:18:25
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 34.146.7.108 (108.7.146.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.146.7.108 (108.7.146.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 16:18:18.098341 2026] [security2:error] [pid 11083:tid 11083] [client 34.146.7.108:43392] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||replacementairfilter.airintakesonline.com|F|2"] [data ".airintakesonline.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "replacementairfilter.airintakesonline.com"] [uri "/z9x8c7v6b5-debug-trigger-replacementairfilter.airintakesonline.com"] [unique_id "arwdCnutwPUfFvcArw5K1wAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
polycoda
2026-09-29 19:23:14
(2 days ago)
๐ฅ VERY AGGRESSIVE SCANNER probed over 300 inexistent files and PHP scripts in less than an hour.
Hacking
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-09-29 19:18:30
(2 days ago)
Try to access /.env.local
Web App Attack
๐จ๐ฑ
Fernando Soto
2026-09-29 19:05:02
(2 days ago)
WAF propio vps1 (CL): sensx202 score 20 en 1h. sondeo rutas sensibles.
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-29 18:52:01
(2 days ago)
Excessive multi-domain requests
Brute-Force