๐บ๐ธ
paulo.apoloni
2026-10-07 00:28:56
(1 hour ago)
34.152.17.253 - - [06/Oct/2026:21:28:56 -0300] "GET /.ssh/id_rsa HTTP/1.1" 404 146 "-" "Mozilla/5.0 ...
show more
34.152.17.253 - - [06/Oct/2026:21:28:56 -0300] "GET /.ssh/id_rsa HTTP/1.1" 404 146 "-" "Mozilla/5.0 (compatible; YiBot/1.0; +https://01.ai/)"
34.152.17.253 - - [06/Oct/2026:21:28:56 -0300] "GET /.env?import&raw HTTP/1.1" 404 146 "-" "DuckAssistBot/1.1 (https://duckduckgo.com/duckassistbot)"
34.152.17.253 - - [06/Oct/2026:21:28:56 -0300] "GET /.htpasswd HTTP/1.1" 404 146 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
34.152.17.253 - - [06/Oct/2026:21:28:56 -0300] "GET /.ssh/config HTTP/1.1" 404 146 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot)"
34.152.17.253 - - [06/Oct/2026:21:28:56 -0300] "GET /.ssh/id_ed25519 HTTP/1.1" 404 146 "-" "Mozilla/5.0 (compatible; YiBot/1.0; +https://01.ai/)"
...
show less
Web App Attack
๐ฉ๐ช
niedson
2026-10-06 17:00:02
(9 hours ago)
Automated scanning for exposed secrets: repeated requests for multiple distinct credential paths (.e ...
show more
Automated scanning for exposed secrets: repeated requests for multiple distinct credential paths (.env variants, .git metadata, .ssh private keys, .aws/credentials). Unsolicited. Reported automatically.
show less
Web App Attack
Anonymous
2026-10-06 16:24:11
(10 hours ago)
34.152.17.253 - - [06/Oct/2026:13:24:11 -0300] "GET /admin HTTP/2.0" 404 858 "-" "Mozilla/5.0 (Linux ...
show more
34.152.17.253 - - [06/Oct/2026:13:24:11 -0300] "GET /admin HTTP/2.0" 404 858 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Mobile Safari/537.36"
34.152.17.253 - - [06/Oct/2026:13:24:11 -0300] "GET /admin/login HTTP/2.0" 404 858 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Mobile Safari/537.36"
...
show less
Port Scan
๐ฌ๐ง
consul.to
2026-10-06 16:05:11
(10 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
paulo.apoloni
2026-10-06 15:27:13
(10 hours ago)
34.152.17.253 - - [06/Oct/2026:12:27:12 -0300] "GET /.ssh/id_ed25519 HTTP/1.1" 444 0 "-" "Mozilla/5. ...
show more
34.152.17.253 - - [06/Oct/2026:12:27:12 -0300] "GET /.ssh/id_ed25519 HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Safari/605.1.15 (Applebot/0.1)"
34.152.17.253 - - [06/Oct/2026:12:27:12 -0300] "GET /.ssh/id_rsa HTTP/1.1" 444 0 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-SearchBot/1.0; [email protected] )"
34.152.17.253 - - [06/Oct/2026:12:27:12 -0300] "GET /.ssh/id_rsa HTTP/1.1" 444 0 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-SearchBot/1.0; [email protected] )"
34.152.17.253 - - [06/Oct/2026:12:27:12 -0300] "GET /.ssh/id_ed25519 HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Safari/605.1.15 (Applebot/0.1)"
34.152.17.253 - - [06/Oct/2026:12:27:12 -0300] "GET /.ssh/id_rsa HTTP/1.1" 444 0 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-
...
show less
Bad Web Bot
Web App Attack
๐ง๐ท
dominioz
2026-10-06 15:01:00
(11 hours ago)
2026-10-06 15:00:52 GET /@fs/..%2f..%2f..%2f..%2f..%2froot/.env raw?? - 34.152.17.253 HTTP/2 Mozilla ...
show more
2026-10-06 15:00:52 GET /@fs/..%2f..%2f..%2f..%2f..%2froot/.env raw?? - 34.152.17.253 HTTP/2 Mozilla/5.0+(compatible;+DeepSeekBot/1.0;++https://www.deepseek.com/) - 301 650
...
show less
Bad Web Bot
Web App Attack
๐ง๐ท
maviei
2026-10-06 13:44:53
(12 hours ago)
radiojfsliberdade.com.br 34.152.17.253 - - [06/Oct/2026:10:44:51 -0300] "GET /.git-credentials HTTP/ ...
show more
radiojfsliberdade.com.br 34.152.17.253 - - [06/Oct/2026:10:44:51 -0300] "GET /.git-credentials HTTP/2.0" 444 0 "-" "Mozilla/5.0 (compatible; Qwenbot/1.0; +https://qwen.alibaba.com/)"
...
show less
Web App Attack
๐ง๐ท
Halux
2026-10-06 09:04:51
(17 hours ago)
34.152.17.253 Web Application Firewall multiple violations
Hacking
Web App Attack
๐ซ๐ท
mrcrassi
2026-10-06 08:22:52
(18 hours ago)
Triggered Cloudflare WAF (firewallManaged) from CA.
Action taken: BLOCK
Protocol: HTTP/1.1 (POST met ...
show more
Triggered Cloudflare WAF (firewallManaged) from CA.
Action taken: BLOCK
Protocol: HTTP/1.1 (POST method)
Endpoint: /admin
UA: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; [email protected] )
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ง๐ท
Halux
2026-10-06 08:15:08
(18 hours ago)
34.152.17.253 Probing protected path or service
Web App Attack
๐บ๐ธ
paulo.apoloni
2026-10-06 07:34:33
(18 hours ago)
34.152.17.253 - - [06/Oct/2026:04:34:32 -0300] "GET /.ssh/id_rsa HTTP/1.1" 444 0 "-" "Mozilla/5.0 (c ...
show more
34.152.17.253 - - [06/Oct/2026:04:34:32 -0300] "GET /.ssh/id_rsa HTTP/1.1" 444 0 "-" "Mozilla/5.0 (compatible; cohere-ai; +https://cohere.com/crawler)"
34.152.17.253 - - [06/Oct/2026:04:34:32 -0300] "GET /.htpasswd HTTP/1.1" 444 0 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; GPTBot/1.4; +https://openai.com/gptbot"
34.152.17.253 - - [06/Oct/2026:04:34:32 -0300] "GET /.ssh/id_ed25519 HTTP/1.1" 444 0 "-" "DuckAssistBot/1.1 (https://duckduckgo.com/duckassistbot)"
34.152.17.253 - - [06/Oct/2026:04:34:32 -0300] "GET /.htpasswd HTTP/1.1" 444 0 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; GPTBot/1.4; +https://openai.com/gptbot"
34.152.17.253 - - [06/Oct/2026:04:34:32 -0300] "GET /.ssh/id_rsa HTTP/1.1" 444 0 "-" "Mozilla/5.0 (compatible; cohere-ai; +https://cohere.com/crawler)"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
agenciahypelab.com.br
2026-10-06 07:02:50
(19 hours ago)
WordPress login brute-force detectado e bloqueado pelo CSF/LFD. Trigger: LF_TRIGGER
Brute-Force
SSH
Anonymous
2026-10-06 07:00:01
(19 hours ago)
suspicious request in access.log
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 05:05:23
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 34.152.17.253 (253.17.152.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.152.17.253 (253.17.152.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 01:05:18.132415 2026] [security2:error] [pid 17887:tid 17887] [client 34.152.17.253:54812] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.matteozacchino.dev"] [uri "/.env.js"] [unique_id "ar3qDp1xBSa1aY63xb4mCQAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฟ
akac
2026-10-01 05:03:06
(5 days ago)
Web vulnerability scanning: HTTP/2 GET /forgot-password
Hacking
Brute-Force
Bad Web Bot
Web App Attack