๐ฉ๐ช
yitzhaq
2026-10-01 14:57:14
(4 days ago)
34.158.243.180 - - [01/Oct/2026:16:57:12 +0200] "GET /actuator/mappings HTTP/2.0" 403 292 "-" "Mozil ...
show more
34.158.243.180 - - [01/Oct/2026:16:57:12 +0200] "GET /actuator/mappings HTTP/2.0" 403 292 "-" "Mozilla/5.0 (compatible; Qwenbot/1.0; +https://qwen.alibaba.com/)"
34.158.243.180 - - [01/Oct/2026:16:57:12 +0200] "GET /telescope/requests HTTP/2.0" 404 288 "-" "Mozilla/5.0 (compatible; Hunyuan/1.0; +https://hunyuan.tencent.com/)"
34.158.243.180 - - [01/Oct/2026:16:57:12 +0200] "GET /_debugbar/open HTTP/2.0" 404 288 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot"
34.158.243.180 - - [01/Oct/2026:16:57:12 +0200] "GET /phpinfo.php HTTP/2.0" 403 292 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36; compatible; OAI-SearchBot/1.4; +https://openai.com/searchbot"
34.158.243.180 - - [01/Oct/2026:16:57:12 +0200] "GET /__debug__/ HTTP/2.0" 404 288 "-" "Mozilla/5.0 (compatible; DeepSeekBot/1.0; +https://www.deepseek.com/)"
34.158.243.180 - - [01/Oct/2026:16:57:12 +02
show less
Bad Web Bot
๐ฉ๐ช
Skyrider
2026-10-01 14:55:16
(4 days ago)
crowdsecurity/http-bad-user-agent
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-01 14:42:33
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.158.243.180 (180.243.158.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.158.243.180 (180.243.158.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 10:42:30.396413 2026] [security2:error] [pid 6658:tid 6658] [client 34.158.243.180:50458] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "doctorc.net"] [uri "/.htpasswd"] [unique_id "ar5xVqtBQRqoX2Hm2FBEawAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
firestorm
2026-10-01 14:32:55
(4 days ago)
34.158.243.180 - - [01/Oct/2026:16:32:54 +0200] "GET /..%2f.env HTTP/1.1" 400 150 "-" "-"
34.158.243 ...
show more
34.158.243.180 - - [01/Oct/2026:16:32:54 +0200] "GET /..%2f.env HTTP/1.1" 400 150 "-" "-"
34.158.243.180 - - [01/Oct/2026:16:32:54 +0200] "GET /%2e%2e/.env HTTP/1.1" 400 150 "-" "-"
34.158.243.180 - - [01/Oct/2026:16:32:55 +0200] "GET /..%2f..%2f.env HTTP/1.1" 400 150 "-" "-"
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
kosada.com
2026-10-01 14:32:42
(4 days ago)
Repeated requests for suspicious nonexistent URLs, for example: /assets/manifest.json (HTTP/2.0 port ...
show more
Repeated requests for suspicious nonexistent URLs, for example: /assets/manifest.json (HTTP/2.0 port 443, user agent: "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36 Edg/153.0.0.0")
show less
Web App Attack
Anonymous
2026-10-01 14:31:11
(4 days ago)
Aggressive web scan
Web App Attack
๐ต๐ฑ
sefinek.net
2026-10-01 14:25:04
(4 days ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action: BLOCK | Protocol: HTTP/2 (GET) | Endpoint ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action: BLOCK | Protocol: HTTP/2 (GET) | Endpoint: /privatekey.key | UA: Mozilla/5.0 (compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot) โข Generated by: github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
Anonymous
2026-10-01 14:00:08
(4 days ago)
| Multiple common web attacks from same source ip. (multiple servers)
Web App Attack
Hacking
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-10-01 13:58:58
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.158.243.180 (180.243.158.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.158.243.180 (180.243.158.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 09:58:54.418212 2026] [security2:error] [pid 22441:tid 22441] [client 34.158.243.180:57088] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.adj-tech.net"] [uri "/.htpasswd"] [unique_id "ar5nHmVWabt_0f2CW4MaJgAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 13:43:27
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.158.243.180 (180.243.158.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.158.243.180 (180.243.158.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 09:43:23.910190 2026] [security2:error] [pid 22791:tid 22791] [client 34.158.243.180:53428] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "eeeckythump.net"] [uri "/.htpasswd"] [unique_id "ar5je9gXAvDG5qWl9sUHAwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
noise.agency
2026-10-01 13:42:01
(4 days ago)
34.158.243.180 (US/United States/180.243.158.34.bc.googleusercontent.com), more than 10 Apache 403 h ...
show more
34.158.243.180 (US/United States/180.243.158.34.bc.googleusercontent.com), more than 10 Apache 403 hits
show less
Hacking
๐บ๐ธ
zwebvigil
2026-10-01 13:34:03
(4 days ago)
34.158.243.180 [01/Oct/2026:06:34:02 -0700] "GET /static/manifest.json HTTP/1.1" 404 2720 "-" port= ...
show more
34.158.243.180 [01/Oct/2026:06:34:02 -0700] "GET /static/manifest.json HTTP/1.1" 404 2720 "-" port=56620 "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Mobile Safari/537.36" "-" "-" "www.<host>" 492
34.158.243.180 [01/Oct/2026:06:34:02 -0700] "GET /37eyyqwuoy2o3x7heqnv HTTP/1.1" 404 2720 "-" port=56620 "Mozilla/5.0 (compatible; Bravebot/1.0; +https://brave.com/search/)" "-" "-" "www.<host>" 895
34.158.243.180 [01/Oct/2026:06:34:02 -0700] "GET /webpack-stats.json HTTP/1.1" 404 2716 "-" port=56620 "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Mobile Safari/537.36" "-" "-" "www.<host>" 467
34.158.243.180 [01/Oct/2026:06:34:02 -0700] "GET /z9x8c7v6b5-debug-trigger-www.<host> HTTP/1.1" 404 2760 "-" port=56628 "Mozilla/5.0 (compatible; PanguBot/1.0; +https://www.huaweicloud.com/)" "-" "-" "www.<host>" 1324
34.158.243.180 [01/Oct/2026:06:34:02 -0700] "GET /m
show less
Web App Attack
๐ฎ๐น
VHosting
2026-10-01 13:30:03
(4 days ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 12:47:41
(4 days ago)
(mod_security) mod_security (id:210730) triggered by 34.158.243.180 (180.243.158.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 34.158.243.180 (180.243.158.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 08:47:34.747968 2026] [security2:error] [pid 18605:tid 18605] [client 34.158.243.180:58322] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||billystuff.net|F|2"] [data ".axd"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "billystuff.net"] [uri "/trace.axd"] [unique_id "ar5WZvSaK9GkGkabGj_3TwAAADA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
clapper
2026-10-01 12:41:49
(4 days ago)
(mod_security) mod_security (id:980001) triggered by 34.158.243.180 (US/United States/180.243.158.34 ...
show more
(mod_security) mod_security (id:980001) triggered by 34.158.243.180 (US/United States/180.243.158.34.bc.googleusercontent.com): 3 in the last 3600 secs; ID: LUC
show less
Brute-Force
Bad Web Bot