π©πͺ
Gwyneth Llewelyn
2026-09-23 18:05:34
(25 minutes ago)
2026/09/23 19:05:32 [error] 325888#325888: *1641614 access forbidden by rule, client: 34.159.194.88, ...
show more
2026/09/23 19:05:32 [error] 325888#325888: *1641614 access forbidden by rule, client: 34.159.194.88, server: getasecondlife.net, request: "GET /admin/.env HTTP/2.0", host: "getasecondlife.net", referrer: "https://www.getasecondlife.net/admin/.env"
2026/09/23 19:05:32 [error] 325888#325888: *1641614 access forbidden by rule, client: 34.159.194.88, server: getasecondlife.net, request: "GET /backend/.env HTTP/2.0", host: "getasecondlife.net", referrer: "https://www.getasecondlife.net/backend/.env"
2026/09/23 19:05:32 [error] 325888#325888: *1641614 access forbidden by rule, client: 34.159.194.88, server: getasecondlife.net, request: "GET /api/.env HTTP/2.0", host: "getasecondlife.net", referrer: "https://www.getasecondlife.net/api/.env"
show less
Brute-Force
Web App Attack
πΊπΈ
Charlesiv
2026-09-23 18:00:34
(30 minutes ago)
Triggered Cloudflare WAF (firewallCustom) from DE.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Prot ...
show more
Triggered Cloudflare WAF (firewallCustom) from DE.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Protocol: HTTP/2 (GET method)
Endpoint: /actuator/heapdump
Timestamp: 2026-09-23T17:14:49Z
Ray ID: a3fb301dff45f877
UA: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; [email protected] )
show less
Bad Web Bot
πΊπΈ
zwebvigil
2026-09-23 17:56:35
(34 minutes ago)
34.159.194.88 [23/Sep/2026:10:56:34 -0700] "GET /asset-manifest.json HTTP/1.1" 404 2718 "-" port=40 ...
show more
34.159.194.88 [23/Sep/2026:10:56:34 -0700] "GET /asset-manifest.json HTTP/1.1" 404 2718 "-" port=40558 "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Mobile Safari/537.36" "-" "-" "www.<host>" 834
34.159.194.88 [23/Sep/2026:10:56:35 -0700] "GET /f9k1q9niogzbj3ryrhma HTTP/1.1" 404 2720 "-" port=40558 "Mozilla/5.0 (compatible; Hunyuan/1.0; +https://hunyuan.tencent.com/)" "-" "-" "www.<host>" 844
34.159.194.88 [23/Sep/2026:10:56:35 -0700] "GET /webpack-stats.json HTTP/1.1" 404 2716 "-" port=40584 "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Mobile Safari/537.36" "-" "-" "www.<host>" 2655
34.159.194.88 [23/Sep/2026:10:56:35 -0700] "GET /f9k1q9niogzbj3ryrhma HTTP/1.1" 404 2720 "-" port=40558 "Mozilla/5.0 (compatible; Hunyuan/1.0; +https://hunyuan.tencent.com/)" "-" "-" "www.<host>" 844
34.159.194.88 [23/Sep/2026:10:56:35 -0700] "GET /webpack-stats.json HTTP/1.
show less
Web App Attack
πͺπΈ
el-brujo
2026-09-23 17:21:52
(1 hour ago)
34.159.194.88 - - [23/Sep/2026:19:21:52 +0200] "GET /z9x8c7v6b5-debug-trigger-www.elhacker.net HTTP/ ...
show more
34.159.194.88 - - [23/Sep/2026:19:21:52 +0200] "GET /z9x8c7v6b5-debug-trigger-www.elhacker.net HTTP/2.0" 404 15955 "-" "Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; +https://kimi.ai/)"
34.159.194.88 - - [23/Sep/2026:19:21:52 +0200] "GET /.vite/manifest.json HTTP/2.0" 404 15955 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36 Edg/153.0.0.0"
34.159.194.88 - - [23/Sep/2026:19:21:52 +0200] "GET /build/manifest.json HTTP/2.0" 404 15955 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36 Edg/153.0.0.0"
34.159.194.88 - - [23/Sep/2026:19:21:52 +0200] "GET /86czgk5oewxne502b0mh HTTP/2.0" 404 15955 "-" "Mozilla/5.0 (compatible; Google-Extended; +http://www.google.com/bot.html)"
...
show less
Web App Attack
Hacking
π¬π§
NotCool
2026-09-23 17:21:05
(1 hour ago)
[7200] (CRAWLDELAY,DOTENVPROBE) Login failure/trigger from 34.159.194.88 (DE/Germany/88.194.159.34.b ...
show more
[7200] (CRAWLDELAY,DOTENVPROBE) Login failure/trigger from 34.159.194.88 (DE/Germany/88.194.159.34.bc.googleusercontent.com): 50 in the last 3600 secs
show less
Brute-Force
π©πͺ
AetherFox
2026-09-23 17:20:33
(1 hour ago)
AetherFox VoidGuard detected: [Wed Sep 23 17:20:30.403318 2026] [authz_core:error] [pid 3700731:tid ...
show more
AetherFox VoidGuard detected: [Wed Sep 23 17:20:30.403318 2026] [authz_core:error] [pid 3700731:tid 3700784] [client 34.159.194.88:55544] AH01630: client denied by server configuration: proxy:https://[MASKED]/
[Wed Sep 23 17:20:32.779660 2026] [authz_core:error] [pid 3700731:tid 3700774] [client 34.159.194.88:55544] AH01630: client denied by server configuration: proxy:https://[MASKED]/5w7w7p35az0xarxkn2t8
[Wed Sep 23 17:20:32.997460 2026] [authz_core:error] [pid 3700730:tid 3700770] [client 34.159.194.88:55560] AH01630: client denied by server configuration: proxy:https://[MASKED]/z9x8c7v6b5-debug-trigger-www.draconigen.net
[Wed Sep 23 17:20:33.006953 2026] [authz_core:error] [pid 3700730:tid 3700733] [client 34.159.194.88:55564] AH01630: client denied by server configuration: proxy:https://[MASKED]/9dlgue6p59vpc7mdg3d9
[Wed Sep 23 17:20:33.042629 2026] [authz_core:error] [pid 3700731:tid 3700751] [client 34.159.194.88:55548] AH01630: client denied by s
...
show less
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-23 16:56:21
(1 hour ago)
(mod_security) mod_security (id:210730) triggered by 34.159.194.88 (88.194.159.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.159.194.88 (88.194.159.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 12:56:13.213922 2026] [security2:error] [pid 22559:tid 22559] [client 34.159.194.88:51210] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||anthonyanimalclinic.net|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "anthonyanimalclinic.net"] [uri "/rclone.conf"] [unique_id "arQErZng6O1vjjz8RsI37AAAACQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
abenage
2026-09-23 16:50:52
(1 hour ago)
34.159.194.88 - - [23/Sep/2026:10:50:51 -0600] "GET /auth HTTP/2.0" 404 564 "-" "Mozilla/5.0 (Window ...
show more
34.159.194.88 - - [23/Sep/2026:10:50:51 -0600] "GET /auth HTTP/2.0" 404 564 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36 Edg/153.0.0.0"
show less
Bad Web Bot
Web App Attack
π³π±
Savvii
2026-09-23 16:36:46
(1 hour ago)
20 attempts against mh-misbehave-ban on redirect
Brute-Force
Bad Web Bot
Web App Attack
π³π±
ItsJustStan
2026-09-23 16:21:44
(2 hours ago)
Web app attack - scanning for vulnerabilities
Web App Attack
πΊπΈ
Omega Threat-ID
2026-09-23 16:01:07
(2 hours ago)
Omega Point Threat ID honeypot sensor observed: abuse-reported
Port Scan
π©πͺ
Viveronese
2026-09-23 15:06:27
(3 hours ago)
HTTP vulnerability scanning
Web App Attack
π³π±
MM-bot
2026-09-23 15:05:16
(3 hours ago)
URL-probe: HTTP/2 GET request on /admin/login (2026-09-23 17:05:16 UTC+2)
Web App Attack
Hacking
πΊπΈ
zwebvigil
2026-09-23 15:03:40
(3 hours ago)
34.159.194.88 [23/Sep/2026:08:03:39 -0700] "GET /z9x8c7v6b5-debug-trigger-<host> HTTP/1.1" 404 2752 ...
show more
34.159.194.88 [23/Sep/2026:08:03:39 -0700] "GET /z9x8c7v6b5-debug-trigger-<host> HTTP/1.1" 404 2752 "-" port=49330 "Mozilla/5.0 (compatible; Bytespider; [email protected] ) AppleWebKit/537.36" "-" "-" "<host>" 918
34.159.194.88 [23/Sep/2026:08:03:40 -0700] "GET /manifest.json HTTP/1.1" 404 2706 "-" port=35272 "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Mobile Safari/537.36" "-" "-" "<host>" 1369
34.159.194.88 [23/Sep/2026:08:03:40 -0700] "GET /webpack-stats.json HTTP/1.1" 404 2716 "-" port=35280 "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Mobile Safari/537.36" "-" "-" "<host>" 1542
34.159.194.88 [23/Sep/2026:08:03:40 -0700] "GET /asset-manifest.json HTTP/1.1" 404 2718 "-" port=49330 "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Mobile Safari/537.36" "-" "-" "<host>" 1348
34.159.194.88 [23/S
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-23 14:47:36
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.159.194.88 (88.194.159.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.159.194.88 (88.194.159.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 10:47:29.865516 2026] [security2:error] [pid 2579644:tid 2579644] [client 34.159.194.88:52024] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gensou.net"] [uri "/@fs/.env"] [unique_id "arPmgb01wKJTsN1rZZf1lAAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack