๐บ๐ธ
[email protected]
2026-10-05 18:23:08
(2 hours ago)
CrowdSec ban: crowdsecurity/unifi-flood-detection (duration: 71h59m57s)
Port Scan
๐ฉ๐ช
pscriptos
2026-10-05 15:45:37
(4 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐ธ๐ช
cider1725
2026-10-05 15:04:54
(5 hours ago)
34.168.103.222 - - [05/Oct/2026:15:04:53 +0000] "GET /i46i3ls5fxw2gl3x5ysm HTTP/1.1" 444 0 "-" "Mozi ...
show more
34.168.103.222 - - [05/Oct/2026:15:04:53 +0000] "GET /i46i3ls5fxw2gl3x5ysm HTTP/1.1" 444 0 "-" "Mozilla/5.0 (compatible; PanguBot/1.0; +https://www.huaweicloud.com/)" "-"
34.168.103.222 - - [05/Oct/2026:15:04:53 +0000] "POST / HTTP/1.1" 444 0 "-" "Mozilla/5.0 (compatible; YouBot/1.0; +https://you.com/bot)" "-"
34.168.103.222 - - [05/Oct/2026:15:04:53 +0000] "GET /i46i3ls5fxw2gl3x5ysm HTTP/1.1" 444 0 "-" "Mozilla/5.0 (compatible; PanguBot/1.0; +https://www.huaweicloud.com/)" "-"
...
show less
Brute-Force
Web App Attack
๐ฐ๐ท
Seung Seog Han
2026-10-05 14:20:57
(6 hours ago)
Brute-force attack detected
Brute-Force
SSH
๐บ๐ธ
Charlesiv
2026-10-05 14:16:02
(6 hours ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Prot ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Protocol: HTTP/2 (POST method)
Endpoint: /cgi-bin/php-cgi
Query: ?-d+allow_url_include%3don+-d+auto_prepend_file%3dphp://input
Timestamp: 2026-10-05T12:32:41Z
Ray ID: a45c73515b49eb43
UA: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot)
show less
Bad Web Bot
๐ณ๐ด
Abuse Buster
2026-10-05 13:32:01
(7 hours ago)
34.168.103.222 - - [05/Oct/2026:15:31:59 +0200] "GET /z9x8c7v6b5-debug-trigger-api.wingthor.net HTTP ...
show more
34.168.103.222 - - [05/Oct/2026:15:31:59 +0200] "GET /z9x8c7v6b5-debug-trigger-api.wingthor.net HTTP/2.0" 404 22 "-" "DuckAssistBot/1.1 (https://duckduckgo.com/duckassistbot)"
34.168.103.222 - - [05/Oct/2026:15:31:59 +0200] "GET /gfmae1ofzwhh42dnlz1v HTTP/2.0" 404 22 "-" "Mozilla/5.0 (compatible; PanguBot/1.0; +https://www.huaweicloud.com/)"
34.168.103.222 - - [05/Oct/2026:15:31:59 +0200] "GET /ntng7n8tmdrsgs7tqzrh HTTP/2.0" 404 22 "-" "Mozilla/5.0 (compatible; Qwenbot/1.0; +https://qwen.alibaba.com/)"
...
show less
Web App Attack
๐ซ๐ฎ
oh.mg
2026-10-05 13:08:37
(7 hours ago)
[Mon Oct 05 15:08:36.984321 2026] [security2:error] [pid 2887481:tid 2887507] [client 34.168.103.222 ...
show more
[Mon Oct 05 15:08:36.984321 2026] [security2:error] [pid 2887481:tid 2887507] [client 34.168.103.222:0] [client 34.168.103.222] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [ver "OWASP_CRS/4.10.0-dev"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "api.mmn.ca"] [uri "/.htpasswd"] [unique_id "asOhVNCHpfL7-icjl0-nKgAAAJg"]
...
show less
Web App Attack
Bad Web Bot
๐บ๐ธ
[email protected]
2026-10-05 11:00:38
(9 hours ago)
CrowdSec ban: crowdsecurity/http-bad-user-agent (duration: 71h59m54s)
Web App Attack
๐ฆ๐บ
FireGuard Server
2026-10-05 08:40:07
(12 hours ago)
Blocked by os-abuseipdb; 8 hits, proto=tcp, ports=443,80
Port Scan
Hacking
๐ญ๐ฐ
zhengka
2026-10-05 08:07:36
(12 hours ago)
ZhengKa WAF detected scan_probe. Rule: scan_probe #/(?:\.env|\.git|\.svn|composer\.json|composer\.lo ...
show more
ZhengKa WAF detected scan_probe. Rule: scan_probe #/(?:\.env|\.git|\.svn|composer\.json|composer\.lock|id_rsa|server-status)(?:$|[/?])#. Method: GET. URI: /.ssh/id_rsa. Incident: 0292E0C8F7A6227A. UA: DuckAssistBot/1.1 (https://duckduckgo.com/duckassistbot)
show less
Port Scan
Web App Attack
๐ฉ๐ช
Michel Wijnberg
2026-10-05 07:56:34
(12 hours ago)
34.168.103.222 - - [05/Oct/2026:07:56:34 +0000] "GET /files../.env HTTP/1.1" 301 162 "-" "Mozilla/5. ...
show more
34.168.103.222 - - [05/Oct/2026:07:56:34 +0000] "GET /files../.env HTTP/1.1" 301 162 "-" "Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; +https://kimi.ai/)"
...
show less
Bad Web Bot
Web App Attack
๐ฏ๐ต
weils.net
2026-10-05 07:55:34
(12 hours ago)
2026-10-05 15:55:34(GMT+8) - /document.php?modulepart=systemtools&file=../conf/conf.php&hashp=shared
Bad Web Bot
๐ฉ๐ช
LRob
2026-10-05 07:54:24
(12 hours ago)
Wordlist path sweep | method: GET | path: /088dch3ij2b9tuflt4a4, /03b5unq37fenry9505rb, /manifest.js ...
show more
Wordlist path sweep | method: GET | path: /088dch3ij2b9tuflt4a4, /03b5unq37fenry9505rb, /manifest.json | ua: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; [email protected] ), Mozilla/5.0 (compatible; Bytespider; [email protected] ) AppleWebKit/537.36, Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36 | 2026-10-05 07:54 UTC
show less
Port Scan
Web App Attack
๐ฉ๐ช
Viveronese
2026-10-05 07:17:18
(13 hours ago)
HTTP vulnerability scanning
Web App Attack
๐บ๐ธ
HamSammich
2026-10-05 07:14:50
(13 hours ago)
Automated sensor: 5 HTTPS connection/probe attempts over the last 24h (latest 2026-10-05T07:14Z).
Brute-Force
Web App Attack