๐บ๐ธ
[email protected]
2026-10-01 07:05:57
(23 hours ago)
CrowdSec ban: crowdsecurity/unifi-flood-detection (duration: 71h59m52s)
Port Scan
๐บ๐ธ
TPI-Abuse
2026-10-01 05:17:52
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.168.121.208 (208.121.168.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 34.168.121.208 (208.121.168.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 01:17:44.223965 2026] [security2:error] [pid 1620:tid 1620] [client 34.168.121.208:56906] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||larkinplumbing.net|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "larkinplumbing.net"] [uri "/config.php.bak"] [unique_id "ar3s-Cf68OmoU6Hn0IA3AgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ช
sweplox.se
2026-10-01 04:46:35
(1 day ago)
Ip 34.168.121.208 performed 'crowdsecurity/http-sensitive-files' (5 events over 112.159024ms) at 202 ...
show more
Ip 34.168.121.208 performed 'crowdsecurity/http-sensitive-files' (5 events over 112.159024ms) at 2026-10-01 04:46:33.898428013 +0000 UTC
show less
Hacking
๐ง๐ช
cmbplf
2026-10-01 04:36:51
(1 day ago)
324 requests with url.path *.env
Brute-Force
Bad Web Bot
๐ณ๐ฑ
Savvii
2026-10-01 03:23:35
(1 day ago)
20 attempts against mh-misbehave-ban on redirect
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Charlesiv
2026-10-01 02:08:08
(1 day ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Prot ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Protocol: HTTP/2 (POST method)
Endpoint: /cgi-bin/php-cgi.exe
Query: ?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input
Timestamp: 2026-10-01T01:13:18Z
Ray ID: a4379aa2f85f2c3d
UA: Mozilla/5.0 (compatible; Qwenbot/1.0; +https://qwen.alibaba.com/)
show less
Bad Web Bot
๐ช๐ธ
el-brujo
2026-10-01 00:59:08
(1 day ago)
34.168.121.208 - - [01/Oct/2026:02:59:08 +0200] "GET /z9x8c7v6b5-debug-trigger-www.elhacker.net HTTP ...
show more
34.168.121.208 - - [01/Oct/2026:02:59:08 +0200] "GET /z9x8c7v6b5-debug-trigger-www.elhacker.net HTTP/2.0" 404 15908 "-" "Mozilla/5.0 (compatible; Hunyuan/1.0; +https://hunyuan.tencent.com/)"
34.168.121.208 - - [01/Oct/2026:02:59:08 +0200] "GET /build/manifest.json HTTP/2.0" 404 15908 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36 Edg/153.0.0.0"
34.168.121.208 - - [01/Oct/2026:02:59:08 +0200] "GET /zg3r5rv1s7u9kluw43kg HTTP/2.0" 404 15908 "-" "Mozilla/5.0 (compatible; YouBot/1.0; +https://you.com/bot)"
34.168.121.208 - - [01/Oct/2026:02:59:08 +0200] "GET /dist/.vite/manifest.json HTTP/2.0" 404 15908 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36 Edg/153.0.0.0"
...
show less
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-10-01 00:55:27
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.168.121.208 (208.121.168.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.168.121.208 (208.121.168.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 20:55:20.071792 2026] [security2:error] [pid 32721:tid 32748] [client 34.168.121.208:47512] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.appraisalteam.net"] [uri "/img../.env"] [unique_id "ar2veIqCMxB8atLJJ8X-hQAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
AetherFox
2026-09-30 23:27:31
(1 day ago)
AetherFox VoidGuard detected: [Thu Oct 01 01:27:30.671815 2026] [authz_core:error] [pid 93601:tid 93 ...
show more
AetherFox VoidGuard detected: [Thu Oct 01 01:27:30.671815 2026] [authz_core:error] [pid 93601:tid 93653] [client 34.168.121.208:50118] AH01630: client denied by server configuration: proxy:https://136.243.123.86/
[Thu Oct 01 01:27:30.672377 2026] [authz_core:error] [pid 93601:tid 93653] [client 34.168.121.208:50118] AH01630: client denied by server configuration: /var/www/ERRORpages/403.html
[Thu Oct 01 01:27:30.823887 2026] [authz_core:error] [pid 93601:tid 93630] [client 34.168.121.208:50118] AH01630: client denied by server configuration: proxy:https://136.243.123.86/signin
[Thu Oct 01 01:27:30.824005 2026] [authz_core:error] [pid 93601:tid 93630] [client 34.168.121.208:50118] AH01630: client denied by server configuration: /var/www/ERRORpages/403.html
[Thu Oct 01 01:27:30.973707 2026] [authz_core:error] [pid 93601:tid 93631] [client 34.168.121.208:50118] AH01630: client denied by server configuration: proxy:https://136.243.123.86/users/login
...
show less
Bad Web Bot
Web App Attack
๐ซ๐ท
Sorgin Informatique
2026-09-30 22:54:17
(1 day ago)
nee-10 : Block HTTP using HEAD/TRACE/DELETE/TRACK methods=>/inngest(DELETE)
Hacking
๐ง๐ท
radardatelecom
2026-09-30 22:26:03
(1 day ago)
Blocked by Radar da Telecom firewall โ abuseipdb
Bad Web Bot
Web App Attack
Anonymous
2026-09-30 22:07:56
(1 day ago)
34.168.121.208 - - [30/Sep/2026:22:07:55 +0000] "POST /cgi-bin/php-cgi.exe?%ADd+allow_url_include%3d ...
show more
34.168.121.208 - - [30/Sep/2026:22:07:55 +0000] "POST /cgi-bin/php-cgi.exe?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input HTTP/1.1" 404 152 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
34.168.121.208 - - [30/Sep/2026:22:07:55 +0000] "POST /cgi-bin/php?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input HTTP/1.1" 404 152 "-" "CCBot/2.0 (https://commoncrawl.org/faq/)"
34.168.121.208 - - [30/Sep/2026:22:07:55 +0000] "POST /cgi-bin/php-cgi?-d+allow_url_include%3don+-d+auto_prepend_file%3dphp://input HTTP/1.1" 404 152 "-" "Mozilla/5.0 (compatible; Bytespider; [email protected] ) AppleWebKit/537.36"
...
show less
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-30 21:42:42
(1 day ago)
[backup01al] Web exploit scanning: 3 suspicious requests detected by fail2ban jail apache-scanner. E ...
show more
[backup01al] Web exploit scanning: 3 suspicious requests detected by fail2ban jail apache-scanner. Example: 34.168.121.208 - - [30/Sep/2026:23:42:34 +0200] "GET /static../.env HTTP/2.0" 403 346 "-" "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)"
...
show less
Bad Web Bot
Web App Attack
๐ณ๐ด
Abuse Buster
2026-09-30 21:28:33
(1 day ago)
34.168.121.208 - - [30/Sep/2026:23:28:30 +0200] "GET /ppmdwmozme7d5x23oz85 HTTP/2.0" 404 22 "-" "Moz ...
show more
34.168.121.208 - - [30/Sep/2026:23:28:30 +0200] "GET /ppmdwmozme7d5x23oz85 HTTP/2.0" 404 22 "-" "Mozilla/5.0 (compatible; Bravebot/1.0; +https://brave.com/search/)"
34.168.121.208 - - [30/Sep/2026:23:28:30 +0200] "GET /model/info HTTP/2.0" 404 22 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot"
34.168.121.208 - - [30/Sep/2026:23:28:30 +0200] "GET /oy6pu6xdsv1q6mw8a866 HTTP/2.0" 404 22 "-" "Mozilla/5.0 (compatible; Hunyuan/1.0; +https://hunyuan.tencent.com/)"
...
show less
Web App Attack
๐ฌ๐ง
consul.to
2026-09-30 20:51:19
(1 day ago)
Web attack/malicious scanning detected
Web App Attack