๐ฉ๐ช
klaus_ph
2026-09-27 03:13:55
(21 hours ago)
2026-09-26 00:39:52,636 fail2ban.actions [594716]: NOTICE [ipblocklist] Ban 34.168.139.6
...
Bad Web Bot
๐ฉ๐ช
klaus_ph
2026-09-23 14:45:47
(4 days ago)
2026-09-23 01:21:15,412 fail2ban.actions [535885]: NOTICE [ipblocklist] Ban 34.168.139.6
...
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-20 15:24:57
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.168.139.6 (6.139.168.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.168.139.6 (6.139.168.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 11:24:52.636788 2026] [security2:error] [pid 12191:tid 12191] [client 34.168.139.6:52922] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "frootloops.net"] [uri "/api/.env"] [unique_id "aq_6xHlUFlfwyZwv9G7OZQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 14:57:12
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.168.139.6 (6.139.168.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.168.139.6 (6.139.168.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 10:57:08.069429 2026] [security2:error] [pid 31870:tid 31958] [client 34.168.139.6:53294] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "emmaryan.net"] [uri "/.git/config"] [unique_id "aq_0RH5BVSQSo7CrEc_UAwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฟ๐ฆ
conure.sh
2026-09-20 14:45:29
(1 week ago)
csagent: score 20.7: 404 noise floor x3, secrets grab x2; 1 domain(s) in 1s
Web App Attack
๐ฉ๐ช
AetherFox
2026-09-20 14:43:39
(1 week ago)
AetherFox VoidGuard detected: [Sun Sep 20 14:43:38.372790 2026] [authz_core:error] [pid 3234461:tid ...
show more
AetherFox VoidGuard detected: [Sun Sep 20 14:43:38.372790 2026] [authz_core:error] [pid 3234461:tid 3234490] [client 34.168.139.6:39814] AH01630: client denied by server configuration: proxy:https://[MASKED]/
[Sun Sep 20 14:43:38.689892 2026] [authz_core:error] [pid 3234461:tid 3234480] [client 34.168.139.6:39814] AH01630: client denied by server configuration: proxy:https://[MASKED]/
[Sun Sep 20 14:43:38.842686 2026] [authz_core:error] [pid 3234461:tid 3234471] [client 34.168.139.6:39814] AH01630: client denied by server configuration: proxy:https://[MASKED]/__/firebase/init.json
[Sun Sep 20 14:43:38.995993 2026] [authz_core:error] [pid 3234461:tid 3234475] [client 34.168.139.6:39816] AH01630: client denied by server configuration: proxy:https://[MASKED]/env.js
[Sun Sep 20 14:43:38.996530 2026] [authz_core:error] [pid 3234461:tid 3234476] [client 34.168.139.6:39814] AH01630: client denied by server configuration: proxy:https://[MASKED]/api/v2/config
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 14:40:45
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.168.139.6 (6.139.168.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.168.139.6 (6.139.168.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 10:40:42.390854 2026] [security2:error] [pid 12104:tid 12104] [client 34.168.139.6:34074] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "doctorc.net"] [uri "/.git/HEAD"] [unique_id "aq_was9R12UdCUx0VWO8TAAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
todix
2026-09-20 14:36:00
(1 week ago)
WebAttack or semilar from 34.168.139.6
Web App Attack
๐ณ๐ฑ
Savvii
2026-09-20 14:32:05
(1 week ago)
20 attempts against mh-misbehave-ban on redirect
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-09-20 14:20:13
(1 week ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 14:16:45
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 34.168.139.6 (6.139.168.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.168.139.6 (6.139.168.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 10:16:39.692949 2026] [security2:error] [pid 6159:tid 6159] [client 34.168.139.6:42920] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||crazycoin.net|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "crazycoin.net"] [uri "/rclone.conf"] [unique_id "aq_qxyfOWFJybbX-DySLCAAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
yitzhaq
2026-09-20 14:10:51
(1 week ago)
34.168.139.6 - - [20/Sep/2026:16:10:48 +0200] "GET /api/settings HTTP/2.0" 404 293 "-" "Mozilla/5.0 ...
show more
34.168.139.6 - - [20/Sep/2026:16:10:48 +0200] "GET /api/settings HTTP/2.0" 404 293 "-" "Mozilla/5.0 (compatible; MoonshotBot/1.0; +https://kimi.ai/)"
34.168.139.6 - - [20/Sep/2026:16:10:48 +0200] "GET /firebase-config.json HTTP/2.0" 404 293 "-" "Mozilla/5.0 (compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot)"
34.168.139.6 - - [20/Sep/2026:16:10:48 +0200] "GET /app_dev.php HTTP/2.0" 404 83 "-" "Mozilla/5.0 (compatible; xAI-Grok/1.0; +https://x.ai/)"
34.168.139.6 - - [20/Sep/2026:16:10:48 +0200] "GET /scripts/.env HTTP/2.0" 404 293 "-" "Mozilla/5.0 (compatible; MoonshotBot/1.0; +https://kimi.ai/)"
34.168.139.6 - - [20/Sep/2026:16:10:48 +0200] "GET /src/.env HTTP/2.0" 404 293 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; GPTBot/1.4; +https://openai.com/gptbot"
34.168.139.6 - - [20/Sep/2026:16:10:48 +0200] "GET /env.json HTTP/2.0" 403 296 "-" "Mozilla/5.0 (compatible; cohere-ai; +https://cohere.com/crawler)"
34.168.139.6 - - [20/Sep/2026:16:1
show less
Bad Web Bot
๐ฉ๐ช
Sรฉfora Srl
2026-09-20 14:01:13
(1 week ago)
crowdsecurity/http-bad-user-agent detected by CrowdSec
Bad Web Bot
๐ซ๐ท
masterguru
2026-09-20 13:48:55
(1 week ago)
BAD BOT - Detected and Blocked.. Matched phrase "PerplexityBot" at REQUEST_HEADERS:user-agent. (1100 ...
show more
BAD BOT - Detected and Blocked.. Matched phrase "PerplexityBot" at REQUEST_HEADERS:user-agent. (1100000-131)
show less
Bad Web Bot
๐ซ๐ท
masterguru
2026-09-20 13:13:19
(1 week ago)
BAD BOT - Detected and Blocked.. Matched phrase "baidu" at REQUEST_HEADERS:User-Agent. (1100000-196)
Bad Web Bot