๐ฌ๐ง
noise.agency
2026-09-24 14:27:34
(2 hours ago)
34.177.84.228 (SG/Singapore/228.84.177.34.bc.googleusercontent.com), more than 10 Apache 403 hits
Hacking
๐ซ๐ท
dynamix
2026-09-24 12:35:15
(4 hours ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
[email protected]
2026-09-24 11:27:22
(5 hours ago)
CrowdSec ban: crowdsecurity/unifi-flood-detection (duration: 71h59m55s)
Port Scan
๐ฉ๐ช
AetherFox
2026-09-24 09:06:53
(8 hours ago)
AetherFox VoidGuard detected: [Thu Sep 24 09:06:51.839537 2026] [authz_core:error] [pid 3856107:tid ...
show more
AetherFox VoidGuard detected: [Thu Sep 24 09:06:51.839537 2026] [authz_core:error] [pid 3856107:tid 3856146] [client 34.177.84.228:38382] AH01630: client denied by server configuration: proxy:https://[MASKED]/
[Thu Sep 24 09:06:52.236913 2026] [authz_core:error] [pid 3856107:tid 3856144] [client 34.177.84.228:38382] AH01630: client denied by server configuration: proxy:https://[MASKED]/3cyj8eer73qn6z14fqb0
[Thu Sep 24 09:06:52.640130 2026] [authz_core:error] [pid 3856107:tid 3856114] [client 34.177.84.228:38390] AH01630: client denied by server configuration: proxy:https://[MASKED]/dhusy9tjvvvebw4u6o56
[Thu Sep 24 09:06:52.641450 2026] [authz_core:error] [pid 3856107:tid 3856122] [client 34.177.84.228:38396] AH01630: client denied by server configuration: proxy:https://[MASKED]/
[Thu Sep 24 09:06:52.769123 2026] [authz_core:error] [pid 3856107:tid 3856115] [client 34.177.84.228:38486] AH01630: client denied by server configuration: proxy:https://5.75.191
...
show less
Bad Web Bot
Web App Attack
๐ฆ๐บ
Starburst SysOp Team
2026-09-24 09:02:16
(8 hours ago)
HTTP header is restricted by policy (/x-middleware-subrequest/). String match within "/content-encod ...
show more
HTTP header is restricted by policy (/x-middleware-subrequest/). String match within "/content-encoding/ /proxy/ /lock-token/ /content-range/ /if/ /x-http-method-override/ /x-http-method/ /x-method-override/ /x-middleware-subrequest/ /expect/" at TX:header_name_920450_x-middleware-subrequest. (920450-syd2-4)
show less
Bad Web Bot
๐บ๐ธ
nasset
2026-09-24 08:15:58
(9 hours ago)
34.177.84.228 - - [24/Sep/2026:01:15:57 -0700] "GET /.env?import&raw HTTP/1.1" 403 584 "-" "Mozilla/ ...
show more
34.177.84.228 - - [24/Sep/2026:01:15:57 -0700] "GET /.env?import&raw HTTP/1.1" 403 584 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Safari/605.1.15 (Applebot/0.1)"
34.177.84.228 - - [24/Sep/2026:01:15:57 -0700] "GET /.env?import&url&inline HTTP/1.1" 403 584 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; [email protected] )"
34.177.84.228 - - [24/Sep/2026:01:15:57 -0700] "GET /.env.local?import&raw HTTP/1.1" 403 584 "-" "Mozilla/5.0 (compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot)"
34.177.84.228 - - [24/Sep/2026:01:15:57 -0700] "GET /auth/login HTTP/1.1" 403 584 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
34.177.84.228 - - [24/Sep/2026:01:15:57 -0700] "GET /sign-in HTTP/1.1" 403 584 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
Charlesiv
2026-09-24 08:00:46
(9 hours ago)
Triggered Cloudflare WAF (firewallCustom) from SG.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Prot ...
show more
Triggered Cloudflare WAF (firewallCustom) from SG.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Protocol: HTTP/2 (GET method)
Endpoint: /proc/self/cmdline
Timestamp: 2026-09-24T07:38:43Z
Ray ID: a40021963cd1df08
UA: Mozilla/5.0 (compatible; YiBot/1.0; +https://01.ai/)
show less
Bad Web Bot
๐ณ๐ฑ
Alt255
2026-09-24 07:28:32
(9 hours ago)
[ti-04al] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail apac ...
show more
[ti-04al] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail apache-404. Example: 34.177.84.228 - - [24/Sep/2026:09:28:21 +0200] "GET /account/login HTTP/2.0" 404 1878 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36"
34.177.84.228 - - [24/Sep/2026:09:28:21 +0200] "GET /signin HTTP/2.0" 404 1855 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36"
34.177.84.228 - - [24/Sep/2026:09:28:21 +0200] "GET /signup HTTP/2.0" 404 1855 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36"
34.177.84.228 - - [24/Sep/2026:09:28:21 +0200] "GET /user/login HTTP/2.0" 404 1855 "-" "Mozilla/5.0 (Windows NT 10.0;
...
show less
Bad Web Bot
Web App Attack
๐ฎ๐ณ
evicky2002
2026-09-24 06:00:03
(11 hours ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
Anonymous
2026-09-24 05:45:22
(11 hours ago)
$f2bV_matches
Brute-Force
๐ฒ๐ฝ
octageeks.com
2026-09-24 04:23:09
(12 hours ago)
Wordpress malicious attack:[octamissingdomain]
Web App Attack
๐ฎ๐น
eliosbrocchi
2026-09-24 04:10:16
(13 hours ago)
34.177.84.228 - - [24/Sep/2026:06:10:14 +0200] "GET /rclone.conf HTTP/2.0" 404 264 "-" "Mozilla/5.0 ...
show more
34.177.84.228 - - [24/Sep/2026:06:10:14 +0200] "GET /rclone.conf HTTP/2.0" 404 264 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; GPTBot/1.4; +https://openai.com/gptbot"
...
show less
VPN IP
๐บ๐ธ
NeverBehave
2026-09-24 04:04:52
(13 hours ago)
[fail2ban] service ocserv jail
Brute-Force
Web App Attack
๐น๐ญ
pothirak
2026-09-24 03:52:00
(13 hours ago)
Web App Attack
๐ฉ๐ช
raph
2026-09-24 02:28:36
(14 hours ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack