Anonymous
2026-09-23 10:08:15
(2 days ago)
34.182.28.249 - - [22/Sep/2026:07:36:55 -0500] "GET /.env.development HTTP/1.1" 403 199 "-" "Mozilla ...
show more
34.182.28.249 - - [22/Sep/2026:07:36:55 -0500] "GET /.env.development HTTP/1.1" 403 199 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot" 34.182.28.249
34.182.28.249 - - [22/Sep/2026:07:36:55 -0500] "GET /.env.staging HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; Bravebot/1.0; +https://brave.com/search/)" 34.182.28.249
34.182.28.249 - - [22/Sep/2026:07:36:55 -0500] "GET /.env.test HTTP/1.1" 403 199 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Safari/605.1.15 (Applebot/0.1)" 34.182.28.249
34.182.28.249 - - [22/Sep/2026:07:36:56 -0500] "GET /.env.docker HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot)" 34.182.28.249
34.182.28.249 - - [22/Sep/2026:07:36:56 -0500] "GET /.env.production.bak HTTP/1.1" 403 199 "-" "DuckAssistBot/1.1 (https://duckduckgo.com/duckassistbot)" 34.182.28.249
34.182.28.249 - - [22
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ณ
evicky2002
2026-09-23 06:00:01
(3 days ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐ฉ๐ช
Philister11
2026-09-23 01:16:02
(3 days ago)
CrowdSec: crowdsecurity/http-path-traversal-probing (US/AS396982)
Web App Attack
Hacking
๐บ๐ธ
ersei.net
2026-09-22 23:13:37
(3 days ago)
Web app exploiting
Web App Attack
๐ฉ๐ช
s@ch@
2026-09-22 22:15:02
(3 days ago)
Jail: plesk-modsecurity | Web application attack (Plesk ModSecurity)
Web App Attack
๐บ๐ธ
Charlesiv
2026-09-22 22:00:32
(3 days ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Prot ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Protocol: HTTP/2 (GET method)
Endpoint: /@fs/../.env
Query: ?import&raw??
Timestamp: 2026-09-22T21:23:14Z
Ray ID: a3f45e9f6f213167
UA: Mozilla/5.0 (compatible; Google-Extended; +http://www.google.com/bot.html)
show less
Bad Web Bot
๐ณ๐ฑ
oisecnet
2026-09-22 21:03:04
(3 days ago)
Automated report: Unauthorized vulnerability scanning detected on 2026-09-22. 828 requests from this ...
show more
Automated report: Unauthorized vulnerability scanning detected on 2026-09-22. 828 requests from this IP.
show less
Port Scan
Hacking
Web App Attack
๐ณ๐ด
Abuse Buster
2026-09-22 20:47:50
(3 days ago)
34.182.28.249 - [22/Sep/2026:22:47:48 +0200] "GET /dist/.vite/manifest.json HTTP/2.0" 403 548 "-" "M ...
show more
34.182.28.249 - [22/Sep/2026:22:47:48 +0200] "GET /dist/.vite/manifest.json HTTP/2.0" 403 548 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36"
34.182.28.249 - [22/Sep/2026:22:47:48 +0200] "GET /.vite/manifest.json HTTP/2.0" 403 548 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36"
34.182.28.249 - [22/Sep/2026:22:47:48 +0200] "GET /n1vzux3wz3vbw96oyt5w HTTP/2.0" 404 1862 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; GPTBot/1.4; +https://openai.com/gptbot"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 20:30:43
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 34.182.28.249 (249.28.182.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.182.28.249 (249.28.182.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 16:30:39.203876 2026] [security2:error] [pid 2601:tid 2601] [client 34.182.28.249:0] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.thectegroup.net|F|2"] [data ".key"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.thectegroup.net"] [uri "/config/master.key"] [unique_id "arLlb29id1SY-xeriTqX4wAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
pscriptos
2026-09-22 20:28:29
(3 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐ต๐ฑ
sefinek.net
2026-09-22 20:15:26
(3 days ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action: BLOCK | Protocol: HTTP/2 (GET) | Endpoint ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action: BLOCK | Protocol: HTTP/2 (GET) | Endpoint: /files../.env | UA: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot โข Generated by: github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-22 20:10:29
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.182.28.249 (249.28.182.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.182.28.249 (249.28.182.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 16:10:24.557081 2026] [security2:error] [pid 16564:tid 16564] [client 34.182.28.249:43946] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/Web.config" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.robotrodeo.net"] [uri "/web.config"] [unique_id "arLgsFVCSAzxBnpQJGuzYQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
magnetosphere-tarpit
2026-09-22 19:37:13
(3 days ago)
Automated web scanner: repeatedly probed for .env, .git, wp-admin and PHP webshell paths that do not ...
show more
Automated web scanner: repeatedly probed for .env, .git, wp-admin and PHP webshell paths that do not exist on this host. Tarpitted, then banned: 10 requests within 24h0m0s
show less
Port Scan
Bad Web Bot
Web App Attack
Anonymous
2026-09-22 19:36:54
(3 days ago)
Aggressive web scan
Web App Attack
๐ต๐ฑ
MatStef132
2026-09-22 19:02:24
(3 days ago)
MatShield L7: blocked on fivevault.net (suspicious behaviour)
DDoS Attack