🇺🇸
mnsf
2026-09-10 22:05:43
(2 minutes ago)
Scanning/Probing (13)
Brute-Force
Web App Attack
🇬🇧
Marten Mark
2026-09-10 21:31:35
(36 minutes ago)
34.185.95.157 - - [10/Sep/2026:21:31:23 +0000] "GET /.docker/config.json HTTP/2.0" 404 23033 "-" "Mo ...
show more
34.185.95.157 - - [10/Sep/2026:21:31:23 +0000] "GET /.docker/config.json HTTP/2.0" 404 23033 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot)"
34.185.95.157 - - [10/Sep/2026:21:31:23 +0000] "GET /rclone.conf HTTP/2.0" 404 23033 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-SearchBot/1.0; [email protected] )"
34.185.95.157 - - [10/Sep/2026:21:31:23 +0000] "GET /.npmrc HTTP/2.0" 404 23033 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; OAI-SearchBot/1.0; +https://openai.com/searchbot)"
34.185.95.157 - - [10/Sep/2026:21:31:25 +0000] "GET /z9x8c7v6b5-debug-trigger-cfi.co HTTP/2.0" 404 23033 "-" "Mozilla/5.0 (compatible; DeepSeekBot/1.0; +https://www.deepseek.com/)"
34.185.95.157 - - [10/Sep/2026:21:31:25 +0000] "GET /.s3cfg HTTP/2.0" 404 23033 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; [email protected] )"
34.185.
...
show less
Port Scan
Web App Attack
🇩🇪
grassau.com
2026-09-10 21:30:42
(37 minutes ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 34.185.95.157 (US/Un ...
show more
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 34.185.95.157 (US/United States/Utah/Salt Lake City/157.95.185.34.bc.googleusercontent.com)
show less
Bad Web Bot
🇨🇦
Anytech
2026-09-10 21:25:51
(42 minutes ago)
Blocked by ConnMonitor
Web App Attack
🇳🇱
Alboweb B.V.
2026-09-10 21:11:06
(56 minutes ago)
Bad web bot activity detected by Fail2Ban in plesk-apache-badbot jail
Bad Web Bot
🇺🇸
Penny Packer
2026-09-10 20:58:25
(1 hour ago)
Fail2Ban apache-404
Web App Attack
🇺🇸
TPI-Abuse
2026-09-10 20:41:59
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.185.95.157 (157.95.185.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.185.95.157 (157.95.185.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 10 16:41:50.749224 2026] [security2:error] [pid 15635:tid 15635] [client 34.185.95.157:58580] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bigkevsperformance.com"] [uri "/.svn/entries"] [unique_id "aqMWDmq8Vb_cxCW7U88qswAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
big-cloud.nl
2026-09-10 20:33:36
(1 hour ago)
Try to access /.aws/credentials
Web App Attack
Anonymous
2026-09-10 20:08:53
(1 hour ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
🇸🇪
vaia.cloud
2026-09-10 20:00:04
(2 hours ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
Anonymous
2026-09-10 19:55:09
(2 hours ago)
Banned by Fail2Ban on server
Web App Attack
🇫🇷
Baking333
2026-09-10 19:39:33
(2 hours ago)
[redacted] 34.185.95.157 - - [10/Sep/2026:20:39:32 +0100] "GET /.aws/credentials HTTP/1.1" 302 1559 ...
show more
[redacted] 34.185.95.157 - - [10/Sep/2026:20:39:32 +0100] "GET /.aws/credentials HTTP/1.1" 302 1559 0/35399 "-" "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://[redacted]/search/[redacted])" [redacted] 34.185.95.157 - - [10/Sep/2026:20:39:32 +0100] "GET /.git/config HTTP/1.1" 302 6778 0/41543 "-" "Mozilla/5.0 (compatible; KimiBot/1.0; +https://[redacted]/)"
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-10 19:22:29
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.185.95.157 (157.95.185.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.185.95.157 (157.95.185.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 10 15:22:24.349400 2026] [security2:error] [pid 6169:tid 6169] [client 34.185.95.157:54282] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||advantstudio.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "advantstudio.com"] [uri "/z9x8c7v6b5-debug-trigger-advantstudio.com"] [unique_id "aqMDcB56-ZFBkwy1edxzGQAAAAA"], referer: http://advantstudio.com/z9x8c7v6b5-debug-trigger-advantstudio.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Ilop
2026-09-10 19:01:34
(3 hours ago)
[hp-100] 4 unsolicited packets to honeypot ports 8443,80,443,8080 (OCI DShield sensor)
Port Scan