๐ฉ๐ช
klaus_ph
2026-09-23 15:51:39
(1 day ago)
2026-09-23 01:53:44,262 fail2ban.actions [535885]: NOTICE [ipblocklist] Ban 34.187.170.88
.. ...
show more
2026-09-23 01:53:44,262 fail2ban.actions [535885]: NOTICE [ipblocklist] Ban 34.187.170.88
...
show less
Bad Web Bot
๐บ๐ธ
nasset
2026-09-20 15:18:38
(4 days ago)
34.187.170.88 - - [20/Sep/2026:08:18:37 -0700] "GET /public/.env HTTP/1.1" 403 584 "-" "Mozilla/5.0 ...
show more
34.187.170.88 - - [20/Sep/2026:08:18:37 -0700] "GET /public/.env HTTP/1.1" 403 584 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
34.187.170.88 - - [20/Sep/2026:08:18:37 -0700] "GET /.gitlab-ci.yml HTTP/1.1" 403 584 "-" "Mozilla/5.0 (compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot)"
34.187.170.88 - - [20/Sep/2026:08:18:37 -0700] "GET /infra/.env HTTP/1.1" 403 584 "-" "Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; +https://kimi.ai/)"
34.187.170.88 - - [20/Sep/2026:08:18:37 -0700] "GET /.env.save HTTP/1.1" 403 584 "-" "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)"
34.187.170.88 - - [20/Sep/2026:08:18:37 -0700] "GET /.github/workflows/deploy.yml HTTP/1.1" 403 584 "-" "CCBot/2.0 (https://commoncrawl.org/faq/)"
...
show less
Bad Web Bot
Web App Attack
๐ซ๐ท
Sorgin Informatique
2026-09-20 15:11:26
(4 days ago)
nee-88 : Bloc AI bots=>/__/firebase/init.json(.ai)
Hacking
๐ฌ๐ง
consul.to
2026-09-20 15:09:58
(4 days ago)
Web attack/malicious scanning detected
Web App Attack
๐ท๐บ
DZBOT
2026-09-20 14:54:47
(4 days ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 14:50:31
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.187.170.88 (88.170.187.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.187.170.88 (88.170.187.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 10:50:27.117734 2026] [security2:error] [pid 23532:tid 23532] [client 34.187.170.88:39444] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nanchy.net"] [uri "/.env.backup"] [unique_id "aq_ys-pvX5H7WZfJx_CKPwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ger-stg-sifi1
2026-09-20 14:50:01
(4 days ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 14:22:09
(4 days ago)
(mod_security) mod_security (id:210730) triggered by 34.187.170.88 (88.170.187.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.187.170.88 (88.170.187.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 10:22:00.836074 2026] [security2:error] [pid 22039:tid 22039] [client 34.187.170.88:60400] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mydobdate.net|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mydobdate.net"] [uri "/rclone.conf"] [unique_id "aq_sCNupMUyAnJ9NhoEo0wAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-09-20 14:20:52
(4 days ago)
Restricted File Access Attempt. Matched phrase "config.json" at REQUEST_FILENAME. (930130-195)
Hacking
Web App Attack
๐บ๐ธ
mnsf
2026-09-20 14:05:24
(4 days ago)
Too many Status 40X (13)
Brute-Force
Web App Attack
๐ซ๐ฎ
oh.mg
2026-09-20 13:56:26
(4 days ago)
34.187.170.88 - - [20/Sep/2026:15:56:14 +0200] "GET /config.js HTTP/1.1" 403 498 "-" "Mozilla/5.0 Ap ...
show more
34.187.170.88 - - [20/Sep/2026:15:56:14 +0200] "GET /config.js HTTP/1.1" 403 498 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; [email protected] )"
34.187.170.88 - - [20/Sep/2026:15:56:18 +0200] "GET /.well-known/jwks.json HTTP/1.1" 403 498 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; [email protected] )"
34.187.170.88 - - [20/Sep/2026:15:56:24 +0200] "GET /configuration.js HTTP/1.1" 403 498 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; [email protected] )"
34.187.170.88 - - [20/Sep/2026:15:56:25 +0200] "GET /settings.js HTTP/1.1" 403 498 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
34.187.170.88 - - [20/Sep/2026:15:56:25 +0200] "GET /environment.js HTTP/1.1" 403 498 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 13:53:59
(4 days ago)
(mod_security) mod_security (id:210730) triggered by 34.187.170.88 (88.170.187.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.187.170.88 (88.170.187.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 09:53:52.650662 2026] [security2:error] [pid 2899277:tid 2899277] [client 34.187.170.88:50914] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mphq.net|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mphq.net"] [uri "/rclone.conf"] [unique_id "aq_lcEF6JUWZCE4o2E18AQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 13:38:14
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.187.170.88 (88.170.187.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.187.170.88 (88.170.187.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 09:38:08.789181 2026] [security2:error] [pid 23628:tid 23628] [client 34.187.170.88:39862] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "monteriggioni.net"] [uri "/admin/.env"] [unique_id "aq_hwLdq5mukgEFnBvsB0wAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Tamsy
2026-09-20 13:30:17
(4 days ago)
HTTPD - 4xx scan
Web App Attack
๐บ๐ธ
magnetosphere-tarpit
2026-09-20 13:15:02
(4 days ago)
Automated web scanner: repeatedly probed for .env, .git, wp-admin and PHP webshell paths that do not ...
show more
Automated web scanner: repeatedly probed for .env, .git, wp-admin and PHP webshell paths that do not exist on this host. Tarpitted, then banned: 10 requests within 24h0m0s
show less
Port Scan
Bad Web Bot
Web App Attack