๐ฉ๐ช
klaus_ph
2026-09-23 01:38:46
(4 days ago)
2026-09-22 06:24:09,262 fail2ban.actions [3721954]: NOTICE [ipblocklist] Ban 34.21.162.84
.. ...
show more
2026-09-22 06:24:09,262 fail2ban.actions [3721954]: NOTICE [ipblocklist] Ban 34.21.162.84
...
show less
Bad Web Bot
๐ฉ๐ช
klaus_ph
2026-09-22 09:31:52
(5 days ago)
2026-09-21 23:27:50,216 fail2ban.actions [1549]: NOTICE [ipblocklist] Ban 34.21.162.84
...
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-20 15:25:46
(6 days ago)
(mod_security) mod_security (id:210730) triggered by 34.21.162.84 (84.162.21.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.21.162.84 (84.162.21.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 11:25:37.845040 2026] [security2:error] [pid 12356:tid 12378] [client 34.21.162.84:45960] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||kiwimagic.net|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "kiwimagic.net"] [uri "/rclone.conf"] [unique_id "aq_68XxC0kT9B5KaHY8O3AAAAJU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
alexbfr
2026-09-20 14:59:56
(6 days ago)
Fail2Ban report from nginx-bot-trap; automated HTTP honeypot detection.
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 14:52:06
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 34.21.162.84 (84.162.21.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.21.162.84 (84.162.21.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 10:51:58.851865 2026] [security2:error] [pid 10847:tid 10847] [client 34.21.162.84:45370] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "intersession.net"] [uri "/agent/.env"] [unique_id "aq_zDuQy-EmCrEgyxUGGbgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Charlesiv
2026-09-20 14:34:21
(6 days ago)
Triggered Cloudflare WAF (firewallCustom) from SG.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Prot ...
show more
Triggered Cloudflare WAF (firewallCustom) from SG.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Protocol: HTTP/2 (GET method)
Endpoint: /info.php
Timestamp: 2026-09-20T12:41:41Z
Ray ID: a3e0e7e3ef79fcf8
UA: Mozilla/5.0 (compatible; xAI-Grok/1.0; +https://x.ai/)
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-20 14:33:10
(6 days ago)
(mod_security) mod_security (id:210730) triggered by 34.21.162.84 (84.162.21.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.21.162.84 (84.162.21.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 10:33:06.941329 2026] [security2:error] [pid 15916:tid 15916] [client 34.21.162.84:42462] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||iberhome.net|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "iberhome.net"] [uri "/rclone.conf"] [unique_id "aq_uojsFi_qAJrXzz8jS5wAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
valornode
2026-09-20 14:32:35
(6 days ago)
Detected by CrowdSec on www.iambrayden.net-47d88224: CrowdSec: crowdsecurity/http-path-traversal-pro ...
show more
Detected by CrowdSec on www.iambrayden.net-47d88224: CrowdSec: crowdsecurity/http-path-traversal-probing | ASN: 396982 (GOOGLE-CLOUD-PLATFORM) | Country: SG | Range: 34.16.0.0/12
show less
Brute-Force
SSH
๐ฉ๐ช
Gwyneth Llewelyn
2026-09-20 14:06:32
(6 days ago)
2026/09/20 15:06:30 [error] 325888#325888: *753804 access forbidden by rule, client: 34.21.162.84, s ...
show more
2026/09/20 15:06:30 [error] 325888#325888: *753804 access forbidden by rule, client: 34.21.162.84, server: gwynethllewelyn.net, request: "GET /apps/.env HTTP/2.0", host: "gwynethllewelyn.net"
2026/09/20 15:06:31 [error] 325888#325888: *753817 access forbidden by rule, client: 34.21.162.84, server: gwynethllewelyn.net, request: "GET /.env HTTP/2.0", host: "gwynethllewelyn.net"
34.21.162.84 - - [20/Sep/2026:15:06:31 +0100] "GET /.env HTTP/2.0" 403 1048 "-" "Mozilla/5.0 (compatible; cohere-ai; +https://cohere.com/crawler)"
show less
Brute-Force
Web App Attack
Anonymous
2026-09-20 14:05:32
(6 days ago)
Banned by Fail2Ban on server
Web App Attack
Anonymous
2026-09-20 13:58:58
(6 days ago)
34.21.162.84 - - [20/Sep/2026:15:58:50 +0200] "GET /test.php HTTP/2.0" 404 106 "-" "Mozilla/5.0 Appl ...
show more
34.21.162.84 - - [20/Sep/2026:15:58:50 +0200] "GET /test.php HTTP/2.0" 404 106 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; GPTBot/1.4; +https://openai.com/gptbot"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 13:58:58
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 34.21.162.84 (84.162.21.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.21.162.84 (84.162.21.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 09:58:52.725855 2026] [security2:error] [pid 26394:tid 26394] [client 34.21.162.84:54312] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "glamorgirl.net"] [uri "/.env.js"] [unique_id "aq_mnIxNeofHph-tZ1x6ZwAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
el-brujo
2026-09-20 13:29:24
(6 days ago)
Cloudflare WAF: Request Path: /debug/pprof/cmdline Request Query: Host: elhacker.net userAgent: Moz ...
show more
Cloudflare WAF: Request Path: /debug/pprof/cmdline Request Query: Host: elhacker.net userAgent: Mozilla/5.0 (compatible; MoonshotBot/1.0; +https://kimi.ai/) Action: block Source: ratelimit ASN Description: Google LLC Country: SG Method: GET Timestamp: 2026-09-20T13:29:24Z ruleId: 11a71ad4659e48b29b5173e3bcc61b4a. Report generated by Cloudflare-WAF-to-AbuseIPDB.
show less
Hacking
SQL Injection
Web App Attack
๐ช๐ธ
el-brujo
2026-09-20 13:29:12
(6 days ago)
34.21.162.84 - - [20/Sep/2026:15:29:12 +0200] "GET /.gitlab-ci.yml HTTP/2.0" 404 15909 "-" "Mozilla/ ...
show more
34.21.162.84 - - [20/Sep/2026:15:29:12 +0200] "GET /.gitlab-ci.yml HTTP/2.0" 404 15909 "-" "Mozilla/5.0 (compatible; MoonshotBot/1.0; +https://kimi.ai/)"
34.21.162.84 - - [20/Sep/2026:15:29:12 +0200] "GET /.gitconfig HTTP/2.0" 404 15909 "-" "Mozilla/5.0 (compatible; ChatGLM-Spider/1.0; +https://zhipuai.cn/)"
34.21.162.84 - - [20/Sep/2026:15:29:12 +0200] "GET /api/config HTTP/2.0" 404 15909 "-" "Mozilla/5.0 (compatible; Hunyuan/1.0; +https://hunyuan.tencent.com/)"
34.21.162.84 - - [20/Sep/2026:15:29:12 +0200] "GET /__/firebase/init.json HTTP/2.0" 404 15909 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36; compatible; OAI-SearchBot/1.4; +https://openai.com/searchbot"
...
show less
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-20 13:24:16
(6 days ago)
(mod_security) mod_security (id:210730) triggered by 34.21.162.84 (84.162.21.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.21.162.84 (84.162.21.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 09:24:08.590797 2026] [security2:error] [pid 18752:tid 18752] [client 34.21.162.84:55812] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||eagleoaks.net|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "eagleoaks.net"] [uri "/rclone.conf"] [unique_id "aq_eeCMA3Yz0Ivtl44V1JwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack