๐ฉ๐ช
klaus_ph
2026-09-23 01:49:01
(13 hours ago)
2026-09-22 06:30:45,496 fail2ban.actions [3721954]: NOTICE [ipblocklist] Ban 34.21.239.151
. ...
show more
2026-09-22 06:30:45,496 fail2ban.actions [3721954]: NOTICE [ipblocklist] Ban 34.21.239.151
...
show less
Bad Web Bot
๐ฉ๐ช
klaus_ph
2026-09-22 09:34:03
(1 day ago)
2026-09-21 23:30:01,744 fail2ban.actions [1549]: NOTICE [ipblocklist] Ban 34.21.239.151
...
Bad Web Bot
๐ฎ๐ณ
evicky2002
2026-09-22 06:00:01
(1 day ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐บ๐ธ
Charlesiv
2026-09-21 10:03:13
(2 days ago)
Triggered Cloudflare WAF (firewallCustom) from SG.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Prot ...
show more
Triggered Cloudflare WAF (firewallCustom) from SG.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Protocol: HTTP/2 (GET method)
Endpoint: /actuator/heapdump
Timestamp: 2026-09-21T05:40:21Z
Ray ID: a3e6bc107a1d41d7
UA: Mozilla/5.0 (compatible; KimiBot/1.0; +https://kimi.ai/)
show less
Bad Web Bot
๐บ๐ธ
valornode
2026-09-21 06:32:08
(2 days ago)
Detected by CrowdSec on www.iambrayden.net-47d88224: CrowdSec: crowdsecurity/thinkphp-cve-2018-20062 ...
show more
Detected by CrowdSec on www.iambrayden.net-47d88224: CrowdSec: crowdsecurity/thinkphp-cve-2018-20062 | ASN: 396982 (GOOGLE-CLOUD-PLATFORM) | Country: SG | Range: 34.16.0.0/12
show less
Brute-Force
SSH
๐ณ๐ฑ
Savvii
2026-09-21 06:21:12
(2 days ago)
20 attempts against mh-misbehave-ban on redirect
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
pscriptos
2026-09-21 04:57:40
(2 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-path-traversal-probing
Web App Attack
Hacking
๐ฌ๐ง
Andrew
2026-09-21 04:44:42
(2 days ago)
34.21.239.151 - - [21/Sep/2026:05:44:23 +0100] "GET /admin%2F.env HTTP/1.1" 404 491 "-" "Mozilla/5.0 ...
show more
34.21.239.151 - - [21/Sep/2026:05:44:23 +0100] "GET /admin%2F.env HTTP/1.1" 404 491 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot"
34.21.239.151 - - [21/Sep/2026:05:44:24 +0100] "GET /dashboard%2F.env HTTP/1.1" 404 491 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot)"
34.21.239.151 - - [21/Sep/2026:05:44:24 +0100] "GET /settings%2F.env HTTP/1.1" 404 491 "-" "Mozilla/5.0 (compatible; MoonshotBot/1.0; +https://kimi.ai/)"
34.21.239.151 - - [21/Sep/2026:05:44:24 +0100] "GET /api%2F.env HTTP/1.1" 404 491 "-" "Mozilla/5.0 (compatible; Qwenbot/1.0; +https://qwen.alibaba.com/)"
34.21.239.151 - - [21/Sep/2026:05:44:25 +0100] "GET /api/uploads/%2e%2e%2f%2e%2e%2f.env HTTP/1.1" 404 491 "-" "Mozilla/5.0 (compatible; MistralAI-User/1.0; +https://mistral.ai/)"
34.21.239.151 - - [21/Sep/2026:05:44:41 +0100] "POST /lib/terminal-xhr.php HTTP/1.1" 404 557 "-" "Mozil
...
show less
Hacking
Web App Attack
๐ฉ๐ช
itsolon
2026-09-21 03:38:10
(2 days ago)
[21/Sep/2026:05:38:09 +0200] 178996188974.486058 34.21.239.151 50030 217.154.7.177 443
[21/Sep/2026: ...
show more
[21/Sep/2026:05:38:09 +0200] 178996188974.486058 34.21.239.151 50030 217.154.7.177 443
[21/Sep/2026:05:38:09 +0200] 178996188927.778770 34.21.239.151 50030 217.154.7.177 443
[21/Sep/2026:05:38:09 +0200] 178996188934.068849 34.21.239.151 50030 217.154.7.177 443
[21/Sep/2026:05:38:09 +0200] 178996188915.282031 34.21.239.151 50030 217.154.7.177 443
[21/Sep/2026:05:38:10 +0200] 178996189049.079109 34.21.239.151 50030 217.154.7.177 443
...
show less
Port Scan
Hacking
Brute-Force
Web App Attack
๐ซ๐ฎ
oh.mg
2026-09-21 03:33:09
(2 days ago)
[Mon Sep 21 05:33:08.355444 2026] [security2:error] [pid 1339174:tid 1339189] [client 34.21.239.151: ...
show more
[Mon Sep 21 05:33:08.355444 2026] [security2:error] [pid 1339174:tid 1339189] [client 34.21.239.151:0] [client 34.21.239.151] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 15)"] [ver "OWASP_CRS/4.10.0-dev"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "intl.mmn.ca"] [uri "/api/v1/validate/code"] [unique_id "arCldFuWWJkQ6cWSb53pbwAAAE0"]
[Mon Sep 21 05:33:08.976012 2026] [security2:error] [pid 1339174:tid 1339190] [client 34.21.239.151:0] [client 34.21.239.151] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [ver "OWASP_CRS/4.10.0-dev"]
...
show less
Web App Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-21 03:30:37
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.21.239.151 (151.239.21.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.21.239.151 (151.239.21.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 23:30:29.970696 2026] [security2:error] [pid 15133:tid 15133] [client 34.21.239.151:34078] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.catking.net"] [uri "/.env.local"] [unique_id "arCk1TBEwUODSaSG9zJT9wAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
mzaiser12
2026-09-21 02:56:15
(2 days ago)
Web application probing: 99 requests to typical attack paths (/assets/.env, /auth/.env, /cmd/.env, / ...
show more
Web application probing: 99 requests to typical attack paths (/assets/.env, /auth/.env, /cmd/.env, /.github/.env) within 5 min. Reported automatically by a SIEM; contact via abuse mailbox of the reporting network.
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
webanyone
2026-09-21 02:46:42
(2 days ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
๐บ๐ธ
Charlesiv
2026-09-21 02:11:53
(2 days ago)
Triggered Cloudflare WAF (firewallCustom) from SG.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Prot ...
show more
Triggered Cloudflare WAF (firewallCustom) from SG.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Protocol: HTTP/2 (GET method)
Endpoint: /.env.local
Query: ?import&raw
Timestamp: 2026-09-21T00:43:34Z
Ray ID: a3e509538ae749f3
UA: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; [email protected] )
show less
Bad Web Bot
๐ซ๐ฎ
kumiko
2026-09-21 01:23:37
(2 days ago)
[2026-09-21 04:23:36] User-Agent Spoofing (6 unique User-Agent strings from the same IP address with ...
show more
[2026-09-21 04:23:36] User-Agent Spoofing (6 unique User-Agent strings from the same IP address within 0 seconds)
show less
Bad Web Bot