๐ญ๐ฐ
pengpeng
2026-09-16 16:38:46
(3 hours ago)
monitor: on ser162528253480 | port: 443 | ttl: 52 script: github.com/sefinek/UFW-AbuseIPDB-Reporter
Port Scan
Anonymous
2026-09-16 16:29:00
(3 hours ago)
Malicious Probing
Bad Web Bot
Anonymous
2026-09-16 16:28:57
(3 hours ago)
[16/Sep/2026:16:28:56 +0000] host=213.32.24.28 server=_ ip=34.23.43.31 method=GET req=/static../.env ...
show more
[16/Sep/2026:16:28:56 +0000] host=213.32.24.28 server=_ ip=34.23.43.31 method=GET req=/static../.env uri=/static../.env status=301 bytes=162 rt=0.000 urt=- ref="-" ua="Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:78.5) Gecko/20100101 Firefox/78.5; compatible; ChatGPT-User/1.0; +https://openai.com/bot"
...
show less
Web App Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-16 16:12:59
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.23.43.31 (31.43.23.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.23.43.31 (31.43.23.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 12:12:54.187050 2026] [security2:error] [pid 31138:tid 31138] [client 34.23.43.31:60156] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.151.13"] [uri "/static../.env"] [unique_id "aqrABgHVahZkwnzVesicwAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
sc user
2026-09-16 16:12:44
(4 hours ago)
Fail2Ban nginx: repeated suspicious HTTP requests consistent with automated probing, scanning or bad ...
show more
Fail2Ban nginx: repeated suspicious HTTP requests consistent with automated probing, scanning or bad bot behaviour. Technical log details and local server identifiers intentionally omitted for privacy.
show less
Bad Web Bot
Web App Attack
Port Scan
๐ณ๐ฑ
bazter.pro
2026-09-16 16:12:43
(4 hours ago)
34.23.43.31 - - [16/Sep/2026:16:12:42 +0000] "GET /static../.env HTTP/1.1" 404 301 "-" "Mozilla/5.0 ...
show more
34.23.43.31 - - [16/Sep/2026:16:12:42 +0000] "GET /static../.env HTTP/1.1" 404 301 "-" "Mozilla/5.0 (Linux; Android 13; Pixel 7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/130.0.5510.222 Mobile Safari/537.36; compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot"
...
show less
Port Scan
Brute-Force
Bad Web Bot
Web App Attack
SSH
๐ฎ๐ฉ
Burayot
2026-09-16 15:57:32
(4 hours ago)
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 34.23.43.31 (US/United States/31.43. ...
show more
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 34.23.43.31 (US/United States/31.43.23.34.bc.googleusercontent.com): 2 in the last 3600 secs
show less
Web App Attack
๐บ๐ธ
kosada.com
2026-09-16 15:55:02
(4 hours ago)
Repeated requests for suspicious nonexistent URLs, for example: /@fs/home/ec2-user/.aws/credentials? ...
show more
Repeated requests for suspicious nonexistent URLs, for example: /@fs/home/ec2-user/.aws/credentials?raw?? (HTTP/1.1 port 80, bogus vhost, user agent: "Mozilla/5.0 (iPhone; CPU iPhone OS 18_4 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/19.7 Mobile/15E148 Safari/604.1; compatible; Amzn-SearchBot/1.0; +https://developer.amazon.com/support/amazonbot")
show less
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-16 15:54:05
(4 hours ago)
[ti-04al] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail apac ...
show more
[ti-04al] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail apache-404. Example: 34.23.43.31 - - [16/Sep/2026:17:53:25 +0200] "GET /static../.env HTTP/1.1" 404 891 "-" "Mozilla/5.0 (Linux; Android 14; Pixel 8) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.8062.25 Mobile Safari/537.36; compatible; Claude-User/1.0; [email protected] "
34.23.43.31 - - [16/Sep/2026:17:53:25 +0200] "GET /.azure/credentials HTTP/1.1" 404 363 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.5212.145 Safari/537.36 Edg/109.0.5212.145; compatible; Discordbot/2.0; +https://discordapp.com"
34.23.43.31 - - [16/Sep/2026:17:53:36 +0200] "GET /@fs/home/ec2-user/.aws/credentials?raw?? HTTP/1.1" 404 6067 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14_6_1) AppleWebKit/537.36 (KH
...
show less
Bad Web Bot
Web App Attack
Anonymous
2026-09-16 15:53:29
(4 hours ago)
34.23.43.31 - - [16/Sep/2026:10:53:26 -0500] "GET /.env.local HTTP/1.1" 404 1288 "-" "Mozilla/5.0 (L ...
show more
34.23.43.31 - - [16/Sep/2026:10:53:26 -0500] "GET /.env.local HTTP/1.1" 404 1288 "-" "Mozilla/5.0 (Linux; Android 12; Pixel 6) AppleWebKit/537.36 (KHTML, like Gecko; compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot) Chrome/130.0.8428.183 Mobile Safari/537.36"
34.23.43.31 - - [16/Sep/2026:10:53:27 -0500] "GET /.env HTTP/1.1" 404 1288 "-" "Mozilla/5.0 (Linux; Android 12; Pixel 6) AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; [email protected] ) Chrome/128.0.6828.84 Mobile Safari/537.36"
34.23.43.31 - - [16/Sep/2026:10:53:27 -0500] "GET /actuator/env HTTP/1.1" 404 1288 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko; compatible; Slackbot-LinkExpanding/1.0; +https://api.slack.com/robots) Chrome/148.0.1383.105 Safari/537.36"
...
show less
Bad Web Bot
๐ฉ๐ช
larse99
2026-09-16 15:53:05
(4 hours ago)
Detected Scanning / Hacking activity
Port Scan
Hacking
๐บ๐ธ
etu brutus
2026-09-16 15:53:03
(4 hours ago)
34.23.43.31 Blocked by [Attack Vector List]
...
Hacking
Brute-Force
Exploited Host
๐ซ๐ท
abuseipdb_reporter
2026-09-16 15:24:24
(4 hours ago)
34.23.43.31 - - [16/Sep/2026:17:20:53 +0200] "GET / HTTP/1.1" 400 248 "-" "Mozilla/5.0 (Windows NT 1 ...
show more
34.23.43.31 - - [16/Sep/2026:17:20:53 +0200] "GET / HTTP/1.1" 400 248 "-" "Mozilla/5.0 (Windows NT 10.0; rv:150.19) Gecko/20100101 Firefox/150.19; compatible; ChatGPT-User/1.0; +https://openai.com/bot"
34.23.43.31 - - [16/Sep/2026:17:22:32 +0200] "GET /assets../../../etc/passwd HTTP/1.1" 400 150 "-" "-"
34.23.43.31 - - [16/Sep/2026:17:24:23 +0200] "GET /assets../../../.env HTTP/1.1" 400 150 "-" "-"
...
show less
Web App Attack
๐บ๐ธ
Victor Lรณpez
2026-09-16 15:23:15
(4 hours ago)
_ 34.23.43.31 - - [16/Sep/2026:10:21:58 -0500] "GET /assets../../../.env HTTP/1.1" 400 150 "-" "-" - ...
show more
_ 34.23.43.31 - - [16/Sep/2026:10:21:58 -0500] "GET /assets../../../.env HTTP/1.1" 400 150 "-" "-" -
_ 34.23.43.31 - - [16/Sep/2026:10:23:13 -0500] "GET ////../.env HTTP/1.1" 400 150 "-" "-" -
_ 34.23.43.31 - - [16/Sep/2026:10:23:14 -0500] "GET /%2e%2e/%2e%2e/.env HTTP/1.1" 400 150 "-" "-" -
...
show less
Hacking
Web App Attack
๐ท๐บ
genokrad
2026-09-16 15:21:13
(4 hours ago)
Website scan TCP 80/443 "/" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; "
Port Scan
Web App Attack