๐ณ๐ฑ
homeshowdomain.nl
2026-10-09 21:59:46
(11 hours ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-10-08.
show less
Web App Attack
SSH
Hacking
๐ช๐ธ
robotstxt
2026-10-09 06:11:34
(1 day ago)
34.38.125.5 - - [09/Oct/2026:04:39:59 +0000] "POST /cgi-bin/php-cgi.exe?%ADd+allow_url_include%3d1+% ...
show more
34.38.125.5 - - [09/Oct/2026:04:39:59 +0000] "POST /cgi-bin/php-cgi.exe?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input HTTP/2.0" 404 16293 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot"
34.38.125.5 - - [09/Oct/2026:04:39:59 +0000] "POST /cgi-bin/php?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input HTTP/2.0" 404 16287 "-" "Mozilla/5.0 (compatible; Meta-ExternalAgent/1.0; +https://developers.facebook.com/docs/sharing/webmasters/crawler)"
34.38.125.5 - - [09/Oct/2026:04:40:03 +0000] "POST /cgi-bin/php-cgi?-d+allow_url_include%3don+-d+auto_prepend_file%3dphp://input HTTP/2.0" 404 16287 "-" "Mozilla/5.0 (compatible; xAI-Grok/1.0; +https://x.ai/)"
34.38.125.5 - - [09/Oct/2026:04:40:04 +0000] "POST /cgi-bin/php?-d+allow_url_include%3don+-d+auto_prepend_file%3dphp://input HTTP/2.0" 404 16285 "-" "Mozilla/5.0 (compatible; cohere-ai; +https://cohere.com/crawler)"
34.38.125.5 - - [09/Oct/2026:06:11:21
...
show less
Bad Web Bot
๐ต๐ฑ
Budyn
2026-10-09 05:37:35
(1 day ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit Block. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: admin.budyn.ovh | URI: /dist/.vite/manifest.json | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Hacking
Web App Attack
๐ณ๐ฑ
Alt255
2026-10-09 05:22:03
(1 day ago)
[ti-29al] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail apac ...
show more
[ti-29al] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail apache-404. Example: 34.38.125.5 - - [09/Oct/2026:07:21:53 +0200] "GET /i6mhthapos973omoczlw HTTP/2.0" 404 1694 "-" "Mozilla/5.0 (compatible; YiBot/1.0; +https://01.ai/)"
34.38.125.5 - - [09/Oct/2026:07:21:53 +0200] "GET /assets/manifest.json HTTP/2.0" 404 1694 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36"
34.38.125.5 - - [09/Oct/2026:07:21:53 +0200] "GET /api/uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2fproc/self/environ HTTP/2.0" 404 544 "-" "DuckAssistBot/1.1 (https://duckduckgo.com/duckassistbot)"
34.38.125.5 - - [09/Oct/2026:07:21:53 +0200] "GET /webpack-stats.json HTTP/2.0" 404 1694 "
...
show less
Bad Web Bot
Web App Attack
๐จ๐ญ
๐จ๐ญ Hosting
2026-10-09 05:10:24
(1 day ago)
Automated WAF report: 200-300 blocked requests from this IP detected by our WAF.
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 04:53:46
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.38.125.5 (5.125.38.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.38.125.5 (5.125.38.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 00:53:42.337195 2026] [security2:error] [pid 20782:tid 20782] [client 34.38.125.5:35796] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||webserviceswest.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "webserviceswest.com"] [uri "/z9x8c7v6b5-debug-trigger-webserviceswest.com"] [unique_id "ashzVoEa84qT75wxgrwHmAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ฌ
HighWay
2026-10-09 04:50:17
(1 day ago)
34.38.125.5 - - [09/Oct/2026:04:50:12 +0000] "POST /lib/terminal-xhr.php HTTP/1.1" 404 4759 "-" "Moz ...
show more
34.38.125.5 - - [09/Oct/2026:04:50:12 +0000] "POST /lib/terminal-xhr.php HTTP/1.1" 404 4759 "-" "Mozilla/5.0 (compatible; MistralAI-User/1.0; +https://mistral.ai/)"
34.38.125.5 - - [09/Oct/2026:04:50:12 +0000] "GET /80eehxq415pnra2oeenl HTTP/1.1" 404 4758 "-" "Mozilla/5.0 (compatible; YiBot/1.0; +https://01.ai/)"
34.38.125.5 - - [09/Oct/2026:04:50:12 +0000] "POST /graphql HTTP/1.1" 404 770 "https://vhelectronics.com" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36"
34.38.125.5 - - [09/Oct/2026:04:50:12 +0000] "POST /api/graphql HTTP/1.1" 404 770 "https://vhelectronics.com" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36"
34.38.125.5 - - [09/Oct/2026:04:50:12 +0000] "GET /wp-json HTTP/1.1" 404 770 "-" "Mozilla/5.0 (compatible; ChatGLM-Spider/1.0; +https://zhipuai.cn/)"
34.38.125.5 - - [09/Oct/2026:04:50:13 +0000] "POST /v1/graphql HTTP/1.1" 404 770 "https://v
...
show less
Bad Web Bot
Web App Attack
๐จ๐ฟ
ptlab
2026-10-09 04:48:56
(1 day ago)
Web attack probes: 71 suspicious URL paths (63 known-malicious), 73 requests; 5 successful (2xx) req ...
show more
Web attack probes: 71 suspicious URL paths (63 known-malicious), 73 requests; 5 successful (2xx) requests to attack paths; types: admin-panel, cgi, lfi, rce, sensitive-files, traversal, wordpress; last seen 2026-10-09 (UTC). Reported automatically by PathDB log analysis.
show less
Hacking
Bad Web Bot
Web App Attack
๐ฉ๐ช
Bedios GmbH
2026-10-09 04:39:55
(1 day ago)
Keyfile theft attempt
Hacking
๐ฉ๐ช
neckaralb-admin.de
2026-10-09 04:37:07
(1 day ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
๐บ๐ธ
gamabe
2026-10-09 04:34:48
(1 day ago)
Detected crowdsecurity/http-dos-swithcing-ua attack pattern. Reported by CrowdSec IDS.
Hacking
๐ช๐ธ
robotstxt
2026-10-09 04:34:26
(1 day ago)
34.38.125.5 - - [09/Oct/2026:04:34:19 +0000] "GET /build/manifest.json HTTP/2.0" 403 2 "https://star ...
show more
34.38.125.5 - - [09/Oct/2026:04:34:19 +0000] "GET /build/manifest.json HTTP/2.0" 403 2 "https://starship.xyz/build/manifest.json" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36 Edg/153.0.0.0" "-" edge="34.38.125.5"
34.38.125.5 - - [09/Oct/2026:04:34:19 +0000] "GET /.vite/manifest.json HTTP/2.0" 403 2 "https://starship.xyz/.vite/manifest.json" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36 Edg/153.0.0.0" "-" edge="34.38.125.5"
34.38.125.5 - - [09/Oct/2026:04:34:19 +0000] "GET /z9x8c7v6b5-debug-trigger-starship.xyz HTTP/2.0" 403 20 "https://starship.xyz/z9x8c7v6b5-debug-trigger-starship.xyz" "Mozilla/5.0 (compatible; KimiBot/1.0; +https://kimi.ai/)" "-" edge="34.38.125.5"
34.38.125.5 - - [09/Oct/2026:04:34:19 +0000] "GET /dist/manifest.json HTTP/2.0" 403 2 "https://starship.xyz/dist/manifest.json" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7)
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 04:29:07
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.38.125.5 (5.125.38.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.38.125.5 (5.125.38.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 00:29:04.457437 2026] [security2:error] [pid 5999:tid 5999] [client 34.38.125.5:43448] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||sicktrax.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "sicktrax.com"] [uri "/z9x8c7v6b5-debug-trigger-sicktrax.com"] [unique_id "ashtkBdBbB0FWtVL39tgIgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ต๐ฑ
sefinek.net
2026-10-09 04:26:50
(1 day ago)
Triggered Cloudflare WAF (firewallCustom) from BE.
Action: BLOCK | Protocol: HTTP/2 (POST) | Endpoin ...
show more
Triggered Cloudflare WAF (firewallCustom) from BE.
Action: BLOCK | Protocol: HTTP/2 (POST) | Endpoint: /admin | UA: CCBot/2.0 (https://commoncrawl.org/faq/) โข Generated by: github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
jormaster3k
2026-10-09 04:22:37
(1 day ago)
Attack against Apache (too many 404s)
Web App Attack