๐ท๐ด
clauss
2026-10-07 19:23:28
(3 minutes ago)
34.45.254.202 - - [07/Oct/2026:22:23:26 +0300] "GET /.ssh/id_rsa HTTP/2.0" 404 22523 "-" "Mozilla/5. ...
show more
34.45.254.202 - - [07/Oct/2026:22:23:26 +0300] "GET /.ssh/id_rsa HTTP/2.0" 404 22523 "-" "Mozilla/5.0 (compatible; KimiBot/1.0; +https://kimi.ai/)"
34.45.254.202 - - [07/Oct/2026:22:23:27 +0300] "GET /@fs/app/.env?raw?? HTTP/2.0" 403 146 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot"
...
show less
Web App Attack
Anonymous
2026-10-07 19:15:49
(11 minutes ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
๐ณ๐ฑ
Savvii
2026-10-07 18:51:53
(35 minutes ago)
20 attempts against mh-misbehave-ban on choy
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-07 16:37:20
(2 hours ago)
34.45.254.202 - - [07/Oct/2026:18:37:14 +0200] "POST /lib/terminal-xhr.php HTTP/1.1" 404 28769
34.45 ...
show more
34.45.254.202 - - [07/Oct/2026:18:37:14 +0200] "POST /lib/terminal-xhr.php HTTP/1.1" 404 28769
34.45.254.202 - - [07/Oct/2026:18:37:14 +0200] "GET /dist/.vite/manifest.json HTTP/1.1" 404 30374
34.45.254.202 - - [07/Oct/2026:18:37:14 +0200] "POST /graphql HTTP/1.1" 404 30384
34.45.254.202 - - [07/Oct/2026:18:37:15 +0200] "POST /api/graphql HTTP/1.1" 404 28722
34.45.254.202 - - [07/Oct/2026:18:37:16 +0200] "GET /@fs/home/ec2-user/.aws/credentials?raw?? HTTP/1.1" 404 28888
34.45.254.202 - - [07/Oct/2026:18:37:15 +0200] "GET /@fs/..%252f..%252f..%252f..%252f..%252fproc/self/environ?raw?? HTTP/1.1" 404 28568
34.45.254.202 - - [07/Oct/2026:18:37:16 +0200] "GET /@fs/home/ubuntu/.aws/credentials?raw?? HTTP/1.1" 404 28747
34.45.254.202 - - [07/Oct/2026:18:37:16 +0200] "POST /v1/graphql HTTP/1.1" 404 28759
34.45.254.202 - - [07/Oct/2026:18:37:18 +0200] "GET /%2Fadmin HTTP/1.1" 404 1845
34.45.254.202 - - [07/Oct/2026:18:37:18 +0200] "GET /%2Fdashboard HTTP/1.1" 404 1845
...
show less
Web Spam
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-10-07 16:23:24
(3 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 1248
Exploited Host
Web App Attack
Anonymous
2026-10-07 16:15:04
(3 hours ago)
Bot / scanning and/or hacking attempts: POST /cgi-bin/php-cgi.exe?%ADd+allow_url_include%3d1+%ADd+au ...
show more
Bot / scanning and/or hacking attempts: POST /cgi-bin/php-cgi.exe?%ADd+allow_url_include%3d1+%ADd+auto_, POST /php-cgi/php-cgi.exe?%ADd+allow_url_include%3d1+%ADd+auto_
show less
Hacking
Web App Attack
๐ฉ๐ช
Skyrider
2026-10-07 16:05:57
(3 hours ago)
Nginx: HTTP 4xx probe/scan attempts. Automated fail2ban report.
Bad Web Bot
Web App Attack
๐ช๐ธ
el-brujo
2026-10-07 15:54:43
(3 hours ago)
34.45.254.202 - - [07/Oct/2026:17:54:43 +0200] "GET /z9x8c7v6b5-debug-trigger-elhacker.net HTTP/2.0" ...
show more
34.45.254.202 - - [07/Oct/2026:17:54:43 +0200] "GET /z9x8c7v6b5-debug-trigger-elhacker.net HTTP/2.0" 404 15872 "-" "Mozilla/5.0 (compatible; MistralAI-User/1.0; +https://mistral.ai/)"
34.45.254.202 - - [07/Oct/2026:17:54:43 +0200] "GET /izlgif14vcy3uelzrmhd HTTP/2.0" 404 15872 "-" "DuckAssistBot/1.1 (https://duckduckgo.com/duckassistbot)"
34.45.254.202 - - [07/Oct/2026:17:54:43 +0200] "GET /.vite/manifest.json HTTP/2.0" 404 15872 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36 Edg/153.0.0.0"
34.45.254.202 - - [07/Oct/2026:17:54:43 +0200] "GET /yk04jqv97sssklu7xy1m HTTP/2.0" 404 15872 "-" "Mozilla/5.0 (compatible; Meta-ExternalAgent/1.0; +https://developers.facebook.com/docs/sharing/webmasters/crawler)"
...
show less
Web App Attack
Hacking
๐ฉ๐ช
big-cloud.nl
2026-10-07 15:54:39
(3 hours ago)
Try to access /cache/original/%2e%2e/%2e%2e/.env
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 15:47:10
(3 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.45.254.202 (202.254.45.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.45.254.202 (202.254.45.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 11:47:06.199857 2026] [security2:error] [pid 25167:tid 25187] [client 34.45.254.202:44240] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||econpage.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "econpage.com"] [uri "/z9x8c7v6b5-debug-trigger-econpage.com"] [unique_id "asZpenE7lHaaWd-OnLF7iAAAAFI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
zynex
2026-10-07 15:46:38
(3 hours ago)
URL Probing: /@fs/app/.env
Web App Attack
Anonymous
2026-10-07 15:21:27
(4 hours ago)
โฃ๏ธ WAF rule violation. Dangerous payload detected in the request.
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Savvii
2026-10-07 15:17:48
(4 hours ago)
20 attempts against mh-misbehave-ban on ozone
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-10-07 14:59:40
(4 hours ago)
[ti-04al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-04al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 34.45.254.202 - - [07/Oct/2026:16:59:40 +0200] "GET /.htpasswd HTTP/2.0" 403 1893 "-" "Mozilla/5.0 (compatible; YiBot/1.0; +https://01.ai/)"
...
show less
Bad Web Bot
Web App Attack
Anonymous
2026-10-07 14:50:03
(4 hours ago)
suspicious request in access.log
Web App Attack