Anonymous
2026-09-24 10:41:44
(1 hour ago)
34.7.152.182 - - [24/Sep/2026:12:41:42 +0200] "GET /assets/manifest.json HTTP/1.1" 404 65202
34.7.15 ...
show more
34.7.152.182 - - [24/Sep/2026:12:41:42 +0200] "GET /assets/manifest.json HTTP/1.1" 404 65202
34.7.152.182 - - [24/Sep/2026:12:41:42 +0200] "GET /manifest.json HTTP/1.1" 404 65180
34.7.152.182 - - [24/Sep/2026:12:41:42 +0200] "GET /asset-manifest.json HTTP/1.1" 404 65198
34.7.152.182 - - [24/Sep/2026:12:41:42 +0200] "GET /dyn6yrrf59f3xmsvbq3t HTTP/1.1" 404 65201
34.7.152.182 - - [24/Sep/2026:12:41:42 +0200] "GET /webpack-stats.json HTTP/1.1" 404 65195
34.7.152.182 - - [24/Sep/2026:12:41:42 +0200] "GET /static/manifest.json HTTP/1.1" 404 65202
34.7.152.182 - - [24/Sep/2026:12:41:42 +0200] "GET /dist/manifest.json HTTP/1.1" 404 65196
34.7.152.182 - - [24/Sep/2026:12:41:42 +0200] "GET /pjlosj6yqox9b6cwxv4j HTTP/1.1" 404 65201
34.7.152.182 - - [24/Sep/2026:12:41:42 +0200] "POST /graphql HTTP/1.1" 404 65162
34.7.152.182 - - [24/Sep/2026:12:41:43 +0200] "POST /v1/graphql HTTP/1.1" 404 60338
...
show less
Web Spam
Web App Attack
Anonymous
2026-09-24 10:23:24
(1 hour ago)
34.7.152.182 - - [24/Sep/2026:12:23:20 +0200] "GET /dist/manifest.json HTTP/1.1" 404 60362
34.7.152. ...
show more
34.7.152.182 - - [24/Sep/2026:12:23:20 +0200] "GET /dist/manifest.json HTTP/1.1" 404 60362
34.7.152.182 - - [24/Sep/2026:12:23:20 +0200] "GET /webpack-stats.json HTTP/1.1" 404 65195
34.7.152.182 - - [24/Sep/2026:12:23:20 +0200] "GET /static/manifest.json HTTP/1.1" 404 65202
34.7.152.182 - - [24/Sep/2026:12:23:20 +0200] "GET /asset-manifest.json HTTP/1.1" 404 65198
34.7.152.182 - - [24/Sep/2026:12:23:20 +0200] "GET /manifest.json HTTP/1.1" 404 65180
34.7.152.182 - - [24/Sep/2026:12:23:20 +0200] "GET /assets/manifest.json HTTP/1.1" 404 65202
34.7.152.182 - - [24/Sep/2026:12:23:21 +0200] "POST /graphql HTTP/1.1" 404 60328
34.7.152.182 - - [24/Sep/2026:12:23:22 +0200] "POST /v1/graphql HTTP/1.1" 404 60338
34.7.152.182 - - [24/Sep/2026:12:23:22 +0200] "GET /document.php?modulepart=systemtools&file=../conf/conf.php&hashp=shared HTTP/1.1" 404 60923
34.7.152.182 - - [24/Sep/2026:12:23:23 +0200] "GET /proc/self/cmdline HTTP/1.1" 404 60360
...
show less
Web Spam
Web App Attack
๐ฉ๐ช
Skyrider
2026-09-24 09:01:16
(2 hours ago)
crowdsecurity/http-probing
Web App Attack
๐บ๐ธ
1gz
2026-09-24 08:25:51
(3 hours ago)
Triggered Cloudflare WAF (firewallCustom) from NL.
Action taken: CHALLENGE
Protocol: HTTP/2 (POST me ...
show more
Triggered Cloudflare WAF (firewallCustom) from NL.
Action taken: CHALLENGE
Protocol: HTTP/2 (POST method)
Endpoint: /functionRouter
UA: Mozilla/5.0 (compatible; Google-Extended; +http://www.google.com/bot.html)
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ณ๐ฑ
Savvii
2026-09-24 07:12:24
(4 hours ago)
20 attempts against mh-misbehave-ban on onion
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
robotstxt
2026-09-24 06:50:50
(4 hours ago)
34.7.152.182 - - [24/Sep/2026:06:50:33 +0000] "GET /@fs/.env?url&raw?? HTTP/2.0" 403 49629 "https:// ...
show more
34.7.152.182 - - [24/Sep/2026:06:50:33 +0000] "GET /@fs/.env?url&raw?? HTTP/2.0" 403 49629 "https://www.economipedia.com/@fs/.env?url&raw??" "Mozilla/5.0 (compatible; xAI-Grok/1.0; +https://x.ai/)" "-"
34.7.152.182 - - [24/Sep/2026:06:50:34 +0000] "GET /admin%2F.env HTTP/2.0" 403 49629 "https://www.economipedia.com/admin%2F.env" "Mozilla/5.0 (compatible; Meta-ExternalAgent/1.0; +https://developers.facebook.com/docs/sharing/webmasters/crawler)" "-"
34.7.152.182 - - [24/Sep/2026:06:50:44 +0000] "GET /.env?import&url&inline HTTP/2.0" 403 49630 "https://www.economipedia.com/.env?import&url&inline" "Mozilla/5.0 (compatible; Qwenbot/1.0; +https://qwen.alibaba.com/)" "-"
34.7.152.182 - - [24/Sep/2026:06:50:44 +0000] "GET /.env?import&raw HTTP/2.0" 403 49630 "https://www.economipedia.com/.env?import&raw" "Mozilla/5.0 (compatible; Meta-ExternalAgent/1.0; +https://developers.facebook.com/docs/sharing/webmasters/crawler)" "-"
34.7.152.182 - - [24/Sep/2026:06:50:44 +0000] "GET /.env.development?im
...
show less
Web App Attack
๐ซ๐ท
IRISIO
2026-09-24 06:31:41
(5 hours ago)
scans/SQL injection/spam posts : 106 queries
Web App Attack
SQL Injection
๐ฎ๐ณ
evicky2002
2026-09-24 06:00:03
(5 hours ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐ฌ๐ง
openstrike.co.uk
2026-09-24 05:14:37
(6 hours ago)
126 attacks on env grabbing URLs, VC URLs, config grabbing URLs (type 2), PHP URLs, password/key gra ...
show more
126 attacks on env grabbing URLs, VC URLs, config grabbing URLs (type 2), PHP URLs, password/key grabbing URLs, env grabbing URLs (type 2):
GET /@fs/proc/self/cwd/.env?raw?? HTTP/1.1
GET /.git/HEAD HTTP/1.1
GET /src/amplifyconfiguration.json HTTP/1.1
POST /icecoder/lib/terminal-xhr.php HTTP/1.1
GET /@fs/home/ec2-user/.aws/credentials?raw?? HTTP/1.1
GET /public/plugins/alertlist/../../../../../../../../proc/self/environ HTTP/1.1
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 05:06:37
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.7.152.182 (182.152.7.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.7.152.182 (182.152.7.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 01:06:33.377277 2026] [security2:error] [pid 8890:tid 8890] [client 34.7.152.182:41792] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.denvercitymotorparts.com"] [uri "/.env.bak"] [unique_id "arSv2bSdlVsdKh4KDQGAigAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
demomodule
2026-09-24 04:30:45
(7 hours ago)
PrestaShop Security Module: suspicious probe path detected (/.env)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 04:23:57
(7 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.7.152.182 (182.152.7.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.7.152.182 (182.152.7.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 00:23:52.289621 2026] [security2:error] [pid 18685:tid 18685] [client 34.7.152.182:57824] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.danged.com|F|2"] [data ".danged.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.danged.com"] [uri "/z9x8c7v6b5-debug-trigger-www.danged.com"] [unique_id "arSl2K9Ib6BxHECn3JfjLQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-24 04:18:02
(7 hours ago)
34.7.152.182 - - [24/Sep/2026:06:17:51 +0200] "GET /z9x8c7v6b5-debug-trigger-www.crypcool.com HTTP/1 ...
show more
34.7.152.182 - - [24/Sep/2026:06:17:51 +0200] "GET /z9x8c7v6b5-debug-trigger-www.crypcool.com HTTP/1.1" 404 30109
34.7.152.182 - - [24/Sep/2026:06:17:51 +0200] "GET /k4n3hllwdc0z02adxrhl HTTP/1.1" 404 30109
34.7.152.182 - - [24/Sep/2026:06:17:51 +0200] "GET /build/manifest.json HTTP/1.1" 404 30109
34.7.152.182 - - [24/Sep/2026:06:17:51 +0200] "GET /q3n23k8o7oroc1cziw5u HTTP/1.1" 404 30109
34.7.152.182 - - [24/Sep/2026:06:17:51 +0200] "GET /dist/.vite/manifest.json HTTP/1.1" 404 30109
34.7.152.182 - - [24/Sep/2026:06:17:51 +0200] "GET /dist/manifest.json HTTP/1.1" 404 30109
34.7.152.182 - - [24/Sep/2026:06:17:52 +0200] "GET /api/fs/exec HTTP/1.1" 404 30109
34.7.152.182 - - [24/Sep/2026:06:17:55 +0200] "GET /graphql HTTP/1.1" 404 30109
34.7.152.182 - - [24/Sep/2026:06:17:57 +0200] "GET /api/graphql HTTP/1.1" 404 30109
34.7.152.182 - - [24/Sep/2026:06:17:58 +0200] "GET /secrets.json HTTP/1.1" 404 30109
...
show less
Web Spam
Web App Attack
๐ฉ๐ช
robotstxt
2026-09-24 03:51:27
(7 hours ago)
34.7.152.182 - - [24/Sep/2026:03:50:47 +0000] "GET /izfjbqs2hjoayjb82bjh HTTP/2.0" 403 189 "-" "Mozi ...
show more
34.7.152.182 - - [24/Sep/2026:03:50:47 +0000] "GET /izfjbqs2hjoayjb82bjh HTTP/2.0" 403 189 "-" "Mozilla/5.0 (compatible; Bytespider; [email protected] ) AppleWebKit/537.36" "-" edge="34.7.152.182"
34.7.152.182 - - [24/Sep/2026:03:50:47 +0000] "GET /auth HTTP/2.0" 403 165 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36" "-" edge="34.7.152.182"
34.7.152.182 - - [24/Sep/2026:03:50:47 +0000] "GET /user/login HTTP/2.0" 403 165 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36" "-" edge="34.7.152.182"
34.7.152.182 - - [24/Sep/2026:03:50:47 +0000] "GET /account/login HTTP/2.0" 403 165 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36" "-" edge="34.7.152.182"
34.7.152.182 - - [24/Sep/2026:03:50:47 +0000] "GET /login HTTP/2.0" 403 165 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) App
...
show less
Web App Attack
Anonymous
2026-09-24 03:24:55
(8 hours ago)
malicious scanning tool activity
Web App Attack