๐ฉ๐ช
big-cloud.nl
2026-10-08 19:34:24
(7 minutes ago)
Try to access /.ssh/id_ed25519
Web App Attack
๐จ๐ฆ
Anytech
2026-10-08 19:18:15
(23 minutes ago)
Blocked by ConnMonitor
Web App Attack
Anonymous
2026-10-08 19:15:02
(26 minutes ago)
suspicious request in access.log
Web App Attack
๐ฉ๐ช
rh24
2026-10-08 19:07:39
(33 minutes ago)
(badbots) Bad bot user-agent [redacted] from 34.7.6.97 (97.6.7.34.bc.googleusercontent.com)
Hacking
๐บ๐ธ
TPI-Abuse
2026-10-08 18:56:02
(45 minutes ago)
(mod_security) mod_security (id:210730) triggered by 34.7.6.97 (97.6.7.34.bc.googleusercontent.com): ...
show more
(mod_security) mod_security (id:210730) triggered by 34.7.6.97 (97.6.7.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 14:55:54.840106 2026] [security2:error] [pid 19638:tid 19638] [client 34.7.6.97:55608] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||artfranz.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "artfranz.com"] [uri "/z9x8c7v6b5-debug-trigger-artfranz.com"] [unique_id "asfnOpiWzl_WQW8mOmJUwQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-10-08 18:54:09
(47 minutes ago)
Excessive multi-domain requests
Brute-Force
๐ซ๐ท
pm33
2026-10-08 18:52:33
(48 minutes ago)
Excessive crawling HTTP 404
Web App Attack
๐ณ๐ฑ
Alt255
2026-10-08 18:50:11
(51 minutes ago)
[ti-spijkov] Web exploit scanning: 3 suspicious requests detected by fail2ban jail apache-scanner. E ...
show more
[ti-spijkov] Web exploit scanning: 3 suspicious requests detected by fail2ban jail apache-scanner. Example: 34.7.6.97 - - [08/Oct/2026:20:50:10 +0200] "GET /.env.production HTTP/2.0" 301 515 "-" "Mozilla/5.0 (compatible; cohere-ai; +https://cohere.com/crawler)"
34.7.6.97 - - [08/Oct/2026:20:50:10 +0200] "GET /.env HTTP/2.0" 301 493 "-" "Mozilla/5.0 (compatible; xAI-Grok/1.0; +https://x.ai/)"
34.7.6.97 - - [08/Oct/2026:20:50:10 +0200] "GET /.env.example HTTP/2.0" 301 509 "-" "Mozilla/5.0 (compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot)"
...
show less
Bad Web Bot
Web App Attack
๐ซ๐ฎ
as211431.net
2026-10-08 18:43:13
(58 minutes ago)
Triggered Cloudflare WAF (firewallCustom) from NL.
Action taken: BLOCK
Protocol: HTTP/2 (GET method) ...
show more
Triggered Cloudflare WAF (firewallCustom) from NL.
Action taken: BLOCK
Protocol: HTTP/2 (GET method)
Endpoint: /manage/env
UA: Mozilla/5.0 (compatible; ChatGLM-Spider/1.0; +https://zhipuai.cn/)
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ณ๐ฑ
Alt255
2026-10-08 18:25:04
(1 hour ago)
[ti-01ov] Web exploit scanning: 1 suspicious requests detected by fail2ban jail <name>. Example: 34. ...
show more
[ti-01ov] Web exploit scanning: 1 suspicious requests detected by fail2ban jail <name>. Example: 34.7.6.97 - - \[08/Oct/2026:20:24:50 +0200\] "GET /files../.env HTTP/1.1" 403 612 "-" "Mozilla/5.0 AppleWebKit/537.36 \(KHTML, like Gecko\; compatible\; Claude-User/1.0\; [email protected] \)"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 17:48:08
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.7.6.97 (97.6.7.34.bc.googleusercontent.com): ...
show more
(mod_security) mod_security (id:210492) triggered by 34.7.6.97 (97.6.7.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 13:48:04.303036 2026] [security2:error] [pid 22064:tid 22064] [client 34.7.6.97:44992] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "accinternational.net"] [uri "/files../.env"] [unique_id "asfXVFdEnlpL2HGrkO7tdwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-10-08 17:40:03
(2 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐บ๐ธ
xmission.com
2026-10-08 17:19:11
(2 hours ago)
Blocked by UFW (TCP on 8080)
Source port: 34030
TTL: 60
Packet length: 60
TOS: 0x00
This report (fo ...
show more
Blocked by UFW (TCP on 8080)
Source port: 34030
TTL: 60
Packet length: 60
TOS: 0x00
This report (for 34.7.6.97) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
Web App Attack
๐ฌ๐ง
wiredalter
2026-10-08 17:18:45
(2 hours ago)
Blocked by fail2ban on gVPS [8443/tcp]
Source Port: 59052
TTL: 57
Packet Length: 60
TOS: 0x00
Analy ...
show more
Blocked by fail2ban on gVPS [8443/tcp]
Source Port: 59052
TTL: 57
Packet Length: 60
TOS: 0x00
Analyzed by https://ip.wiredalter.com
show less
Brute-Force
SSH
๐จ๐ฆ
polycoda
2026-10-08 16:56:44
(2 hours ago)
AutoBlock: ๐ก Port Scan (Non Decay-Based)
Port Scan