๐จ๐ฆ
zXero
2026-09-23 12:41:04
(18 hours ago)
Fail2Ban automatic report - jail: recidive
Brute-Force
SSH
DDoS Attack
Anonymous
2026-09-23 11:41:06
(19 hours ago)
34.78.36.219 - - [22/Sep/2026:20:46:34 -0500] "GET /.env?import&raw HTTP/1.1" 403 199 "-" "DuckAssis ...
show more
34.78.36.219 - - [22/Sep/2026:20:46:34 -0500] "GET /.env?import&raw HTTP/1.1" 403 199 "-" "DuckAssistBot/1.1 (https://duckduckgo.com/duckassistbot)" 172.71.232.92
34.78.36.219 - - [22/Sep/2026:20:46:34 -0500] "GET /.env?raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" 172.71.232.4
34.78.36.219 - - [22/Sep/2026:20:46:35 -0500] "GET /.env.local?raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; PanguBot/1.0; +https://www.huaweicloud.com/)" 172.71.232.5
34.78.36.219 - - [22/Sep/2026:20:46:35 -0500] "GET /.env.production?import&raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36; compatible; OAI-SearchBot/1.4; +https://openai.com/searchbot" 172.71.232.5
34.78.36.219 - - [22/Sep/2026:20:46:35 -0500] "GET /.env.production?raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; GrokBot/1.0; +https://x.ai/)" 172.71.232.92
34.78.36.219 - - [22/Sep/2026:20
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ณ
evicky2002
2026-09-23 06:00:01
(1 day ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐บ๐ธ
wbsouza
2026-09-23 03:24:19
(1 day ago)
CrowdSec: crowdsecurity/http-probing โ automated firewall drops on self-hosted IDS sensor
Hacking
๐ง๐ช
brechtr
2026-09-23 00:28:04
(1 day ago)
[Press84-BanHammer] 404 flood โ 30 hits in 60s โ Sourced from: brechtryckaert.com โ Request: GET /si ...
show more
[Press84-BanHammer] 404 flood โ 30 hits in 60s โ Sourced from: brechtryckaert.com โ Request: GET /signup
show less
Bad Web Bot
Web App Attack
Anonymous
2026-09-23 00:27:41
(1 day ago)
malicious scanning tool activity
Web App Attack
๐บ๐ธ
robotstxt
2026-09-22 23:35:29
(1 day ago)
34.78.36.219 - - [22/Sep/2026:23:34:57 +0000] "GET /dist/.vite/manifest.json HTTP/2.0" 403 36243 "ht ...
show more
34.78.36.219 - - [22/Sep/2026:23:34:57 +0000] "GET /dist/.vite/manifest.json HTTP/2.0" 403 36243 "https://www.blimburnseeds.com/dist/.vite/manifest.json" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36" "34.78.36.219" edge="162.159.106.123"
34.78.36.219 - - [22/Sep/2026:23:35:01 +0000] "GET /.dockerenv HTTP/2.0" 403 2 "https://www.blimburnseeds.com/.dockerenv" "Mozilla/5.0 (compatible; YiBot/1.0; +https://01.ai/)" "34.78.36.219" edge="172.71.134.119"
34.78.36.219 - - [22/Sep/2026:23:35:01 +0000] "GET /.env.local?raw HTTP/2.0" 403 36243 "https://www.blimburnseeds.com/.env.local?raw" "Mozilla/5.0 (compatible; ChatGLM-Spider/1.0; +https://zhipuai.cn/)" "34.78.36.219" edge="172.71.134.119"
34.78.36.219 - - [22/Sep/2026:23:35:02 +0000] "GET /.env.local?import&raw HTTP/2.0" 403 36244 "https://www.blimburnseeds.com/.env.local?import&raw" "Mozilla/5.0 (compatible; MoonshotBot/1.0; +https://kimi.ai/)" "34.78.36.219" edge="17
...
show less
Web App Attack
Anonymous
2026-09-22 22:06:55
(1 day ago)
IP matched detection query many 3xx errors.
Brute-Force
Anonymous
2026-09-22 22:00:16
(1 day ago)
| Multiple common web attacks from same source ip. (multiple servers)
Web App Attack
Hacking
SQL Injection
๐ซ๐ฎ
albionfreemarket.com
2026-09-22 20:28:48
(1 day ago)
34.78.36.219 - - [22/Sep/2026:20:28:46 +0000] "POST /graphql HTTP/2.0" 403 555 "https://albionfreema ...
show more
34.78.36.219 - - [22/Sep/2026:20:28:46 +0000] "POST /graphql HTTP/2.0" 403 555 "https://albionfreemarket.com" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36" 0.000 "-" "BE"
34.78.36.219 - - [22/Sep/2026:20:28:47 +0000] "POST /api/graphql HTTP/2.0" 403 555 "https://albionfreemarket.com" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36" 0.000 "-" "BE"
...
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
ConsulHosting
2026-09-22 19:34:18
(1 day ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 18:45:11
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.78.36.219 (219.36.78.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.78.36.219 (219.36.78.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 14:45:02.691189 2026] [security2:error] [pid 15950:tid 15950] [client 34.78.36.219:49720] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||blackstarmgmt.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "blackstarmgmt.com"] [uri "/z9x8c7v6b5-debug-trigger-blackstarmgmt.com"] [unique_id "arLMrte2Lfq5-BR-s6ckIgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
robotstxt
2026-09-22 16:00:40
(1 day ago)
34.78.36.219 - - [22/Sep/2026:16:00:00 +0000] "GET /dist/.vite/manifest.json HTTP/2.0" 403 36261 "-" ...
show more
34.78.36.219 - - [22/Sep/2026:16:00:00 +0000] "GET /dist/.vite/manifest.json HTTP/2.0" 403 36261 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36" "34.78.36.219" edge="162.159.106.123"
34.78.36.219 - - [22/Sep/2026:16:00:01 +0000] "GET /.env.prod HTTP/2.0" 403 2 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; GPTBot/1.4; +https://openai.com/gptbot" "34.78.36.219" edge="104.23.225.14"
34.78.36.219 - - [22/Sep/2026:16:00:02 +0000] "GET /.env.save HTTP/2.0" 403 2 "-" "Mozilla/5.0 (compatible; xAI-Grok/1.0; +https://x.ai/)" "34.78.36.219" edge="104.23.225.14"
34.78.36.219 - - [22/Sep/2026:16:00:03 +0000] "GET /.aws/config HTTP/2.0" 403 36245 "-" "Mozilla/5.0 (compatible; Bytespider; [email protected] ) AppleWebKit/537.36" "34.78.36.219" edge="104.23.225.14"
34.78.36.219 - - [22/Sep/2026:16:00:03 +0000] "GET /.aws/credentials HTTP/2.0" 403 36245 "-" "Mozilla/5.0 (compatible; DeepSeekBot
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 15:57:31
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.78.36.219 (219.36.78.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.78.36.219 (219.36.78.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 11:57:23.894317 2026] [security2:error] [pid 26328:tid 26328] [client 34.78.36.219:40374] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||blindshine.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "blindshine.com"] [uri "/z9x8c7v6b5-debug-trigger-blindshine.com"] [unique_id "arKlYypoO4a1pQ--2CKhfQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 14:24:18
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.78.36.219 (219.36.78.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.78.36.219 (219.36.78.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 10:24:14.352129 2026] [security2:error] [pid 516:tid 516] [client 34.78.36.219:60632] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||blucielocapital.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "blucielocapital.com"] [uri "/z9x8c7v6b5-debug-trigger-blucielocapital.com"] [unique_id "arKPjp5IcF2GiZ8YY02R-QAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack