๐ณ๐ฑ
Alt255
2026-10-05 13:58:43
(4 days ago)
[ti-01al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-01al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 34.78.69.170 - - [05/Oct/2026:15:58:23 +0200] "GET /files../.env HTTP/2.0" 404 1855 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
Charlesiv
2026-10-05 12:10:44
(4 days ago)
Triggered Cloudflare WAF (firewallCustom) from BE.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Prot ...
show more
Triggered Cloudflare WAF (firewallCustom) from BE.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Protocol: HTTP/2 (DELETE method)
Endpoint: /inngest
Timestamp: 2026-10-05T10:53:21Z
Ray ID: a45be1d09b8ba0cb
UA: DuckAssistBot/1.1 (https://duckduckgo.com/duckassistbot)
show less
Bad Web Bot
๐น๐ท
Detmach
2026-10-05 11:10:30
(4 days ago)
Security attack detected. Multiple failed attempts from 34.78.69.170. IP banned for 1440 minutes at ...
show more
Security attack detected. Multiple failed attempts from 34.78.69.170. IP banned for 1440 minutes at 05.10.2026 14:10:30. Failed attempts: 1
show less
Brute-Force
๐บ๐ธ
Charlesiv
2026-10-05 06:01:10
(4 days ago)
Triggered Cloudflare WAF (firewallCustom) from BE.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Prot ...
show more
Triggered Cloudflare WAF (firewallCustom) from BE.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Protocol: HTTP/2 (GET method)
Endpoint: /static//.env
Timestamp: 2026-10-05T02:42:47Z
Ray ID: a45913358aeea876
UA: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; GPTBot/1.4; +https://openai.com/gptbot
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-05 05:08:00
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.78.69.170 (170.69.78.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.78.69.170 (170.69.78.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 01:07:53.992082 2026] [security2:error] [pid 29247:tid 29247] [client 34.78.69.170:35952] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.afjm.net"] [uri "/media../.env"] [unique_id "asMwqVfN9a1pFYxEm9oYtgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
el-brujo
2026-10-05 02:21:59
(4 days ago)
Cloudflare WAF: Request Path: /phpinfo.php Request Query: Host: chat.elhacker.net userAgent: Mozill ...
show more
Cloudflare WAF: Request Path: /phpinfo.php Request Query: Host: chat.elhacker.net userAgent: Mozilla/5.0 (compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot) Action: block Source: firewallCustom ASN Description: Google LLC Country: BE Method: GET Timestamp: 2026-10-05T02:21:59Z ruleId: 6b2d48d0415e4adb9f099d85f54d1de6. Report generated by Cloudflare-WAF-to-AbuseIPDB.
show less
Hacking
SQL Injection
Web App Attack
๐ธ๐ช
cider1725
2026-10-05 00:45:27
(4 days ago)
34.78.69.170 - - [05/Oct/2026:00:45:26 +0000] "GET /y8d3hqdl11fir67ue1iv HTTP/1.1" 444 0 "-" "Mozill ...
show more
34.78.69.170 - - [05/Oct/2026:00:45:26 +0000] "GET /y8d3hqdl11fir67ue1iv HTTP/1.1" 444 0 "-" "Mozilla/5.0 (compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot)" "-"
34.78.69.170 - - [05/Oct/2026:00:45:26 +0000] "GET /z9x8c7v6b5-debug-trigger-apps.thesandbox.net HTTP/1.1" 444 0 "-" "Mozilla/5.0 (compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot)" "-"
34.78.69.170 - - [05/Oct/2026:00:45:26 +0000] "GET /xzbst2w3m8pkgdvhsv3z HTTP/1.1" 444 0 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; [email protected] )" "-"
...
show less
Brute-Force
Web App Attack
๐ฉ๐ช
webanyone
2026-10-05 00:39:03
(4 days ago)
Secret file probe | method: GET | path: /firebase-credentials.json | ua: Mozilla/5.0 AppleWebKit/537 ...
show more
Secret file probe | method: GET | path: /firebase-credentials.json | ua: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; GPTBot/1.4; +https://openai.com/gptbot
show less
Hacking
Web App Attack
๐ต๐ฑ
strefapi_com
2026-10-04 23:57:58
(4 days ago)
Brute-force, web
...
Hacking
Brute-Force
Web App Attack
๐ณ๐ฑ
Starburst SysOp Team
2026-10-04 23:39:36
(4 days ago)
HTTP header is restricted by policy (/x-middleware-subrequest/). String match within "/content-encod ...
show more
HTTP header is restricted by policy (/x-middleware-subrequest/). String match within "/content-encoding/ /proxy/ /lock-token/ /content-range/ /if/ /x-http-method-override/ /x-http-method/ /x-method-override/ /x-middleware-subrequest/ /expect/" at TX:header_name_920450_x-middleware-subrequest. (920450-ams6-1)
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-04 23:38:10
(4 days ago)
(mod_security) mod_security (id:210730) triggered by 34.78.69.170 (170.69.78.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.78.69.170 (170.69.78.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 19:38:04.962975 2026] [security2:error] [pid 24131:tid 24131] [client 34.78.69.170:45282] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||amp.rustyog.net|F|2"] [data ".key"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "amp.rustyog.net"] [uri "/server.key"] [unique_id "asLjXJGKTgEI4fBWVITyuAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-04 23:37:39
(4 days ago)
34.78.69.170 - - [05/Oct/2026:01:37:37 +0200] "-" 400 150 "-" "-"
34.78.69.170 - - [05/Oct/2026:01:3 ...
show more
34.78.69.170 - - [05/Oct/2026:01:37:37 +0200] "-" 400 150 "-" "-"
34.78.69.170 - - [05/Oct/2026:01:37:38 +0200] "-" 400 150 "-" "-"
34.78.69.170 - - [05/Oct/2026:01:37:38 +0200] "-" 400 150 "-" "-"
34.78.69.170 - - [05/Oct/2026:01:37:38 +0200] "-" 400 150 "-" "-"
34.78.69.170 - - [05/Oct/2026:01:37:38 +0200] "-" 400 150 "-" "-"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-04 23:14:51
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.78.69.170 (170.69.78.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.78.69.170 (170.69.78.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 19:14:45.481053 2026] [security2:error] [pid 31980:tid 31980] [client 34.78.69.170:48810] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "akramansari.mydobdate.net"] [uri "/%2e%2e/.env"] [unique_id "asLd5SlDIqn983Hfi5p5CwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
magnetosphere-tarpit
2026-10-04 23:11:57
(4 days ago)
Automated web scanner: repeatedly probed for .env, .git, wp-admin and PHP webshell paths that do not ...
show more
Automated web scanner: repeatedly probed for .env, .git, wp-admin and PHP webshell paths that do not exist on this host. Tarpitted, then banned: 10 requests within 24h0m0s
show less
Port Scan
Bad Web Bot
Web App Attack
๐บ๐ธ
daveoctober
2026-10-04 23:05:27
(4 days ago)
October Sentinel: honeypot triggered
Bad Web Bot
Web App Attack