๐ฉ๐ช
itsolon
2026-09-24 16:53:26
(56 minutes ago)
[24/Sep/2026:18:53:25 +0200] 179026880521.678856 34.79.208.22 0 217.154.7.177 443
[24/Sep/2026:18:53 ...
show more
[24/Sep/2026:18:53:25 +0200] 179026880521.678856 34.79.208.22 0 217.154.7.177 443
[24/Sep/2026:18:53:25 +0200] 179026880542.117370 34.79.208.22 0 217.154.7.177 443
[24/Sep/2026:18:53:25 +0200] 179026880538.670504 34.79.208.22 0 217.154.7.177 443
[24/Sep/2026:18:53:25 +0200] 179026880566.754637 34.79.208.22 0 217.154.7.177 443
[24/Sep/2026:18:53:26 +0200] 17902688066.091142 34.79.208.22 0 217.154.7.177 443
...
show less
Port Scan
Hacking
Brute-Force
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-24 12:58:41
(4 hours ago)
Excessive multi-domain requests
Brute-Force
๐บ๐ธ
[email protected]
2026-09-24 11:29:42
(6 hours ago)
CrowdSec ban: crowdsecurity/unifi-flood-detection (duration: 71h59m49s)
Port Scan
Anonymous
2026-09-24 08:35:25
(9 hours ago)
34.79.208.22 - - [24/Sep/2026:03:33:31 -0500] "GET /.env?raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 (Mac ...
show more
34.79.208.22 - - [24/Sep/2026:03:33:31 -0500] "GET /.env?raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Safari/605.1.15 (Applebot/0.1)" 172.71.126.219
34.79.208.22 - - [24/Sep/2026:03:33:31 -0500] "GET /.env?import&raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)" 172.71.126.218
34.79.208.22 - - [24/Sep/2026:03:33:31 -0500] "GET /.env.local?raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; GPTBot/1.4; +https://openai.com/gptbot" 172.71.126.218
34.79.208.22 - - [24/Sep/2026:03:33:31 -0500] "GET /.env?import&url&inline HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; Meta-ExternalAgent/1.0; +https://developers.facebook.com/docs/sharing/webmasters/crawler)" 172.71.126.219
34.79.208.22 - - [24/Sep/2026:03:33:31 -0500] "GET /.env.production?raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; MistralAI-User/1.0
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 07:00:24
(10 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.79.208.22 (22.208.79.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.79.208.22 (22.208.79.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 03:00:20.567353 2026] [security2:error] [pid 19909:tid 19909] [client 34.79.208.22:37808] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.kunzteam.com|F|2"] [data ".kunzteam.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.kunzteam.com"] [uri "/z9x8c7v6b5-debug-trigger-www.kunzteam.com"] [unique_id "arTKhEsY5-L5GipSNy5iZgAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
itsolon
2026-09-24 06:54:09
(10 hours ago)
[24/Sep/2026:08:54:07 +0200] 179023284716.101203 34.79.208.22 34214 217.154.7.177 443
[24/Sep/2026:0 ...
show more
[24/Sep/2026:08:54:07 +0200] 179023284716.101203 34.79.208.22 34214 217.154.7.177 443
[24/Sep/2026:08:54:07 +0200] 17902328473.365499 34.79.208.22 34214 217.154.7.177 443
[24/Sep/2026:08:54:08 +0200] 17902328480.126450 34.79.208.22 34214 217.154.7.177 443
[24/Sep/2026:08:54:08 +0200] 179023284829.516328 34.79.208.22 34214 217.154.7.177 443
[24/Sep/2026:08:54:08 +0200] 17902328480.022884 34.79.208.22 34214 217.154.7.177 443
...
show less
Port Scan
Hacking
Brute-Force
Web App Attack
๐ฎ๐น
CoreTech srl
2026-09-24 06:29:46
(11 hours ago)
cloudlinux2 fail2ban: 2026-09-24 08:23:49,231 fail2ban.actions [1603]: NOTICE [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-09-24 08:23:49,231 fail2ban.actions [1603]: NOTICE [plesk-modsecurity] Unban 2.50.173.45cloudlinux2 fail2ban: 2026-09-24 08:24:54,975 fail2ban.filter [1603]: INFO [plesk-modsecurity] Found 34.79.208.22 - 2026-09-24 08:24:54cloudlinux2 fail2ban: 2026-09-24 08:24:55,318 fail2ban.actions [1603]: NOTICE [plesk-modsecurity] Ban 34.79.208.22cloudlinux2 fail2ban: 2026-09-24 08:24:54,525 fail2ban.filter [1603]: INFO [plesk-modsecurity] Found 34.79.208.22 - 2026-09-24 08:24:54cloudlinux2 fail2ban: 2026-09-24 08:24:55,050 fail2ban.filter [1603]: INFO [plesk-modsecurity] Found 34.79.208.22 - 2026-09-24 08:24:55cloudlinux2 fail2ban: 2026-09-24 08:24:55,320 fail2ban.filter [1603]: INFO [recidive] Found 34.79.208.22 - 2026-09-24 08:24:55cloudlinux2 fail2ban: 2026-09-24 08:25:20,224 fail2ban.filter [1603]: INFO [plesk-wordpress] Found 45.61.187.148 - 2026-09-24 08:25:19cloudlinux2 fail2ban: 2026-09-24 08:25:29,417 fail2ban.acti
show less
Web App Attack
๐ณ๐ฑ
ConsulHosting
2026-09-24 06:05:54
(11 hours ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack
๐จ๐ญ
๐จ๐ญ Hosting
2026-09-24 05:10:43
(12 hours ago)
Automated WAF report: 125-150 blocked requests from this IP detected by our WAF.
Bad Web Bot
Web App Attack
๐ซ๐ฎ
mnazibo
2026-09-24 03:00:21
(14 hours ago)
Date: Sep 24 05:32:28 2026 EAT | Reported IP: 34.79.208.22 mod_security | id: 920450 949110 930120 9 ...
show more
Date: Sep 24 05:32:28 2026 EAT | Reported IP: 34.79.208.22 mod_security | id: 920450 949110 930120 932160 934100 934130 942550 920440 930130 930100 930110 933160 911100 932250 920420 | BE/usernameab.my_domain/- | Connections: 1 | Blocked: Permanent Block: [LF_MODSEC] | Logs: ; HTTP header is restricted by policy (/x-middleware-subrequest/); Inbound Anomaly Score Exceeded (Total Score: 5); HTTP header is restricted by policy (/x-middleware-subrequest/); HTTP header is restricted by policy (/x-middleware-subrequest/); HTTP header is restricted by policy (/x-middleware-subrequest/); HTTP header is restricted by policy (/x-middleware-subrequest/); HTTP header is restricted by policy (/x-middleware-subrequest/); HTTP header is restricted by policy (/x-middleware-subrequest/); HTTP header is restricted by policy (/x-middleware-subrequest/); OS File Access Attempt; Remote Command Execution: Unix Shell Code Found; Node.js Injection Attack 1/2;
show less
SQL Injection
Brute-Force
Bad Web Bot
๐ช๐ธ
robotstxt
2026-09-24 02:34:10
(15 hours ago)
34.79.208.22 - - [24/Sep/2026:02:33:13 +0000] "GET /web/.env HTTP/2.0" 403 0 "https://www.economiped ...
show more
34.79.208.22 - - [24/Sep/2026:02:33:13 +0000] "GET /web/.env HTTP/2.0" 403 0 "https://www.economipedia.com/web/.env" "Mozilla/5.0 (compatible; KimiBot/1.0; +https://kimi.ai/)" "-"
34.79.208.22 - - [24/Sep/2026:02:33:13 +0000] "GET /.next/.env HTTP/2.0" 403 0 "https://www.economipedia.com/.next/.env" "Mozilla/5.0 (compatible; MoonshotBot/1.0; +https://kimi.ai/)" "-"
34.79.208.22 - - [24/Sep/2026:02:33:13 +0000] "GET /dist/.env HTTP/2.0" 403 0 "https://www.economipedia.com/dist/.env" "Mozilla/5.0 (compatible; GrokBot/1.0; +https://x.ai/)" "-"
34.79.208.22 - - [24/Sep/2026:02:33:13 +0000] "GET /.aws/config HTTP/2.0" 403 0 "https://www.economipedia.com/.aws/config" "Mozilla/5.0 (compatible; Meta-ExternalAgent/1.0; +https://developers.facebook.com/docs/sharing/webmasters/crawler)" "-"
34.79.208.22 - - [24/Sep/2026:02:33:13 +0000] "GET /.git/HEAD HTTP/2.0" 403 0 "https://www.economipedia.com/.git/HEAD" "Mozilla/5.0 (compatible; xAI-Grok/1.0; +https://x.ai/)" "-"
...
show less
Web App Attack
๐ฎ๐น
VHosting
2026-09-24 01:35:04
(16 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 01:13:53
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.79.208.22 (22.208.79.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.79.208.22 (22.208.79.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 21:13:45.926445 2026] [security2:error] [pid 7082:tid 7082] [client 34.79.208.22:48572] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/Web.config" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "convoyforkids.com"] [uri "/web.config"] [unique_id "arR5SRSnqTiNMqWvsJje0wAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
robotstxt
2026-09-24 00:59:08
(16 hours ago)
34.79.208.22 - - [24/Sep/2026:00:58:30 +0000] "GET /api%2F.env HTTP/2.0" 403 49642 "-" "Mozilla/5.0 ...
show more
34.79.208.22 - - [24/Sep/2026:00:58:30 +0000] "GET /api%2F.env HTTP/2.0" 403 49642 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" "-"
34.79.208.22 - - [24/Sep/2026:00:58:30 +0000] "GET /settings%2F.env HTTP/2.0" 403 49624 "-" "CCBot/2.0 (https://commoncrawl.org/faq/)" "-"
34.79.208.22 - - [24/Sep/2026:00:58:30 +0000] "GET /dashboard%2F.env HTTP/2.0" 403 49629 "-" "Mozilla/5.0 (compatible; xAI-Grok/1.0; +https://x.ai/)" "-"
34.79.208.22 - - [24/Sep/2026:00:58:30 +0000] "GET /@fs/.env?raw&url?? HTTP/2.0" 403 49640 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36; compatible; OAI-SearchBot/1.4; +https://openai.com/searchbot" "-"
34.79.208.22 - - [24/Sep/2026:00:58:30 +0000] "GET /@fs/.env?url&raw?? HTTP/2.0" 403 49647 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" "-"
...
show less
Web App Attack
๐ง๐ช
cmbplf
2026-09-24 00:45:21
(17 hours ago)
4.372 requests from abuseipdb.com blacklisted IP (1yr2mos1w)
Brute-Force
Bad Web Bot