๐ฉ๐ช
itsolon
2026-09-29 07:34:15
(6 days ago)
[29/Sep/2026:09:34:15 +0200] 179066725573.481331 34.79.232.234 47044 217.154.7.177 443
[29/Sep/2026: ...
show more
[29/Sep/2026:09:34:15 +0200] 179066725573.481331 34.79.232.234 47044 217.154.7.177 443
[29/Sep/2026:09:34:15 +0200] 179066725587.687082 34.79.232.234 47044 217.154.7.177 443
[29/Sep/2026:09:34:15 +0200] 179066725529.155010 34.79.232.234 47030 217.154.7.177 443
[29/Sep/2026:09:34:15 +0200] 179066725569.508040 34.79.232.234 47030 217.154.7.177 443
[29/Sep/2026:09:34:15 +0200] 179066725517.856677 34.79.232.234 47030 217.154.7.177 443
...
show less
Port Scan
Hacking
Brute-Force
Web App Attack
Anonymous
2026-09-29 06:30:59
(6 days ago)
XSS Attempt
Hacking
๐บ๐ธ
peaceharbor
2026-09-29 05:15:06
(1 week ago)
Swatter: score=91 intel=abuseipdb:confidence100(100) rule=critical_badpath recidivism=4/30d crit-sin ...
show more
Swatter: score=91 intel=abuseipdb:confidence100(100) rule=critical_badpath recidivism=4/30d crit-single
show less
Web App Attack
Port Scan
๐ช๐ธ
Z|ntrueรฑigO
2026-09-29 03:52:50
(1 week ago)
Auto-report. Hits=2, Ports=80,8080, Country=-.
Brute-Force
๐ฉ๐ช
Philister11
2026-09-29 01:24:45
(1 week ago)
CrowdSec: LePresidente/http-generic-403-bf (BE/AS396982)
Web App Attack
Brute-Force
๐ซ๐ท
dusfor72
2026-09-28 06:56:44
(1 week ago)
stupid access attempts on non-existant files
...
Brute-Force
Web App Attack
Anonymous
2026-09-28 06:21:11
(1 week ago)
34.79.232.234 - - [28/Sep/2026:08:21:09 +0200] "GET /l0cdgkvns46wbd6j2xv0 HTTP/1.1" 404 60367
34.79. ...
show more
34.79.232.234 - - [28/Sep/2026:08:21:09 +0200] "GET /l0cdgkvns46wbd6j2xv0 HTTP/1.1" 404 60367
34.79.232.234 - - [28/Sep/2026:08:21:09 +0200] "GET /dist/manifest.json HTTP/1.1" 404 65196
34.79.232.234 - - [28/Sep/2026:08:21:09 +0200] "GET /asset-manifest.json HTTP/1.1" 404 65198
34.79.232.234 - - [28/Sep/2026:08:21:09 +0200] "GET /manifest.json HTTP/1.1" 404 65180
34.79.232.234 - - [28/Sep/2026:08:21:09 +0200] "GET /static/manifest.json HTTP/1.1" 404 65202
34.79.232.234 - - [28/Sep/2026:08:21:09 +0200] "GET /assets/manifest.json HTTP/1.1" 404 65202
34.79.232.234 - - [28/Sep/2026:08:21:09 +0200] "GET /webpack-stats.json HTTP/1.1" 404 65195
34.79.232.234 - - [28/Sep/2026:08:21:09 +0200] "GET /graphql HTTP/1.1" 404 60328
34.79.232.234 - - [28/Sep/2026:08:21:09 +0200] "GET /icecoder/lib/terminal-xhr.php HTTP/1.1" 404 60396
34.79.232.234 - - [28/Sep/2026:08:21:10 +0200] "GET /@fs/..%252f..%252f..%252f..%252f..%252fproc/self/environ?raw???raw%3F%3F= HTTP/1.1" 404 60667
...
show less
Web Spam
Web App Attack
๐ฉ๐ช
initsol
2026-09-28 02:47:42
(1 week ago)
[Mon Sep 28 04:47:41.777498 2026] [authz_core:error] [pid 1531942:tid 1531942] [client 34.79.232.234 ...
show more
[Mon Sep 28 04:47:41.777498 2026] [authz_core:error] [pid 1531942:tid 1531942] [client 34.79.232.234:46520] AH01630: client denied by server configuration: /var/www/
[Mon Sep 28 04:47:41.843564 2026] [authz_core:error] [pid 1531942:tid 1531942] [client 34.79.232.234:46520] AH01630: client denied by server configuration: /var/www/auth
[Mon Sep 28 04:47:41.913653 2026] [authz_core:error] [pid 1531942:tid 1531942] [client 34.79.232.234:46520] AH01630: client denied by server configuration: /var/www/signin
...
show less
Brute-Force
๐ฌ๐ง
Apache
2026-09-28 02:33:37
(1 week ago)
(mod_security) mod_security (id:930130) triggered by 34.79.232.234 (BE/Belgium/234.232.79.34.bc.goog ...
show more
(mod_security) mod_security (id:930130) triggered by 34.79.232.234 (BE/Belgium/234.232.79.34.bc.googleusercontent.com): 5 in the last 300 secs (CF_ENABLE)
show less
Brute-Force
Web App Attack
๐บ๐ธ
Epimetheus
2026-09-27 23:40:22
(1 week ago)
Zombie network / Bot scanner detected:
[POST] /php-cgi/php-cgi.exe
[GET] /_profiler/latest
[GET] /a ...
show more
Zombie network / Bot scanner detected:
[POST] /php-cgi/php-cgi.exe
[GET] /_profiler/latest
[GET] /api/v1/models
[GET] /api/env
[GET] /.dockerenv
[GET] /static//app/.env
[GET] /@fs/app/.env
[GET] /var/run/secrets/kubernetes.io/serviceaccount/token
[GET] /server.key
[DELETE] /api/inngest
[DELETE] /inngest
[GET] /.ssh/id_dsa
[GET] /private/.env
[GET] /.idea/WebServers.xml
[GET] /common/.env
[GET] /firebase.json
[GET] /google-credentials.json
[GET] /.npmrc
[GET] /serviceAccountKey.json
[GET] /backend/.env
[GET] /.env
[GET] /credentials.json
UA: Mozilla/5.0 (compatible; YouBot/1.0; +https://you.com/bot)
show less
Bad Web Bot
Exploited Host
Web App Attack
๐ฉ๐ช
klaus_ph
2026-09-27 22:42:37
(1 week ago)
2026-09-26 23:59:00,102 fail2ban.actions [8144]: NOTICE [ipblocklist] Ban 34.79.232.234
...
Bad Web Bot
Anonymous
2026-09-27 20:10:12
(1 week ago)
Portscan: TCP/8443 (3x), TCP/8080 (3x)
Port Scan
๐ซ๐ท
masterguru
2026-09-27 18:30:54
(1 week ago)
HTTP header is restricted by policy (/x-middleware-subrequest/). String match within "/content-encod ...
show more
HTTP header is restricted by policy (/x-middleware-subrequest/). String match within "/content-encoding/ /proxy/ /lock-token/ /content-range/ /if/ /x-http-method-override/ /x-http-method/ /x-method-override/ /x-middleware-subrequest/ /expect/" at TX:header_name_920450_x-middleware-subrequest. (920450-201)
show less
Bad Web Bot
๐ช๐ธ
robotstxt
2026-09-27 18:26:19
(1 week ago)
34.79.232.234 - - [27/Sep/2026:18:25:20 +0000] "GET /asset-manifest.json HTTP/2.0" 403 17110 "https: ...
show more
34.79.232.234 - - [27/Sep/2026:18:25:20 +0000] "GET /asset-manifest.json HTTP/2.0" 403 17110 "https://grupofucsa.com/asset-manifest.json" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Mobile Safari/537.36" "-" edge="34.79.232.234"
34.79.232.234 - - [27/Sep/2026:18:25:20 +0000] "GET /jtiwl40y9dk6icb87wmt/ HTTP/2.0" 403 18020 "https://www.grupofucsa.com/jtiwl40y9dk6icb87wmt" "Mozilla/5.0 (compatible; Bravebot/1.0; +https://brave.com/search/)" "-" edge="34.79.232.234"
34.79.232.234 - - [27/Sep/2026:18:25:20 +0000] "GET /static/manifest.json HTTP/2.0" 403 17110 "https://grupofucsa.com/static/manifest.json" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Mobile Safari/537.36" "-" edge="34.79.232.234"
34.79.232.234 - - [27/Sep/2026:18:25:20 +0000] "GET /ksu6orjfv0ilsfli4jfk/ HTTP/2.0" 403 18020 "https://www.grupofucsa.com/ksu6orjfv0ilsfli4jfk" "Mozilla/5.0 (compatible; Amazonbot/0.1; +https://developer.
...
show less
Web App Attack
Anonymous
2026-09-27 18:22:08
(1 week ago)
(mod_security) mod_security triggered on hostname [redacted])
SQL Injection