๐บ๐ธ
alsmanifesto
2026-10-05 14:44:46
(1 day ago)
Enumerated hostnames across our wildcard domain (activate.fluentops.org) against fluentops.org. 288 ...
show more
Enumerated hostnames across our wildcard domain (activate.fluentops.org) against fluentops.org. 288 requests, 2026-10-05 14:44:46 UTC. Blocked at our edge.
show less
Port Scan
Bad Web Bot
๐ฉ๐ช
Melle
2026-10-05 14:41:17
(1 day ago)
Blocked by CrowdSec | Scenario: crowdsecurity/http-probing | 34.80.14.129 triggered 11 events | Dete ...
show more
Blocked by CrowdSec | Scenario: crowdsecurity/http-probing | 34.80.14.129 triggered 11 events | Detected: 2026-10-05T14:41:16.190078221Z
show less
Web App Attack
Hacking
๐ฉ๐ช
ghostwarriors
2026-10-05 14:20:04
(1 day ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
Anonymous
2026-10-05 12:05:07
(1 day ago)
WAF repeated trigger detected by Fail2Ban
Web App Attack
๐ฑ๐น
NotACaptcha
2026-10-05 12:01:25
(1 day ago)
webserver:443 [05/Oct/2026] "GET /.ssh/id_rsa HTTP/1.1" 302 449 "-" "Mozilla/5.0 (compatible; Brave ...
show more
webserver:443 [05/Oct/2026] "GET /.ssh/id_rsa HTTP/1.1" 302 449 "-" "Mozilla/5.0 (compatible; Bravebot/1.0; +https://brave.com/search/)"
webserver:443 [05/Oct/2026] "GET /.htpasswd HTTP/1.1" 302 445 "-" "Mozilla/5.0 (compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot)"
webserver:443 [05/Oct/2026] "GET /z9x8c7v6b5-debug-trigger-_mta-sts.www.ashunledevles.duckdns.org HTTP/1.1" 302 5919 "-" "Mozilla/5.0 (compatible; MoonshotBot/1.0; +https://kimi.ai/)"
webserver:443 [05/Oct/2026] "GET /.ssh/config HTTP/1.1" 404 408 "https://_mta-sts.www.ashunledevles.duckdns.org/.ssh/config" "Mozilla/5.0 (compatible; DeepSeekBot/1.0; +https://www.deepseek.com/)"
webserver:443 [05/Oct/2026] "GET /.ssh/id_ed25519 HTTP/1.1" 404 408 "https://_mta-sts.www.ashunledevles.duckdns.org/.ssh/id_ed25519" "Mozilla/5.0 (compatible; MistralAI-User/1.0; +https://mistral.ai/)"
webserver:443 [05/Oct/2026] "GET /graphql HTTP/1.1" 404 5742 "https://_mta-sts.www.ashunledevles.duckdns.org" "Mozill...
show less
Web App Attack
๐ซ๐ท
geot
2026-10-05 11:56:42
(1 day ago)
GET /.well-known/jwks.json HTTP/1.1
DELETE /api/inngest HTTP/1.1
GET /@fs/home/ubuntu/.aws/credentia ...
show more
GET /.well-known/jwks.json HTTP/1.1
DELETE /api/inngest HTTP/1.1
GET /@fs/home/ubuntu/.aws/credentials?raw?? HTTP/1.1
GET /admin/.env HTTP/1.1
show less
Port Scan
Hacking
Web App Attack
๐ช๐ธ
masterguru
2026-10-05 11:55:19
(1 day ago)
BAD BOT - Detected and Blocked.. Matched phrase "ccbot" at REQUEST_HEADERS:user-agent. (1100000-122)
Bad Web Bot
๐ฉ๐ช
dbmwebdesign
2026-10-05 11:45:20
(1 day ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
๐ช๐ธ
robotstxt
2026-10-05 11:38:51
(1 day ago)
34.80.14.129 - - [05/Oct/2026:11:38:34 +0000] "GET /..%2f.env HTTP/1.1" 400 193 "-" "-" "-" edge="34 ...
show more
34.80.14.129 - - [05/Oct/2026:11:38:34 +0000] "GET /..%2f.env HTTP/1.1" 400 193 "-" "-" "-" edge="34.80.14.129"
34.80.14.129 - - [05/Oct/2026:11:38:34 +0000] "GET /%2e%2e/.env HTTP/1.1" 400 193 "-" "-" "-" edge="34.80.14.129"
34.80.14.129 - - [05/Oct/2026:11:38:34 +0000] "GET /icons/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/proc/self/environ HTTP/1.1" 400 193 "-" "-" "-" edge="34.80.14.129"
34.80.14.129 - - [05/Oct/2026:11:38:34 +0000] "GET /..%2f..%2f.env HTTP/1.1" 400 193 "-" "-" "-" edge="34.80.14.129"
34.80.14.129 - - [05/Oct/2026:11:38:47 +0000] "POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh HTTP/1.1" 400 193 "-" "-" "-" edge="34.80.14.129"
...
show less
Web Spam
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 11:38:41
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.80.14.129 (129.14.80.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.14.129 (129.14.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 07:38:35.967059 2026] [security2:error] [pid 20295:tid 20295] [client 34.80.14.129:50400] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wpcoc.org"] [uri "/.htpasswd"] [unique_id "asOMO-F4Q-7YvSyhSnRkSQAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
pixiekat
2026-10-05 11:11:41
(1 day ago)
[Mon Oct 05 11:11:39.389748 2026] [security2:error] [pid 25611:tid 25650] [client 34.80.14.129:37634 ...
show more
[Mon Oct 05 11:11:39.389748 2026] [security2:error] [pid 25611:tid 25650] [client 34.80.14.129:37634] [client 34.80.14.129] ModSecurity: Access denied with code 403 (phase 1). Pattern match ".+" at REQUEST_HEADERS:Next-Action. [file "/etc/apache2/crs-custom.conf"] [line "14"] [id "9000100"] [msg "Next.js Server Action probe blocked (no Next.js apps on this server)"] [tag "custom/next-action-recon"] [hostname "warnerslack.org"] [uri "/"] [unique_id "asOF69oiyyizJmlMyTG9nAAAABY"]
[Mon Oct 05 11:11:40.561494 2026] [security2:error] [pid 25612:tid 25642] [client 34.80.14.129:37740] [client 34.80.14.129] ModSecurity: Access denied with code 403 (phase 1). Pattern match ".+" at REQUEST_HEADERS:Next-Action. [file "/etc/apache2/crs-custom.conf"] [line "14"] [id "9000100"] [msg "Next.js Server Action probe blocked (no Next.js apps on this server)"] [tag "custom/next-action-recon"] [hostname "warnerslack.org"] [uri "/login"] [unique_id "asOF7DCA98f-TjUK__QJbQAAAEg"]
[Mon Oct 05 11:11:40.857090 2
...
show less
Web App Attack
๐ฉ๐ช
LRob
2026-10-05 10:47:09
(1 day ago)
Not following 301 redirects โ wasted requests | method: GET | path: / | ua: Mozilla/5.0 (Macintosh; ...
show more
Not following 301 redirects โ wasted requests | method: GET | path: / | ua: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-05 10:43:05
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.80.14.129 (129.14.80.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.14.129 (129.14.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 06:42:58.074397 2026] [security2:error] [pid 11123:tid 11123] [client 34.80.14.129:59014] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "untraceable.org"] [uri "/.htpasswd"] [unique_id "asN_MpUXMCoi5_hDwwsLtAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Mundo Bueno
2026-10-05 10:29:27
(1 day ago)
[ISILIA Protection v2.3] Tentative d'accรจs: /api/.env/public/.env [RATE LIMITED - 1800s quarantine] ...
show more
[ISILIA Protection v2.3] Tentative d'accรจs: /api/.env/public/.env [RATE LIMITED - 1800s quarantine] | Pays: TW | UA: DuckAssistBot/1.1 (https://duckduckgo.com/duckassistbot)
show less
Hacking
Web App Attack
๐บ๐ธ
JonathanYoung2161
2026-10-05 10:25:23
(1 day ago)
trekgalactic.org 34.80.14.129 - - [05/Oct/2026:05:25:21 -0500] "GET /cache/original/%2e%2e/%2e%2e/.e ...
show more
trekgalactic.org 34.80.14.129 - - [05/Oct/2026:05:25:21 -0500] "GET /cache/original/%2e%2e/%2e%2e/.env HTTP/2.0" 403 3171 "-" "Mozilla/5.0 (compatible; xAI-Grok/1.0; +https://x.ai/)"
trekgalactic.org 34.80.14.129 - - [05/Oct/2026:05:25:21 -0500] "GET /api/fs/read?allowOutsideWorkspace=true&path=/app/.env HTTP/2.0" 404 3199 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Safari/605.1.15 (Applebot/0.1)"
trekgalactic.org 34.80.14.129 - - [05/Oct/2026:05:25:21 -0500] "GET /userfiles?path=../../.env HTTP/2.0" 404 3199 "-" "Mozilla/5.0 (compatible; YouBot/1.0; +https://you.com/bot)"
...
show less
Brute-Force
Web App Attack