Anonymous
2026-09-20 14:24:09
(6 minutes ago)
34.83.255.195 - - [20/Sep/2026:16:24:08 +0200] "GET / HTTP/1.1" 403 183 "-" "Mozilla/5.0 (X11; Linux ...
show more
34.83.255.195 - - [20/Sep/2026:16:24:08 +0200] "GET / HTTP/1.1" 403 183 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36"
34.83.255.195 - - [20/Sep/2026:16:24:08 +0200] "GET /z9x8c7v6b5-debug-trigger-georvice.com HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36; compatible; OAI-SearchBot/1.4; +https://openai.com/searchbot"
34.83.255.195 - - [20/Sep/2026:16:24:08 +0200] "GET /.env.example HTTP/1.1" 403 124 "-" "Mozilla/5.0 (compatible; YiBot/1.0; +https://01.ai/)"
34.83.255.195 - - [20/Sep/2026:16:24:08 +0200] "GET /api/v1/settings HTTP/1.1" 403 124 "-" "Mozilla/5.0 (compatible; Meta-ExternalAgent/1.0; +https://developers.facebook.com/docs/sharing/webmasters/crawler)"
34.83.255.195 - - [20/Sep/2026:16:24:08 +0200] "POST / HTTP/1.1" 403 124 "-" "Mozilla/5.0 (compatible; MoonshotBot/1.0; +https://kimi.ai/)"
34.83.255.195 - - [20/Sep/2026:16:
...
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-09-20 14:20:10
(10 minutes ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 14:08:35
(22 minutes ago)
(mod_security) mod_security (id:210730) triggered by 34.83.255.195 (195.255.83.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.83.255.195 (195.255.83.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 10:08:28.606796 2026] [security2:error] [pid 9142:tid 9142] [client 34.83.255.195:36340] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||georgesmarina.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "georgesmarina.com"] [uri "/z9x8c7v6b5-debug-trigger-georgesmarina.com"] [unique_id "aq_o3NHTdQGdQHTo8UPj9AAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-09-20 14:05:14
(25 minutes ago)
Scanning/Probing (24)
Brute-Force
Web App Attack
๐ฉ๐ช
yitzhaq
2026-09-20 14:03:04
(27 minutes ago)
34.83.255.195 - - [20/Sep/2026:16:03:02 +0200] "GET /manage/env HTTP/2.0" 404 297 "-" "Mozilla/5.0 ( ...
show more
34.83.255.195 - - [20/Sep/2026:16:03:02 +0200] "GET /manage/env HTTP/2.0" 404 297 "-" "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)"
34.83.255.195 - - [20/Sep/2026:16:03:02 +0200] "GET /api/env HTTP/2.0" 403 299 "-" "Mozilla/5.0 (compatible; Bytespider; [email]) AppleWebKit/537.36"
34.83.255.195 - - [20/Sep/2026:16:03:02 +0200] "GET /debug/vars HTTP/2.0" 404 297 "-" "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)"
34.83.255.195 - - [20/Sep/2026:16:03:02 +0200] "GET /api/v1/.env HTTP/2.0" 403 299 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; [email])"
34.83.255.195 - - [20/Sep/2026:16:03:02 +0200] "GET /runtime-config.js HTTP/2.0" 403 299 "-" "Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; +https://kimi.ai/)"
34.83.255.195 - - [20/Sep/2026:16:03:02 +0200] "GET /debug/pprof HTTP/2.0" 404 297 "-" "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)
show less
Bad Web Bot
๐ณ๐ฑ
Savvii
2026-09-20 14:00:50
(29 minutes ago)
20 attempts against mh-misbehave-ban on onion
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
bazter.pro
2026-09-20 13:50:01
(40 minutes ago)
Fail2Ban: plesk-bot-aggressive - 15 failures
Port Scan
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 13:48:43
(41 minutes ago)
(mod_security) mod_security (id:210730) triggered by 34.83.255.195 (195.255.83.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.83.255.195 (195.255.83.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 09:48:39.468897 2026] [security2:error] [pid 2894545:tid 2894545] [client 34.83.255.195:41386] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||geo-modal.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "geo-modal.com"] [uri "/z9x8c7v6b5-debug-trigger-geo-modal.com"] [unique_id "aq_kNxNDfzhpcEReoAphJAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-20 13:37:15
(53 minutes ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
๐ซ๐ท
dynamix
2026-09-20 13:30:21
(1 hour ago)
Multiple WAF Violations
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-20 13:23:52
(1 hour ago)
Excessive multi-domain requests
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-20 13:15:58
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.83.255.195 (195.255.83.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.83.255.195 (195.255.83.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 09:15:53.838757 2026] [security2:error] [pid 7142:tid 7142] [client 34.83.255.195:35366] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "genevaatlantic.com"] [uri "/.env.prod"] [unique_id "aq_ciTWIp8jPK5zwyf3E6QAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-20 12:59:43
(1 hour ago)
Automatically blocked after 55 security events. Observed sensitive configuration-file probes. Source ...
show more
Automatically blocked after 55 security events. Observed sensitive configuration-file probes. Source: Cloudflare security controls.
show less
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 12:57:24
(1 hour ago)
(mod_security) mod_security (id:210730) triggered by 34.83.255.195 (195.255.83.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.83.255.195 (195.255.83.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 08:57:16.888626 2026] [security2:error] [pid 17450:tid 17450] [client 34.83.255.195:43712] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||g-h2o.com|F|2"] [data ".env.backup"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "g-h2o.com"] [uri "/.env.backup"] [unique_id "aq_YLHt8EvdnXPpG-2IT6gAAADg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Savvii
2026-09-20 12:51:11
(1 hour ago)
61 attempts against mh-misbehave-ban on twig
Brute-Force
Bad Web Bot
Web App Attack