๐บ๐ธ
zcampbell
2026-10-05 17:52:16
(6 hours ago)
Web vulnerability scanning: probing for exposed sensitive files (.ssh). Detected and blocked automat ...
show more
Web vulnerability scanning: probing for exposed sensitive files (.ssh). Detected and blocked automatically.
show less
Web App Attack
Bad Web Bot
๐ฌ๐ง
pinguin
2026-10-05 15:54:21
(8 hours ago)
Triggered Cloudflare WAF (firewallManaged) from JP.
Action taken: BLOCK
Protocol: HTTP/2 (POST metho ...
show more
Triggered Cloudflare WAF (firewallManaged) from JP.
Action taken: BLOCK
Protocol: HTTP/2 (POST method)
Endpoint: /cgi-bin/php-cgi
UA: Mozilla/5.0 (compatible; MoonshotBot/1.0; +https://kimi.ai/)
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ฌ๐ง
thetomtaylor.co.uk
2026-10-05 13:07:01
(11 hours ago)
Fail2Ban - [NGINX]WordPress Logins Sniffings on nginx-wordpress-sniffer ... [mx02,wa02]
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 11:01:24
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.85.46.220 (220.46.85.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.85.46.220 (220.46.85.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 07:01:19.223875 2026] [security2:error] [pid 14191:tid 14191] [client 34.85.46.220:59624] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.flybits.co.uk"] [uri "/.htpasswd"] [unique_id "asODf3RpkbesC2KyHz4lagAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 10:42:47
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.85.46.220 (220.46.85.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.85.46.220 (220.46.85.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 06:42:42.002760 2026] [security2:error] [pid 19265:tid 19265] [client 34.85.46.220:34570] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autoconfig.zenventures.co.uk"] [uri "/img../.env"] [unique_id "asN_IlcmF4DwKEST-1RSdwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
CrownSync.uk
2026-10-05 10:26:51
(13 hours ago)
Automated detection: repeated HTTP 4xx scan-burst against a public web endpoint.
Port Scan
Web App Attack
๐ฌ๐ง
Aetherweb Ark
2026-10-05 10:07:19
(14 hours ago)
(mod_security) mod_security (id:949110) triggered by 34.85.46.220 (JP/Japan/220.46.85.34.bc.googleus ...
show more
(mod_security) mod_security (id:949110) triggered by 34.85.46.220 (JP/Japan/220.46.85.34.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
๐ณ๐ฑ
pearbright
2026-10-05 10:06:21
(14 hours ago)
[Mon Oct 05 10:06:17.317368 2026] [core:error] [pid 2048054:tid 2048054] [client 34.85.46.220:48498] ...
show more
[Mon Oct 05 10:06:17.317368 2026] [core:error] [pid 2048054:tid 2048054] [client 34.85.46.220:48498] AH10244: invalid URI path (/public/plugins/text/../../../../../../../../proc/self/environ)
[Mon Oct 05 10:06:21.706139 2026] [core:error] [pid 2048265:tid 2048265] [client 34.85.46.220:58460] AH10244: invalid URI path (/%2e%2e/%2e%2e/%2e%2e/%2e%2e/.env)
...
show less
Web App Attack
๐ธ๐ฌ
simpeg-adm.bandung.go.id
2026-10-05 09:07:47
(15 hours ago)
05/Oct/2026:09:07:46 +0000;34.85.46.220;"/f37fvc6qzxx3bqehuz23"
05/Oct/2026:09:07:46 +0000;34.85.46. ...
show more
05/Oct/2026:09:07:46 +0000;34.85.46.220;"/f37fvc6qzxx3bqehuz23"
05/Oct/2026:09:07:46 +0000;34.85.46.220;"/dist/.vite/manifest.json"
05/Oct/2026:09:07:46 +0000;34.85.46.220;"/z9x8c7v6b5-debug-trigger-app.alexbucklandphotography.co.uk"
05/Oct/2026:09:07:46 +0000;34.85.46.220;"/u58fb56vqf6fqd5tdm0r"
05/Oct/2026:09:07:46 +0000;34.85.46.220;"/dist/manifest.json"
05/Oct/2026:09:07:46 +0000;34.85.46.220;"/lib/terminal-xhr.php"
05/Oct/2026:09:07:46 +0000;34.85.46.220;"/.vite/manifest.json"
...
show less
Web Spam
Brute-Force
Web App Attack
๐ฏ๐ต
ki3
2026-10-05 08:35:30
(15 hours ago)
Fail2Ban: Web App Attacks and Forum Spam 34.85.46.220 1791189329.0(JST)
Web Spam
Bad Web Bot
Web App Attack
Anonymous
2026-10-05 08:27:14
(15 hours ago)
[Mon Oct 05 08:27:12.562589 2026] [authz_core:error] [pid 445454:tid 445492] [client 34.85.46.220:49 ...
show more
[Mon Oct 05 08:27:12.562589 2026] [authz_core:error] [pid 445454:tid 445492] [client 34.85.46.220:49626] AH01630: client denied by server configuration: /srv/www/erp.gassycat.co.uk/htdocs/
[Mon Oct 05 08:27:12.821552 2026] [authz_core:error] [pid 445454:tid 445496] [client 34.85.46.220:49626] AH01630: client denied by server configuration: /srv/www/erp.gassycat.co.uk/htdocs/users
[Mon Oct 05 08:27:13.068117 2026] [authz_core:error] [pid 445454:tid 445486] [client 34.85.46.220:49626] AH01630: client denied by server configuration: /srv/www/erp.gassycat.co.uk/htdocs/login
[Mon Oct 05 08:27:13.342462 2026] [authz_core:error] [pid 445454:tid 445503] [client 34.85.46.220:49626] AH01630: client denied by server configuration: /srv/www/erp.gassycat.co.uk/htdocs/account
[Mon Oct 05 08:27:13.568638 2026] [authz_core:error] [pid 445454:tid 445502] [client 34.85.46.220:49630] AH01630: client denied by server configuration: /srv/www/erp.gassycat.co.uk/htdocs/secure
...
show less
Brute-Force
๐ฌ๐ง
sc user
2026-10-05 08:22:37
(15 hours ago)
Fail2Ban nginx: repeated suspicious HTTP requests consistent with automated probing, scanning or bad ...
show more
Fail2Ban nginx: repeated suspicious HTTP requests consistent with automated probing, scanning or bad bot behaviour. Technical log details and local server identifiers intentionally omitted for privacy.
show less
Bad Web Bot
Web App Attack
Port Scan
๐ฌ๐ง
Artelis
2026-10-05 08:18:28
(15 hours ago)
34.85.46.220 - - [05/Oct/2026:08:18:27 +0000] "GET /hdvku7i4y96513xwoyxi HTTP/2.0" 404 146 "-" "Mozi ...
show more
34.85.46.220 - - [05/Oct/2026:08:18:27 +0000] "GET /hdvku7i4y96513xwoyxi HTTP/2.0" 404 146 "-" "Mozilla/5.0 (compatible; GrokBot/1.0; +https://x.ai/)"
34.85.46.220 - - [05/Oct/2026:08:18:27 +0000] "GET /auth/login HTTP/2.0" 404 167 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36"
34.85.46.220 - - [05/Oct/2026:08:18:27 +0000] "GET /users/login HTTP/2.0" 404 167 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36"
34.85.46.220 - - [05/Oct/2026:08:18:27 +0000] "GET /sign-in HTTP/2.0" 404 167 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36"
34.85.46.220 - - [05/Oct/2026:08:18:27 +0000] "GET /auth HTTP/2.0" 404 167 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36"
34.85.46.220 - - [05/Oct/2026:08:18:27 +0000] "GET /secure HTTP/2.0" 404 167 "-" "Mozilla/5.0 (X11; L
...
show less
Web App Attack
Anonymous
2026-10-05 06:35:54
(17 hours ago)
34.85.46.220 - - [05/Oct/2026:00:58:25 -0500] "GET /.env?raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 (com ...
show more
34.85.46.220 - - [05/Oct/2026:00:58:25 -0500] "GET /.env?raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; MistralAI-User/1.0; +https://mistral.ai/)" 34.85.46.220
34.85.46.220 - - [05/Oct/2026:01:35:52 -0500] "GET /.env?raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; DeepSeekBot/1.0; +https://www.deepseek.com/)" 34.85.46.220
34.85.46.220 - - [05/Oct/2026:01:35:52 -0500] "GET /.env?import&raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; GPTBot/1.4; +https://openai.com/gptbot" 34.85.46.220
34.85.46.220 - - [05/Oct/2026:01:35:52 -0500] "GET /.env?import&url&inline HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; YiBot/1.0; +https://01.ai/)" 34.85.46.220
34.85.46.220 - - [05/Oct/2026:01:35:52 -0500] "GET /.env.local?raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; Bravebot/1.0; +https://brave.com/search/)" 34.85.46.220
34.85.46.220 - - [05/Oct/2026:01:35:52 -0500] "GET /.env.local?import&raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; x
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
snappic
2026-10-05 06:24:35
(17 hours ago)
Scanning for .env files [GET /api/fs/read?allowOutsideWorkspace=true&path=/app/.env] [Mozilla/5.0 (c ...
show more
Scanning for .env files [GET /api/fs/read?allowOutsideWorkspace=true&path=/app/.env] [Mozilla/5.0 (compatible; MistralAI-User/1.0; +https://mistral.ai/)]
show less
Bad Web Bot
Web App Attack