๐ซ๐ฎ
NoaQT
2026-10-11 03:44:04
(32 minutes ago)
2026-10-11T03:44:04.050124+00:00 ingress-1 haproxy[275]: 34.90.123.252:44320 [11/Oct/2026:03:44:04.0 ...
show more
2026-10-11T03:44:04.050124+00:00 ingress-1 haproxy[275]: 34.90.123.252:44320 [11/Oct/2026:03:44:04.049] https_in~ https_in/<NOSRV> 0/-1/-1/-1/0 429 225 - - PR-- 55/55/0/0/0 0/0 "GET https://git.mentis.si/en-us/ HTTP/2.0"
2026-10-11T03:44:04.054637+00:00 ingress-1 haproxy[275]: 34.90.123.252:44320 [11/Oct/2026:03:44:04.049] https_in~ https_in/<NOSRV> 0/-1/-1/-1/4 429 225 - - PR-- 55/55/0/0/0 0/0 "GET https://git.mentis.si/en-us/ HTTP/2.0"
2026-10-11T03:44:04.054730+00:00 ingress-1 haproxy[275]: 34.90.123.252:44320 [11/Oct/2026:03:44:04.054] https_in~ https_in/<NOSRV> 0/-1/-1/-1/0 429 225 - - PR-- 55/55/0/0/0 0/0 "GET https://git.mentis.si/.github/workflows/deploy.yml HTTP/2.0"
2026-10-11T03:44:04.055259+00:00 ingress-1 haproxy[275]: 34.90.123.252:44320 [11/Oct/2026:03:44:04.054] https_in~ https_in/<NOSRV> 0/-1/-1/-1/0 429 225 - - PR-- 55/55/0/0/0 0/0 "GET https://git.mentis.si/firebase-service-account.json HTTP/2.0"
2026-10-11T03:44:04.056661+00:00 ingress-1 haproxy[275]: 34.90.123.252:
...
show less
DDoS Attack
๐ซ๐ฎ
NoaQT
2026-10-11 00:54:50
(3 hours ago)
2026-10-11T00:54:49.479693+00:00 ingress-1 haproxy[275]: 34.90.123.252:40054 [11/Oct/2026:00:54:49.4 ...
show more
2026-10-11T00:54:49.479693+00:00 ingress-1 haproxy[275]: 34.90.123.252:40054 [11/Oct/2026:00:54:49.479] https_in~ https_in/<NOSRV> 0/-1/-1/-1/0 429 225 - - PR-- 51/51/0/0/0 0/0 "GET https://dev.mentis.si/.ssh/id_ed25519 HTTP/2.0"
2026-10-11T00:54:49.480298+00:00 ingress-1 haproxy[275]: 34.90.123.252:40054 [11/Oct/2026:00:54:49.479] https_in~ https_in/<NOSRV> 0/-1/-1/-1/0 429 225 - - PR-- 51/51/0/0/0 0/0 "GET https://dev.mentis.si/@fs/app/.env?raw?? HTTP/2.0"
2026-10-11T00:54:49.502571+00:00 ingress-1 haproxy[275]: 34.90.123.252:40054 [11/Oct/2026:00:54:49.502] https_in~ https_in/<NOSRV> 0/-1/-1/-1/0 429 225 - - PR-- 51/51/0/0/0 0/0 "POST https://dev.mentis.si/v1/graphql HTTP/2.0"
2026-10-11T00:54:49.526320+00:00 ingress-1 haproxy[275]: 34.90.123.252:40054 [11/Oct/2026:00:54:49.525] https_in~ https_in/<NOSRV> 0/-1/-1/-1/0 429 225 - - PR-- 51/51/0/0/0 0/0 "GET https://dev.mentis.si/@fs/.env?raw&url?? HTTP/2.0"
2026-10-11T00:54:49.526574+00:00 ingress-1 haproxy[275]: 34.90.123.252:40054 [
...
show less
DDoS Attack
๐บ๐ธ
TPI-Abuse
2026-10-10 23:32:00
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.90.123.252 (252.123.90.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.90.123.252 (252.123.90.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 19:31:52.819756 2026] [security2:error] [pid 14225:tid 14225] [client 34.90.123.252:39386] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.ameliaschaaf.lawyer"] [uri "/static../.env"] [unique_id "asrK6J3m3JOSuXWTDDrShQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-10-10 19:26:14
(8 hours ago)
Multiple WAF Violations
Web App Attack
๐ฉ๐ช
updown.io
2026-10-10 18:57:56
(9 hours ago)
{"level":"info","ts":1791658647.4712698,"logger":"http.log.access.log0","msg":"handled request","req ...
show more
{"level":"info","ts":1791658647.4712698,"logger":"http.log.access.log0","msg":"handled request","request":{"remote_ip":"34.90.123.252","remote_port":"36106","client_ip":"34.90.123.252","proto":"HTTP/2.0","method":"GET","host":"0e9u.status.updown.io","uri":"//.env","headers":{"Accept-Encoding":["gzip"],"Accept":["*/*"],"Cookie":["REDACTED"],"X-Middleware-Subrequest":["src/middleware:nowaf:src/middleware:src/middleware:src/middleware:src/middleware:middleware:middleware:nowaf:middleware:middleware:middleware:pages/_middleware"],"X-Nextjs-Data":["1"],"User-Agent":["DuckAssistBot/1.1 (https://duckduckgo.com/duckassistbot)"]},"tls":{"resumed":false,"version":772,"cipher_suite":4865,"proto":"h2","server_name":"0e9u.status.updown.io","ech":false}},"bytes_read":0,"user_id":"","duration":0.000130319,"size":0,"status":429,"resp_headers":{"Server":["Caddy"],"Alt-Svc":["h3=\":443\"; ma=2592000"],"Retry-After":["1"]}}
{"level":"info","ts":1791658647.4725604,"logger":"http.log.access.log0","msg":"ha
...
show less
DDoS Attack
Web App Attack
๐ณ๐ฑ
Savvii
2026-10-10 18:25:57
(9 hours ago)
20 attempts against mh-misbehave-ban on chive
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-10-10 18:20:09
(9 hours ago)
HTTP header is restricted by policy (/x-middleware-subrequest/). String match within "/content-encod ...
show more
HTTP header is restricted by policy (/x-middleware-subrequest/). String match within "/content-encoding/ /proxy/ /lock-token/ /content-range/ /if/ /x-http-method-override/ /x-http-method/ /x-method-override/ /x-middleware-subrequest/ /expect/" at TX:header_name_920450_x-middleware-subrequest. (920450-197)
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-10 17:48:20
(10 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.90.123.252 (252.123.90.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.90.123.252 (252.123.90.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 13:48:17.517109 2026] [security2:error] [pid 12332:tid 12332] [client 34.90.123.252:58790] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||zoticus.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "zoticus.com"] [uri "/z9x8c7v6b5-debug-trigger-zoticus.com"] [unique_id "asp6YaMMsXepQvocQlvN3wAAAEM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-10 17:40:09
(10 hours ago)
| Multiple common web attacks from same source ip. (multiple servers)
Web App Attack
Hacking
SQL Injection
๐ณ๐ฑ
Site.eu
2026-10-10 17:30:27
(10 hours ago)
Excessive multi-domain requests
Brute-Force
๐จ๐ญ
zynex
2026-10-10 17:15:09
(11 hours ago)
URL Probing: /@fs/app/.env
Web App Attack
Anonymous
2026-10-10 17:12:14
(11 hours ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
๐ซ๐ฎ
NoaQT
2026-10-10 16:57:58
(11 hours ago)
2026-10-10T16:57:57.807922+00:00 ingress-1 haproxy[275]: 34.90.123.252:41156 [10/Oct/2026:16:57:57.8 ...
show more
2026-10-10T16:57:57.807922+00:00 ingress-1 haproxy[275]: 34.90.123.252:41156 [10/Oct/2026:16:57:57.807] https_in~ https_in/<NOSRV> 0/-1/-1/-1/0 429 225 - - PR-- 128/128/0/0/0 0/0 "POST https://mentis.si/api/graphql HTTP/2.0"
2026-10-10T16:57:57.820933+00:00 ingress-1 haproxy[275]: 34.90.123.252:41156 [10/Oct/2026:16:57:57.820] https_in~ https_in/<NOSRV> 0/-1/-1/-1/0 429 225 - - PR-- 128/128/0/0/0 0/0 "GET https://mentis.si/@fs/home/ec2-user/.aws/credentials?raw?? HTTP/2.0"
2026-10-10T16:57:57.830148+00:00 ingress-1 haproxy[275]: 34.90.123.252:41156 [10/Oct/2026:16:57:57.829] https_in~ https_in/<NOSRV> 0/-1/-1/-1/0 429 225 - - PR-- 128/128/0/0/0 0/0 "GET https://mentis.si/%2e%2e/.env HTTP/2.0"
2026-10-10T16:57:57.839671+00:00 ingress-1 haproxy[275]: 34.90.123.252:41156 [10/Oct/2026:16:57:57.839] https_in~ https_in/<NOSRV> 0/-1/-1/-1/0 429 225 - - PR-- 128/128/0/0/0 0/0 "GET https://mentis.si/.bashrc HTTP/2.0"
2026-10-10T16:57:57.840179+00:00 ingress-1 haproxy[275]: 34.90.123.252:41156 [
...
show less
DDoS Attack
๐ฉ๐ช
webko.si
2026-10-10 16:41:50
(11 hours ago)
JZKK: Bruteforce web app access, URI detail: '/backend/.env'.
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-10 16:41:43
(11 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.90.123.252 (252.123.90.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.90.123.252 (252.123.90.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 12:41:35.591958 2026] [security2:error] [pid 16737:tid 16737] [client 34.90.123.252:39446] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||justmakingitbetter.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "justmakingitbetter.com"] [uri "/z9x8c7v6b5-debug-trigger-justmakingitbetter.com"] [unique_id "aspqv6_SjOcaY8stDKMKAQAAACg"]
show less
Brute-Force
Bad Web Bot
Web App Attack