๐ง๐ช
cmbplf
2026-10-02 07:04:15
(1 day ago)
2.202 requests from abuseipdb.com blacklisted IP (1yr10mos3w)
Brute-Force
Bad Web Bot
๐ฉ๐ช
updown.io
2026-10-02 05:19:30
(2 days ago)
{"level":"info","ts":1790918365.0571833,"logger":"http.log.access.log1","msg":"handled request","req ...
show more
{"level":"info","ts":1790918365.0571833,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"34.95.170.59","remote_port":"44370","client_ip":"34.95.170.59","proto":"HTTP/2.0","method":"GET","host":"status.lmdmax.com","uri":"/assets/manifest.json","headers":{"X-Middleware-Subrequest":["src/middleware:nowaf:src/middleware:src/middleware:src/middleware:src/middleware:middleware:middleware:nowaf:middleware:middleware:middleware:pages/_middleware"],"Sec-Ch-Ua":["\"Not=A?Brand\";v=\"99\", \"Google Chrome\";v=\"151\", \"Chromium\";v=\"151\""],"Sec-Ch-Ua-Mobile":["?0"],"Accept-Encoding":["gzip, deflate, br, zstd"],"Accept":["*/*"],"Sec-Fetch-Dest":["script"],"Sec-Ch-Ua-Platform":["\"Windows\""],"X-Nextjs-Data":["1"],"Sec-Fetch-Site":["same-origin"],"Accept-Language":["en-US,en;q=0.9"],"Priority":["u=1"],"Sec-Fetch-Mode":["no-cors"],"User-Agent":["Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"]},"tls":{
...
show less
DDoS Attack
Web App Attack
๐บ๐ธ
dtorrer
2026-10-02 05:17:50
(2 days ago)
General vulnerability scan.
Port Scan
Anonymous
2026-10-02 05:14:55
(2 days ago)
(mod_security) mod_security triggered on hostname [redacted] 34.95.170.59 (BR/Brazil/59.170.95.34.bc ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.95.170.59 (BR/Brazil/59.170.95.34.bc.googleusercontent.com)
show less
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-10-02 03:43:23
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.95.170.59 (59.170.95.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.95.170.59 (59.170.95.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 23:43:18.957592 2026] [security2:error] [pid 6828:tid 6828] [client 34.95.170.59:46476] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.haroturkiye.com"] [uri "/files../.env"] [unique_id "ar8oVqElmIrmTyMly9XXNQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TAY
2026-10-02 02:37:13
(2 days ago)
34.95.170.59 - - [02/Oct/2026:10:37:06 +0800] "GET /@fs/../.env?raw?? HTTP/1.1" 301 467 "-" "Mozilla ...
show more
34.95.170.59 - - [02/Oct/2026:10:37:06 +0800] "GET /@fs/../.env?raw?? HTTP/1.1" 301 467 "-" "Mozilla/5.0 (compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot)"
34.95.170.59 - - [02/Oct/2026:10:37:08 +0800] "GET /@fs/../.env?import&raw?? HTTP/1.1" 301 485 "-" "Mozilla/5.0 (compatible; YouBot/1.0; +https://you.com/bot)"
34.95.170.59 - - [02/Oct/2026:10:37:11 +0800] "GET /_nuxt/../.env HTTP/1.1" 301 455 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot)"
34.95.170.59 - - [02/Oct/2026:10:37:12 +0800] "GET /public/plugins/alertlist/../../../../../../../../proc/self/environ HTTP/1.1" 301 474 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexitybot)"
34.95.170.59 - - [02/Oct/2026:10:37:13 +0800] "GET /public/plugins/grafana-clock-panel/../../../../../../../../proc/self/environ HTTP/1.1" 301 474 "-" "CCBot/2.0 (https://commoncrawl
...
show less
Brute-Force
๐บ๐ธ
jormaster3k
2026-10-02 01:51:21
(2 days ago)
Attack against Apache (too many 404s)
Web App Attack
๐ฉ๐ช
Gwyneth Llewelyn
2026-10-02 01:27:52
(2 days ago)
2026/10/02 02:27:48 [error] 2513#2513: *81627 access forbidden by rule, client: 34.95.170.59, server ...
show more
2026/10/02 02:27:48 [error] 2513#2513: *81627 access forbidden by rule, client: 34.95.170.59, server: feminina.eu, request: "GET /images../.env HTTP/2.0", host: "feminina.eu"
2026/10/02 02:27:50 [error] 2513#2513: *81641 access forbidden by rule, client: 34.95.170.59, server: feminina.eu, request: "GET /static../.env HTTP/2.0", host: "feminina.eu"
2026/10/02 02:27:50 [error] 2513#2513: *81643 access forbidden by rule, client: 34.95.170.59, server: feminina.eu, request: "GET /media../.env HTTP/2.0", host: "feminina.eu"
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 01:16:23
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.95.170.59 (59.170.95.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.95.170.59 (59.170.95.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 21:16:16.903162 2026] [security2:error] [pid 22428:tid 22474] [client 34.95.170.59:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.humanet.io"] [uri "/images../.env"] [unique_id "ar8F4Jgwr0h6iMXk7OYUhQAAAZE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
bazter.pro
2026-10-01 23:22:39
(2 days ago)
Fail2Ban: plesk-bot-aggressive - 15 failures
Port Scan
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-10-01 23:09:35
(2 days ago)
[cb-06al] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail ngin ...
show more
[cb-06al] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail nginx-404. Example: 34.95.170.59 - - [02/Oct/2026:01:09:29 +0200] "POST /lib/terminal-xhr.php HTTP/2.0" 404 1338 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-SearchBot/1.0; [email protected] )"
34.95.170.59 - - [02/Oct/2026:01:09:29 +0200] "GET /dist/.vite/manifest.json HTTP/2.0" 404 1338 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36 Edg/153.0.0.0"
34.95.170.59 - - [02/Oct/2026:01:09:29 +0200] "GET /.vite/manifest.json HTTP/2.0" 404 1338 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36 Edg/153.0.0.0"
34.95.170.59 - - [02/Oct/2026:01:09:30 +0200] "POST /icecoder/lib/terminal-xhr.php HTTP/2.0" 404 1338 "-" "Mozilla/5.0 (compati
...
show less
Bad Web Bot
Web App Attack
๐น๐ท
ycoskun41
2026-10-01 22:30:50
(2 days ago)
fail2ban: plesk-modsecurity jail on genckocaeli.com
Web App Attack
๐ง๐ท
govfacil.app
2026-10-01 21:23:35
(2 days ago)
(cpanel) Failed cPanel login from 34.95.170.59 (BR/Brazil/59.170.95.34.bc.googleusercontent.com): 50 ...
show more
(cpanel) Failed cPanel login from 34.95.170.59 (BR/Brazil/59.170.95.34.bc.googleusercontent.com): 50 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CPANEL; Logs: [2026-10-01 18:23:29 -0300] info [cpaneld] 34.95.170.59 - - "GET /dist/.vite/manifest.json HTTP/1.1" FAILED LOGIN cpaneld: login attempt without username
[2026-10-01 18:23:29 -0300] info [cpaneld] 34.95.170.59 - - "GET /firebase-config.json HTTP/1.1" FAILED LOGIN cpaneld: login attempt without username
[2026-10-01 18:23:29 -0300] info [cpaneld] 34.95.170.59 - - "POST /graphql HTTP/1.1" FAILED LOGIN cpaneld: login attempt without username
[2026-10-01 18:23:29 -0300] info [cpaneld] 34.95.170.59 - - "GET /api/config HTTP/1.1" FAILED LOGIN cpaneld: login attempt without username
[2026-10-01 18:23:29 -0300] info [cpaneld] 34.95.170.59 - - "GET /api/v1/env HTTP/1.1" FAILED LOGIN cpaneld: login attempt without username
[2026-10-01 18:23:29 -0300] info [cpaneld] 34.95.170.59 - - "GET /settings.json HTTP/1.1" FAILED LOG [truncated]
show less
Brute-Force
Anonymous
2026-10-01 21:22:26
(2 days ago)
(mod_security) mod_security triggered on hostname [redacted])
SQL Injection
๐จ๐ญ
4server
2026-10-01 20:06:47
(2 days ago)
[ThuOct0122:06:42.3110452026][security2:error][pid3934110:tid3934114][client34.95.170.59:0]ModSecuri ...
show more
[ThuOct0122:06:42.3110452026][security2:error][pid3934110:tid3934114][client34.95.170.59:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".env\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"710\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"cpanel.edilmarra.ch\"][uri\"/uploads../.env\"][unique_id\"ar69Uus3I8NZikk8BjIbxAAAAEI\"]
show less
Hacking
Web App Attack