๐ง๐ช
cmbplf
2026-09-24 00:41:54
(55 minutes ago)
3.895 requests from abuseipdb.com blacklisted IP (1mo4w10h)
Brute-Force
Bad Web Bot
๐ณ๐ฑ
Savvii
2026-09-23 23:59:32
(1 hour ago)
23 attempts against mh-misbehave-ban on twig
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
robotstxt
2026-09-23 23:50:00
(1 hour ago)
34.95.209.114 - - [23/Sep/2026:23:49:29 +0000] "GET /config/.env HTTP/2.0" 403 49561 "https://www.ec ...
show more
34.95.209.114 - - [23/Sep/2026:23:49:29 +0000] "GET /config/.env HTTP/2.0" 403 49561 "https://www.economipedia.com/config/.env" "Mozilla/5.0 (compatible; Meta-ExternalAgent/1.0; +https://developers.facebook.com/docs/sharing/webmasters/crawler)" "-"
34.95.209.114 - - [23/Sep/2026:23:49:29 +0000] "GET /src/.env HTTP/2.0" 403 49633 "https://www.economipedia.com/src/.env" "Mozilla/5.0 (compatible; YiBot/1.0; +https://01.ai/)" "-"
34.95.209.114 - - [23/Sep/2026:23:49:30 +0000] "GET /app/.env HTTP/2.0" 403 49641 "https://www.economipedia.com/app/.env" "Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; +https://kimi.ai/)" "-"
34.95.209.114 - - [23/Sep/2026:23:49:30 +0000] "GET /web/.env HTTP/2.0" 403 49641 "https://www.economipedia.com/web/.env" "Mozilla/5.0 (compatible; Qwenbot/1.0; +https://qwen.alibaba.com/)" "-"
34.95.209.114 - - [23/Sep/2026:23:49:30 +0000] "GET /frontend/.env HTTP/2.0" 403 49641 "https://www.economipedia.com/frontend/.env" "Mozilla/5.0 (compatible; YiBot/1.0; +https://01.ai/
...
show less
Web App Attack
Anonymous
2026-09-23 23:45:41
(1 hour ago)
XSS Attempt
Hacking
๐ซ๐ท
Zundapper
2026-09-23 23:00:06
(2 hours ago)
34.95.209.114 - - [24/Sep/2026:01:00:05 +0200] "GET /signin HTTP/2.0" 404 167 "https://www.airsanit. ...
show more
34.95.209.114 - - [24/Sep/2026:01:00:05 +0200] "GET /signin HTTP/2.0" 404 167 "https://www.airsanit.com/signin" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Mobile Safari/537.36"
34.95.209.114 - - [24/Sep/2026:01:00:05 +0200] "GET /auth HTTP/2.0" 404 167 "https://www.airsanit.com/auth" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Mobile Safari/537.36"
34.95.209.114 - - [24/Sep/2026:01:00:05 +0200] "GET /signup HTTP/2.0" 404 167 "https://www.airsanit.com/signup" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Mobile Safari/537.36"
34.95.209.114 - - [24/Sep/2026:01:00:05 +0200] "GET /account/login HTTP/2.0" 404 167 "https://www.airsanit.com/account/login" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Mobile Safari/537.36"
34.95.209.114 - - [24/Sep/2026:01:00:05 +0200] "GET /sign-in HTTP/2.0" 404 167 "https:
...
show less
Web App Attack
Port Scan
Anonymous
2026-09-23 22:40:02
(2 hours ago)
| [Dangerous/Brazil] Aggressive IP 34.95.209.114 (~30 hits). Type: DoS Defender- Web server 400 erro ...
show more
| [Dangerous/Brazil] Aggressive IP 34.95.209.114 (~30 hits). Type: DoS Defender- Web server 400 error code
show less
Web App Attack
Hacking
SQL Injection
๐ท๐ด
iulianh
2026-09-23 22:27:46
(3 hours ago)
80,443
Brute-Force
SSH
๐บ๐ธ
oralunal
2026-09-23 22:27:29
(3 hours ago)
IP banned by Fail2Ban in jail ah-suss access.log mvfnds
...
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 21:53:33
(3 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.95.209.114 (114.209.95.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.95.209.114 (114.209.95.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 17:53:29.078825 2026] [security2:error] [pid 8469:tid 8469] [client 34.95.209.114:60772] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||calvinavalos.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "calvinavalos.com"] [uri "/z9x8c7v6b5-debug-trigger-calvinavalos.com"] [unique_id "arRKWUm4vfRvNlSI-zGB9wAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
dalslab ltd
2026-09-23 21:26:15
(4 hours ago)
34.95.209.114 - - [23/Sep/2026:23:26:12 +0200] "POST / HTTP/1.1" 405 154 "-" "Mozilla/5.0 (compatibl ...
show more
34.95.209.114 - - [23/Sep/2026:23:26:12 +0200] "POST / HTTP/1.1" 405 154 "-" "Mozilla/5.0 (compatible; Google-Extended; +http://www.google.com/bot.html)"
34.95.209.114 - - [23/Sep/2026:23:26:13 +0200] "POST /api HTTP/1.1" 405 556 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36; compatible; OAI-SearchBot/1.4; +https://openai.com/searchbot"
34.95.209.114 - - [23/Sep/2026:23:26:13 +0200] "POST /graphql HTTP/1.1" 405 556 "http://dalslab.com" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36"
34.95.209.114 - - [23/Sep/2026:23:26:14 +0200] "POST /api/graphql HTTP/1.1" 405 556 "http://dalslab.com" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36"
34.95.209.114 - - [23/Sep/2026:23:26:14 +0200] "POST /v1/graphql HTTP/1.1" 405 556 "http://dalslab.com" "Mozilla/5.0 (Macintosh; Intel Mac
...
show less
Web Spam
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
kosada.com
2026-09-23 21:24:11
(4 hours ago)
Repeated exploit attempts, for example: /.env.save /.env (HTTP/2.0 port 443, user agent: "Mozilla/5. ...
show more
Repeated exploit attempts, for example: /.env.save /.env (HTTP/2.0 port 443, user agent: "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)")
show less
Web App Attack
๐ช๐ธ
robotstxt
2026-09-23 21:06:53
(4 hours ago)
34.95.209.114 - - [23/Sep/2026:21:06:12 +0000] "GET /backend/.env HTTP/2.0" 403 49647 "-" "Mozilla/5 ...
show more
34.95.209.114 - - [23/Sep/2026:21:06:12 +0000] "GET /backend/.env HTTP/2.0" 403 49647 "-" "Mozilla/5.0 (compatible; Meta-ExternalAgent/1.0; +https://developers.facebook.com/docs/sharing/webmasters/crawler)" "-"
34.95.209.114 - - [23/Sep/2026:21:06:13 +0000] "GET /.env.prod HTTP/2.0" 403 49645 "-" "Mozilla/5.0 (compatible; DeepSeekBot/1.0; +https://www.deepseek.com/)" "-"
34.95.209.114 - - [23/Sep/2026:21:06:13 +0000] "GET /api/.env HTTP/2.0" 403 49573 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-SearchBot/1.0; [email protected] )" "-"
34.95.209.114 - - [23/Sep/2026:21:06:13 +0000] "GET /.env.save HTTP/2.0" 403 49634 "-" "Mozilla/5.0 (compatible; DeepSeekBot/1.0; +https://www.deepseek.com/)" "-"
34.95.209.114 - - [23/Sep/2026:21:06:13 +0000] "GET /config/.env HTTP/2.0" 403 49642 "-" "Mozilla/5.0 (compatible; PanguBot/1.0; +https://www.huaweicloud.com/)" "-"
...
show less
Web App Attack
๐ซ๐ท
ELYAZ
2026-09-23 21:04:09
(4 hours ago)
(y3) Failed access -byebye- from 34.95.209.114 (BR/Brazil/114.209.95.34.bc.googleusercontent.com): ...
show more
(y3) Failed access -byebye- from 34.95.209.114 (BR/Brazil/114.209.95.34.bc.googleusercontent.com): (CF_ENABLE)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-23 21:02:12
(4 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.95.209.114 (114.209.95.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.95.209.114 (114.209.95.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 17:02:07.952209 2026] [security2:error] [pid 32281:tid 32328] [client 34.95.209.114:37302] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||emehache.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "emehache.com"] [uri "/z9x8c7v6b5-debug-trigger-emehache.com"] [unique_id "arQ-T709CYNVX1vv5-CpOgAAAdA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ด
jad-abuse
2026-09-23 20:55:04
(4 hours ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: env_probe ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: env_probe, path_traversal, aws_creds, ssh_keys, think_rce. Observed by 1 sensor(s); 119 hits.
show less
Hacking
Web App Attack