Anonymous
2026-10-07 07:30:04
(22 hours ago)
CrowdSec decision: crowdsecurity/http-path-traversal-probing (origin: crowdsec)
Port Scan
Anonymous
2026-10-06 23:30:08
(1 day ago)
CrowdSec decision: crowdsecurity/http-bad-user-agent (origin: crowdsec)
Port Scan
π§π·
radardatelecom
2026-10-06 22:27:02
(1 day ago)
Blocked by Radar da Telecom firewall β abuseipdb
Bad Web Bot
Web App Attack
πΊπΈ
deskpass.com
2026-10-06 22:07:26
(1 day ago)
POST /index.php
Web App Attack
Anonymous
2026-10-06 14:54:56
(1 day ago)
34.95.235.138 - - [06/Oct/2026:09:36:53 -0500] "GET /.env HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compat ...
show more
34.95.235.138 - - [06/Oct/2026:09:36:53 -0500] "GET /.env HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; Google-Extended; +http://www.google.com/bot.html)" 34.95.235.138
34.95.235.138 - - [06/Oct/2026:09:36:53 -0500] "GET /.env.production HTTP/1.1" 403 199 "-" "CCBot/2.0 (https://commoncrawl.org/faq/)" 34.95.235.138
34.95.235.138 - - [06/Oct/2026:09:36:53 -0500] "GET /.env.example HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; Qwenbot/1.0; +https://qwen.alibaba.com/)" 34.95.235.138
34.95.235.138 - - [06/Oct/2026:09:36:53 -0500] "GET /.env.local HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; +https://kimi.ai/)" 34.95.235.138
34.95.235.138 - - [06/Oct/2026:09:36:53 -0500] "GET /.env.backup HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot)" 34.95.235.138
34.95.235.138 - - [06/Oct/2026:09:36:53 -0500] "GET /.env.bak HTTP/1.1" 403 199 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claud
...
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-06 14:30:04
(1 day ago)
CrowdSec decision: crowdsecurity/http-admin-interface-probing (origin: crowdsec)
Web App Attack
π¨π·
Klicks
2026-10-06 13:39:00
(1 day ago)
Request URL: https://1.com:443/trace.axd
Request path: /trace.axd
User host address: ...
show more
Request URL: https://1.com:443/trace.axd
Request path: /trace.axd
User host address: 34.95.235.138
show less
Bad Web Bot
Web App Attack
Web Spam
πΊπΈ
[email protected]
2026-10-06 13:11:18
(1 day ago)
CrowdSec ban: crowdsecurity/http-crawl-non_statics (duration: 71h59m52s)
Web App Attack
Anonymous
2026-10-06 13:07:03
(1 day ago)
Automated web scanner. Requested suspicious paths: /dist/manifest.json | /.vite/manifest.json | /dis ...
show more
Automated web scanner. Requested suspicious paths: /dist/manifest.json | /.vite/manifest.json | /dist/.vite/manifest.json | /build/manifest.json. UTC: 2026-10-06 13:02:46.
show less
Web App Attack
πΊπΈ
CDO
2026-10-06 12:51:44
(1 day ago)
URL Injection attempt detected. Automated web attack.
Hacking
Bad Web Bot
Web App Attack
π©πͺ
ghostwarriors
2026-10-06 12:20:08
(1 day ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
πͺπΈ
masterguru
2026-10-06 12:16:16
(1 day ago)
Inbound Anomaly Score Exceeded (Total Score: 5). Operator GE matched 5 at TX:anomaly_score. (949110- ...
show more
Inbound Anomaly Score Exceeded (Total Score: 5). Operator GE matched 5 at TX:anomaly_score. (949110-122)
show less
Hacking
π³π±
Savvii
2026-10-06 12:02:16
(1 day ago)
20 attempts against mh_ha-misbehave-ban on boron
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
yitzhaq
2026-10-06 12:01:58
(1 day ago)
34.95.235.138 - - [06/Oct/2026:14:01:55 +0200] "GET /static/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f.env ...
show more
34.95.235.138 - - [06/Oct/2026:14:01:55 +0200] "GET /static/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f.env HTTP/2.0" 404 293 "-" "Mozilla/5.0 (compatible; cohere-ai; +https://cohere.com/crawler)"
34.95.235.138 - - [06/Oct/2026:14:01:55 +0200] "GET /userfiles/x?path=../../.env HTTP/2.0" 301 391 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
34.95.235.138 - - [06/Oct/2026:14:01:55 +0200] "GET /static/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2fproc/self/environ HTTP/2.0" 404 293 "-" "Mozilla/5.0 (compatible; YiBot/1.0; +https://01.ai/)"
34.95.235.138 - - [06/Oct/2026:14:01:55 +0200] "GET /google-credentials.json HTTP/2.0" 301 382 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
34.95.235.138 - - [06/Oct/2026:14:01:55 +0200] "GET /keys/service-account.json HTTP/2.0" 301 386 "-" "Mozilla/5.0 (compatible; KimiBot/1.0; +https://kimi.ai/)"
34.95.235.138 - - [06/Oct/2026:14:01:56 +0200] "GET /gcp-credentials.json HTTP/2.0" 301 401 "-" "DuckAssist
show less
Web App Attack
Hacking
πΊπΈ
TPI-Abuse
2026-10-06 11:17:03
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.95.235.138 (138.235.95.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.95.235.138 (138.235.95.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 07:16:59.279411 2026] [security2:error] [pid 6505:tid 6505] [client 34.95.235.138:56432] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||realitytourist.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "realitytourist.com"] [uri "/z9x8c7v6b5-debug-trigger-realitytourist.com"] [unique_id "asTYqxJtdRFqWwL9EQ2BsgAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack