Anonymous
2026-10-09 06:05:07
(8 hours ago)
WAF repeated trigger detected by Fail2Ban
Web App Attack
π©πͺ
jakidomi
2026-10-09 05:49:42
(8 hours ago)
CrowdSec detection: crowdsecurity/http-sensitive-files
Web App Attack
π«π·
sthoyer.de
2026-10-09 03:49:19
(10 hours ago)
34.95.29.58 - - [09/Oct/2026:05:49:18 +0200] "GET /login HTTP/2" 302 495 "-" "Mozilla/5.0 (Macintosh ...
show more
34.95.29.58 - - [09/Oct/2026:05:49:18 +0200] "GET /login HTTP/2" 302 495 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36 Edg/153.0.0.0"
34.95.29.58 - - [09/Oct/2026:05:49:18 +0200] "GET /z9x8c7v6b5-debug-trigger-api.sthoyer.de HTTP/2" 302 495 "-" "Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; +https://kimi.ai/)"
34.95.29.58 - - [09/Oct/2026:05:49:18 +0200] "GET /webpack-stats.json HTTP/2" 302 495 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36 Edg/153.0.0.0"
...
show less
Web App Attack
π³π±
Alt255
2026-10-09 03:03:03
(11 hours ago)
[ti-12al] Web exploit scanning: 2 suspicious requests detected by fail2ban jail <name>. Example: 34. ...
show more
[ti-12al] Web exploit scanning: 2 suspicious requests detected by fail2ban jail <name>. Example: 34.95.29.58 - - \[09/Oct/2026:05:02:59 +0200\] "GET /.ssh/id_rsa HTTP/2.0" 404 1863 "-" "Mozilla/5.0 AppleWebKit/537.36 \(KHTML, like Gecko\; compatible\; Perplexity-User/1.0\; +https://perplexity.ai/perplexitybot\)"
34.95.29.58 - - \[09/Oct/2026:05:02:59 +0200\] "GET /.htpasswd HTTP/2.0" 403 1866 "-" "Mozilla/5.0 \(compatible\; MistralAI-User/1.0\; +https://mistral.ai/\)"
...
show less
Bad Web Bot
Web App Attack
π©πͺ
XICTRON
2026-10-09 02:25:03
(12 hours ago)
ModSecurity rule violation detected by Fail2Ban
Web App Attack
π©πͺ
jack252
2026-10-09 01:53:48
(12 hours ago)
2026/10/09 03:53:47 [error] 1331#1331: *131727 open() "/var/www/html/cgi-bin/php-cgi.exe" failed (2: ...
show more
2026/10/09 03:53:47 [error] 1331#1331: *131727 open() "/var/www/html/cgi-bin/php-cgi.exe" failed (2: No such file or directory), client: 34.95.29.58, server: _, request: "POST /cgi-bin/php-cgi.exe?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input HTTP/2.0", host: "account.webuptime.de"
2026/10/09 03:53:47 [error] 1331#1331: *131727 open() "/var/www/html/cgi-bin/php" failed (2: No such file or directory), client: 34.95.29.58, server: _, request: "POST /cgi-bin/php?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input HTTP/2.0", host: "account.webuptime.de"
2026/10/09 03:53:47 [error] 1331#1331: *131727 open() "/var/www/html/cgi-bin/php-cgi" failed (2: No such file or directory), client: 34.95.29.58, server: _, request: "POST /cgi-bin/php-cgi?-d+allow_url_include%3don+-d+auto_prepend_file%3dphp://input HTTP/2.0", host: "account.webuptime.de"
...
show less
Brute-Force
Bad Web Bot
π©πͺ
Marc
2026-10-09 01:43:32
(13 hours ago)
34.95.29.58 - - [09/Oct/2026:03:43:32 +0200] "GET /user/login HTTP/2.0" 404 291 "-" "Mozilla/5.0 (Wi ...
show more
34.95.29.58 - - [09/Oct/2026:03:43:32 +0200] "GET /user/login HTTP/2.0" 404 291 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36" 34.95.29.58 - - [09/Oct/2026:03:43:32 +0200] "GET /z9x8c7v6b5-debug-trigger-account.tin-whistle.de HTTP/2.0" 404 269 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; [email protected] )" 34.95.29.58 - - [09/Oct/2026:03:43:32 +0200] "GET /forgot-password HTTP/2.0" 404 269 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
show less
Brute-Force
π©πͺ
Hazzard
2026-10-09 01:40:13
(13 hours ago)
(PERMBLOCK) 34.95.29.58 (CA/Canada/Quebec/Montreal/58.29.95.34.bc.googleusercontent.com/[redacted]) ...
show more
(PERMBLOCK) 34.95.29.58 (CA/Canada/Quebec/Montreal/58.29.95.34.bc.googleusercontent.com/[redacted]) has had more than 4 temp blocks
show less
Hacking
π©πͺ
itsolon
2026-10-09 01:15:59
(13 hours ago)
[09/Oct/2026:03:15:58 +0200] 179150855868.071357 34.95.29.58 0 217.154.7.177 443
[09/Oct/2026:03:15: ...
show more
[09/Oct/2026:03:15:58 +0200] 179150855868.071357 34.95.29.58 0 217.154.7.177 443
[09/Oct/2026:03:15:58 +0200] 179150855842.756367 34.95.29.58 0 217.154.7.177 443
[09/Oct/2026:03:15:58 +0200] 179150855886.804588 34.95.29.58 0 217.154.7.177 443
[09/Oct/2026:03:15:58 +0200] 179150855846.897432 34.95.29.58 0 217.154.7.177 443
[09/Oct/2026:03:15:58 +0200] 179150855863.418782 34.95.29.58 0 217.154.7.177 443
...
show less
Port Scan
Hacking
Brute-Force
Web App Attack
πͺπΈ
robotstxt
2026-10-09 01:12:23
(13 hours ago)
34.95.29.58 - - [09/Oct/2026:01:12:15 +0000] "GET /?474ab6=2f99ce4ca5.js& HTTP/2.0" 403 2 "-" "Mozil ...
show more
34.95.29.58 - - [09/Oct/2026:01:12:15 +0000] "GET /?474ab6=2f99ce4ca5.js& HTTP/2.0" 403 2 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36" "-" edge="34.95.29.58"
34.95.29.58 - - [09/Oct/2026:01:12:15 +0000] "GET /wp-content/plugins/altcha/public/altcha.min.js?ver=3.3.0 HTTP/2.0" 403 15103 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36" "-" edge="34.95.29.58"
34.95.29.58 - - [09/Oct/2026:01:12:15 +0000] "GET /wp-content/plugins/stop-user-enumeration/frontend/js/frontend.js?ver=1.7.9 HTTP/2.0" 403 15103 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36" "-" edge="34.95.29.58"
34.95.29.58 - - [09/Oct/2026:01:12:15 +0000] "GET /wp-includes/js/dist/script-modules/block-library/navigation/view.min.js?ver=1bf28ded04f9f188bdcb HTTP/2.0" 403 15103 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64
...
show less
Web App Attack
π³π±
Alt255
2026-10-09 01:09:06
(13 hours ago)
[ti-26al] Web exploit scanning: 2 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-26al] Web exploit scanning: 2 suspicious requests detected by fail2ban jail apache-scanner. Example: 34.95.29.58 - - [09/Oct/2026:03:08:56 +0200] "GET /static../.env HTTP/1.1" 301 582 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; [email protected] )"
34.95.29.58 - - [09/Oct/2026:03:08:56 +0200] "GET /public../.env HTTP/1.1" 301 582 "-" "Mozilla/5.0 (compatible; ChatGLM-Spider/1.0; +https://zhipuai.cn/)"
...
show less
Bad Web Bot
Web App Attack
π©πͺ
netman
2026-10-09 00:48:53
(13 hours ago)
34.95.29.58 wirenow.de - [09/Oct/2026:00:48:45 +0000] "GET / HTTP/2.0" 200 257732 "-" "Mozilla/5.0 ( ...
show more
34.95.29.58 wirenow.de - [09/Oct/2026:00:48:45 +0000] "GET / HTTP/2.0" 200 257732 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36"
34.95.29.58 wirenow.de - [09/Oct/2026:00:48:45 +0000] "GET /z9x8c7v6b5-debug-trigger-wirenow.de HTTP/2.0" 404 158 "-" "Mozilla/5.0 (compatible; Google-Extended; +http://www.google.com/bot.html)"
34.95.29.58 wirenow.de - [09/Oct/2026:00:48:46 +0000] "GET /api/uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2fproc/self/environ HTTP/2.0" 404 158 "-" "Mozilla/5.0 (compatible; Bravebot/1.0; +https://brave.com/search/)"
34.95.29.58 wirenow.de - [09/Oct/2026:00:48:46 +0000] "GET /..%2f..%2f.env HTTP/2.0" 404 158 "-" "Mozilla/5.0 (compatible; cohere-ai; +https://cohere.com/crawler)"
34.95.29.58 wirenow.de - [09/Oct/2026:00:48:46 +0000] "GET /%2e%2e/.env HTTP/2.0" 404 158 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot)"
34.95.29.58 wiren
...
show less
DDoS Attack
Web App Attack
π©πͺ
Manuel Braeuer
2026-10-09 00:44:29
(13 hours ago)
34.95.29.58 - - [09/Oct/2026:02:44:22 +0200] "GET /.htpasswd HTTP/2.0" 403 106 "https://winsvr-berli ...
show more
34.95.29.58 - - [09/Oct/2026:02:44:22 +0200] "GET /.htpasswd HTTP/2.0" 403 106 "https://winsvr-berlin.de/.htpasswd" "Mozilla/5.0 (compatible; YiBot/1.0; +https://01.ai/)"
34.95.29.58 - - [09/Oct/2026:02:44:23 +0200] "GET /@fs/app/.env.local?import&raw?? HTTP/2.0" 403 106 "https://winsvr-berlin.de/@fs/app/.env.local?import&raw??" "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)"
34.95.29.58 - - [09/Oct/2026:02:44:23 +0200] "GET /__vite_rsc_findSourceMapURL?filename=file:///proc/self/environ&environmentName=rsc HTTP/2.0" 403 106 "https://winsvr-berlin.de/__vite_rsc_findSourceMapURL?filename=file:///proc/self/environ&environmentName=rsc" "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)"
34.95.29.58 - - [09/Oct/2026:02:44:25 +0200] "GET /api/orders/..%2f..%2fproc/self/environ HTTP/2.0" 403 106 "https://winsvr-berlin.de/api/orders/..%2f..%2fproc/self/environ" "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.
...
show less
Web App Attack
π©πͺ
patrisei
2026-10-09 00:29:51
(14 hours ago)
You are now banned for 10 years by Schiffdorf-West Patrol. Trigger: crowdsecurity/http-probing
Port Scan
Web App Attack
π©πͺ
Philister11
2026-10-09 00:17:13
(14 hours ago)
CrowdSec: crowdsecurity/http-sensitive-files (CA/AS396982)
Web App Attack
Hacking