๐ฎ๐ณ
evicky2002
2026-09-22 06:00:01
(3 hours ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐ช๐ธ
robotstxt
2026-09-22 01:47:31
(7 hours ago)
34.136.159.4 - - [22/Sep/2026:01:47:30 +0000] "GET /icons/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/proc/self/en ...
show more
34.136.159.4 - - [22/Sep/2026:01:47:30 +0000] "GET /icons/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/proc/self/environ HTTP/1.1" 400 193 "-" "-" "-"
34.136.159.4 - - [22/Sep/2026:01:47:30 +0000] "GET /public/plugins/alertlist/../../../../../../../../proc/self/environ HTTP/1.1" 400 193 "-" "-" "-"
34.136.159.4 - - [22/Sep/2026:01:47:31 +0000] "GET /public/plugins/grafana-clock-panel/../../../../../../../../proc/self/environ HTTP/1.1" 400 193 "-" "-" "-"
34.136.159.4 - - [22/Sep/2026:01:47:31 +0000] "GET /api/uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2fproc/self/environ HTTP/1.1" 400 193 "-" "-" "-"
34.136.159.4 - - [22/Sep/2026:01:47:31 +0000] "GET /api/uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2f.env HTTP/1.1" 400 193 "-" "-" "-"
...
show less
Web Spam
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 01:32:04
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.136.159.4 (4.159.136.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.136.159.4 (4.159.136.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 21:31:58.796274 2026] [security2:error] [pid 16665:tid 16665] [client 34.136.159.4:43684] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sabri.es"] [uri "/api/v1/.env"] [unique_id "arHajp1HdNPdg9T_l0sDaQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 01:00:09
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.136.159.4 (4.159.136.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.136.159.4 (4.159.136.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 21:00:02.262018 2026] [security2:error] [pid 10954:tid 10993] [client 34.136.159.4:58640] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.indigocapital.es"] [uri "/.env.production"] [unique_id "arHTEjaNEnj04MCwK6R4SAAAAU8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
robotstxt
2026-09-22 00:17:04
(9 hours ago)
34.136.159.4 - - [22/Sep/2026:00:16:34 +0000] "GET /.git/config HTTP/2.0" 403 30885 "https://www.bli ...
show more
34.136.159.4 - - [22/Sep/2026:00:16:34 +0000] "GET /.git/config HTTP/2.0" 403 30885 "https://www.blimburnseeds.es/.git/config" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot)" "-" edge="34.136.159.4"
34.136.159.4 - - [22/Sep/2026:00:16:34 +0000] "GET /.aws/config HTTP/2.0" 403 30885 "https://www.blimburnseeds.es/.aws/config" "Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; +https://kimi.ai/)" "-" edge="34.136.159.4"
34.136.159.4 - - [22/Sep/2026:00:16:34 +0000] "GET /.aws/credentials HTTP/2.0" 403 30944 "https://www.blimburnseeds.es/.aws/credentials" "Mozilla/5.0 (compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot)" "-" edge="34.136.159.4"
34.136.159.4 - - [22/Sep/2026:00:16:34 +0000] "GET /.git/HEAD HTTP/2.0" 403 30885 "https://www.blimburnseeds.es/.git/HEAD" "Mozilla/5.0 (compatible; MistralAI-User/1.0; +https://mistral.ai/)" "-" edge="34.136.159.4"
34.136.159.4 - - [22/Sep/2026:00:16:34 +00
...
show less
Web App Attack
๐ช๐ธ
robotstxt
2026-09-21 23:47:03
(9 hours ago)
34.136.159.4 - - [21/Sep/2026:23:46:01 +0000] "GET /.profile HTTP/2.0" 403 20 "https://acuariozarago ...
show more
34.136.159.4 - - [21/Sep/2026:23:46:01 +0000] "GET /.profile HTTP/2.0" 403 20 "https://acuariozaragoza.es/.profile" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot" "-" edge="34.136.159.4"
34.136.159.4 - - [21/Sep/2026:23:46:01 +0000] "GET /z9x8c7v6b5-debug-trigger-acuariozaragoza.es HTTP/2.0" 403 20 "https://acuariozaragoza.es/z9x8c7v6b5-debug-trigger-acuariozaragoza.es" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-SearchBot/1.0; [email protected] )" "-" edge="34.136.159.4"
34.136.159.4 - - [21/Sep/2026:23:46:01 +0000] "GET /admin/.env HTTP/2.0" 403 20 "https://acuariozaragoza.es/admin/.env" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Safari/605.1.15 (Applebot/0.1)" "-" edge="34.136.159.4"
34.136.159.4 - - [21/Sep/2026:23:46:01 +0000] "GET /.bash_profile HTTP/2.0" 403 20 "https://acuariozaragoza.es/.bash_profile" "Mozilla/5.0 (compatible
...
show less
Web App Attack
๐ง๐ช
cmbplf
2026-09-21 22:49:23
(10 hours ago)
150 requests with url.path */@fs/*
Brute-Force
Bad Web Bot
๐ช๐ธ
robotstxt
2026-09-21 22:07:42
(11 hours ago)
34.136.159.4 - - [21/Sep/2026:22:07:38 +0000] "GET /%2E%2E/%2E%2E/%2E%2E/%2E%2E/.env HTTP/1.1" 400 1 ...
show more
34.136.159.4 - - [21/Sep/2026:22:07:38 +0000] "GET /%2E%2E/%2E%2E/%2E%2E/%2E%2E/.env HTTP/1.1" 400 193 "-" "-" "-" edge="34.136.159.4"
34.136.159.4 - - [21/Sep/2026:22:07:39 +0000] "GET /api/uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2f.env HTTP/1.1" 400 193 "-" "-" "-" edge="34.136.159.4"
34.136.159.4 - - [21/Sep/2026:22:07:39 +0000] "GET /api/uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2f.env HTTP/1.1" 400 193 "-" "-" "-" edge="34.136.159.4"
34.136.159.4 - - [21/Sep/2026:22:07:39 +0000] "GET /api/uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2fproc/self/environ HTTP/1.1" 400 193 "-" "-" "-" edge="34.136.159.4"
34.136.159.4 - - [21/Sep/2026:22:07:39 +0000] "GET /api/uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2fproc/self/environ HTTP/1.1" 400 193 "-" "-" "-" edge="34.136.159.4"
...
show less
Web Spam
Web App Attack
๐ช๐ธ
elcruzado.es
2026-09-21 21:53:11
(11 hours ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 34.136.159.4 (US/Uni ...
show more
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 34.136.159.4 (US/United States/4.159.136.34.bc.googleusercontent.com)
show less
Bad Web Bot
๐ช๐ธ
bohl-aiG5aef
2026-09-21 20:37:25
(12 hours ago)
Suricata Alert [SID:2066027] ET WEB_SPECIFIC_APPS React Server Components React2Shell Unsafe Flight ...
show more
Suricata Alert [SID:2066027] ET WEB_SPECIFIC_APPS React Server Components React2Shell Unsafe Flight Protocol Property Access (CVE-2025-55182)
show less
Web App Attack
๐ช๐ธ
robotstxt
2026-09-21 20:18:12
(13 hours ago)
34.136.159.4 - - [21/Sep/2026:20:18:08 +0000] "GET /static/../../../a/../../../../.env HTTP/1.1" 400 ...
show more
34.136.159.4 - - [21/Sep/2026:20:18:08 +0000] "GET /static/../../../a/../../../../.env HTTP/1.1" 400 193 "-" "-" "-" edge="34.136.159.4"
34.136.159.4 - - [21/Sep/2026:20:18:08 +0000] "GET /static/../../../a/../../../../proc/self/environ HTTP/1.1" 400 193 "-" "-" "-" edge="34.136.159.4"
34.136.159.4 - - [21/Sep/2026:20:18:08 +0000] "GET /public/plugins/alertlist/../../../../../../../../proc/self/cmdline HTTP/1.1" 400 193 "-" "-" "-" edge="34.136.159.4"
34.136.159.4 - - [21/Sep/2026:20:18:08 +0000] "GET /..%2f.env HTTP/1.1" 400 193 "-" "-" "-" edge="34.136.159.4"
34.136.159.4 - - [21/Sep/2026:20:18:09 +0000] "GET /%2e%2e/.env HTTP/1.1" 400 193 "-" "-" "-" edge="34.136.159.4"
...
show less
Web Spam
Web App Attack
๐ช๐ธ
robotstxt
2026-09-21 19:22:58
(14 hours ago)
34.136.159.4 - - [21/Sep/2026:19:22:29 +0000] "POST / HTTP/2.0" 403 34672 "-" "Mozilla/5.0 AppleWebK ...
show more
34.136.159.4 - - [21/Sep/2026:19:22:29 +0000] "POST / HTTP/2.0" 403 34672 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexitybot)" "-" edge="34.136.159.4"
34.136.159.4 - - [21/Sep/2026:19:22:29 +0000] "GET /config.json HTTP/2.0" 403 32247 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexitybot)" "-" edge="34.136.159.4"
34.136.159.4 - - [21/Sep/2026:19:22:29 +0000] "GET /__/firebase/init.json HTTP/2.0" 403 32247 "-" "Mozilla/5.0 (compatible; Bytespider; [email protected] ) AppleWebKit/537.36" "-" edge="34.136.159.4"
34.136.159.4 - - [21/Sep/2026:19:22:29 +0000] "GET /api/config/ HTTP/2.0" 403 20 "https://test.ccoo-servicios.es/api/config" "Mozilla/5.0 (compatible; Bytespider; [email protected] ) AppleWebKit/537.36" "-" edge="34.136.159.4"
34.136.159.4 - - [21/Sep/2026:19:22:29 +0000] "GET /settings.json HTTP/2.0" 403 32188 "-"
...
show less
Web App Attack
๐ช๐ธ
robotstxt
2026-09-21 18:40:51
(14 hours ago)
34.136.159.4 - - [21/Sep/2026:18:40:20 +0000] "-" 400 193 "-" "-" "-" edge="34.136.159.4"
34.136.159 ...
show more
34.136.159.4 - - [21/Sep/2026:18:40:20 +0000] "-" 400 193 "-" "-" "-" edge="34.136.159.4"
34.136.159.4 - - [21/Sep/2026:18:40:20 +0000] "-" 400 193 "-" "-" "-" edge="34.136.159.4"
34.136.159.4 - - [21/Sep/2026:18:40:20 +0000] "-" 400 193 "-" "-" "-" edge="34.136.159.4"
34.136.159.4 - - [21/Sep/2026:18:40:20 +0000] "-" 400 193 "-" "-" "-" edge="34.136.159.4"
34.136.159.4 - - [21/Sep/2026:18:40:22 +0000] "-" 400 193 "-" "-" "-" edge="34.136.159.4"
...
show less
Web Spam
Web App Attack
๐ช๐ธ
robotstxt
2026-09-21 15:35:56
(17 hours ago)
34.136.159.4 - - [21/Sep/2026:15:34:58 +0000] "GET /tmp/.env HTTP/2.0" 403 8788 "-" "Mozilla/5.0 (Ma ...
show more
34.136.159.4 - - [21/Sep/2026:15:34:58 +0000] "GET /tmp/.env HTTP/2.0" 403 8788 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36; compatible; OAI-SearchBot/1.4; +https://openai.com/searchbot" "-" edge="34.136.159.4"
34.136.159.4 - - [21/Sep/2026:15:34:58 +0000] "GET /conf/.env HTTP/2.0" 403 8788 "-" "Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; +https://kimi.ai/)" "-" edge="34.136.159.4"
34.136.159.4 - - [21/Sep/2026:15:34:58 +0000] "GET /env/.env HTTP/2.0" 403 8788 "-" "Mozilla/5.0 (compatible; GrokBot/1.0; +https://x.ai/)" "-" edge="34.136.159.4"
34.136.159.4 - - [21/Sep/2026:15:34:58 +0000] "GET /etc/.env HTTP/2.0" 403 8788 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" "-" edge="34.136.159.4"
34.136.159.4 - - [21/Sep/2026:15:35:00 +0000] "GET /.docker/config.json HTTP/2.0" 403 8788 "-" "Mozilla/5.0 (compatible; MoonshotBot/1.0; +https://kimi.ai/)" "-" edge="34.136.159.4"
...
show less
Web App Attack
๐ช๐ธ
robotstxt
2026-09-21 15:16:29
(18 hours ago)
34.136.159.4 - - [21/Sep/2026:15:15:32 +0000] "POST / HTTP/2.0" 403 14780 "-" "Mozilla/5.0 (compatib ...
show more
34.136.159.4 - - [21/Sep/2026:15:15:32 +0000] "POST / HTTP/2.0" 403 14780 "-" "Mozilla/5.0 (compatible; Bravebot/1.0; +https://brave.com/search/)" "-" edge="34.136.159.4"
34.136.159.4 - - [21/Sep/2026:15:15:33 +0000] "GET /z9x8c7v6b5-debug-trigger-widecall.es HTTP/2.0" 403 8674 "-" "Mozilla/5.0 (compatible; KimiBot/1.0; +https://kimi.ai/)" "-" edge="34.136.159.4"
34.136.159.4 - - [21/Sep/2026:15:15:33 +0000] "GET /bejpepbjq15g6qno29or/ HTTP/2.0" 403 8674 "https://widecall.es/bejpepbjq15g6qno29or" "Mozilla/5.0 (compatible; YouBot/1.0; +https://you.com/bot)" "-" edge="34.136.159.4"
34.136.159.4 - - [21/Sep/2026:15:15:33 +0000] "GET /ofj2kv6vya38hlc1vsum/ HTTP/2.0" 403 8674 "https://widecall.es/ofj2kv6vya38hlc1vsum" "Mozilla/5.0 (compatible; Hunyuan/1.0; +https://hunyuan.tencent.com/)" "-" edge="34.136.159.4"
34.136.159.4 - - [21/Sep/2026:15:15:35 +0000] "GET /.profile HTTP/2.0" 403 8674 "-" "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)" "-" edge="34
...
show less
Web App Attack