๐ซ๐ท
SpaceHost-Server
2026-09-21 22:22:13
(1 day ago)
Brute-Force
Web App Attack
๐ซ๐ท
SpaceHost-Server
2026-09-20 22:21:24
(2 days ago)
Brute-Force
Web App Attack
๐ซ๐ท
โจ
2026-09-20 14:39:04
(2 days ago)
Domain : api.gestioncgt.es
Rule : config
2026-09-20 14:37:33 ***hidden-privacy*** GET /.aws/credenti ...
show more
Domain : api.gestioncgt.es
Rule : config
2026-09-20 14:37:33 ***hidden-privacy*** GET /.aws/credentials - 443 - 34.138.110.103 HTTP/2 Mozilla/5.0 (compatible; GrokBot/1.0; https://x.ai/) - api.gestioncgt.es 404 0 2 0 471 257 - -
show less
Hacking
SQL Injection
๐ง๐ช
voormedia
2026-09-20 13:19:33
(2 days ago)
Accessed trap at '/.aws/credentials'
Web App Attack
๐ช๐ธ
robotstxt
2026-09-20 13:13:29
(2 days ago)
34.138.110.103 - - [20/Sep/2026:13:12:59 +0000] "GET /.ssh/known_hosts HTTP/2.0" 403 15397 "https:// ...
show more
34.138.110.103 - - [20/Sep/2026:13:12:59 +0000] "GET /.ssh/known_hosts HTTP/2.0" 403 15397 "https://wppodcast.es/.ssh/known_hosts" "CCBot/2.0 (https://commoncrawl.org/faq/)" "-" edge="34.138.110.103"
34.138.110.103 - - [20/Sep/2026:13:12:59 +0000] "GET /id_rsa/ HTTP/2.0" 403 15397 "https://www.wppodcast.es/id_rsa" "Mozilla/5.0 (compatible; YouBot/1.0; +https://you.com/bot)" "-" edge="34.138.110.103"
34.138.110.103 - - [20/Sep/2026:13:12:59 +0000] "GET /id_ed25519/ HTTP/2.0" 403 15397 "https://www.wppodcast.es/id_ed25519" "Mozilla/5.0 (compatible; Google-Extended; +http://www.google.com/bot.html)" "-" edge="34.138.110.103"
34.138.110.103 - - [20/Sep/2026:13:12:59 +0000] "GET /id_dsa/ HTTP/2.0" 403 15397 "https://www.wppodcast.es/id_dsa" "Mozilla/5.0 (compatible; YiBot/1.0; +https://01.ai/)" "-" edge="34.138.110.103"
34.138.110.103 - - [20/Sep/2026:13:12:59 +0000] "GET / HTTP/2.0" 403 24925 "https://wppodcast.es/" "Mozilla/5.0 (compatible; Bravebot/1.0; +https://brave.com/search/)" "-" e
...
show less
Web App Attack
๐ช๐ธ
robotstxt
2026-09-20 12:38:04
(2 days ago)
34.138.110.103 - - [20/Sep/2026:12:37:42 +0000] "GET / HTTP/2.0" 403 23230 "https://nextlevel.es/" " ...
show more
34.138.110.103 - - [20/Sep/2026:12:37:42 +0000] "GET / HTTP/2.0" 403 23230 "https://nextlevel.es/" "DuckAssistBot/1.1 (https://duckduckgo.com/duckassistbot)" "-" edge="34.138.110.103"
34.138.110.103 - - [20/Sep/2026:12:37:42 +0000] "GET /env.js HTTP/2.0" 403 16818 "https://nextlevel.es/env.js" "DuckAssistBot/1.1 (https://duckduckgo.com/duckassistbot)" "-" edge="34.138.110.103"
34.138.110.103 - - [20/Sep/2026:12:37:42 +0000] "GET /__/firebase/init.json HTTP/2.0" 403 16830 "https://nextlevel.es/__/firebase/init.json" "Mozilla/5.0 (compatible; YiBot/1.0; +https://01.ai/)" "-" edge="34.138.110.103"
34.138.110.103 - - [20/Sep/2026:12:37:43 +0000] "GET /api/config/ HTTP/2.0" 403 16814 "https://www.nextlevel.es/api/config" "Mozilla/5.0 (compatible; YiBot/1.0; +https://01.ai/)" "-" edge="34.138.110.103"
34.138.110.103 - - [20/Sep/2026:12:37:43 +0000] "GET /api/settings/ HTTP/2.0" 403 16834 "https://www.nextlevel.es/api/settings" "Mozilla/5.0 (compatible; Amazonbot/0.1; +https://developer.amazo
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 12:36:33
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.138.110.103 (103.110.138.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.138.110.103 (103.110.138.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 08:36:26.606319 2026] [security2:error] [pid 1305:tid 1305] [client 34.138.110.103:53314] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nagareinkpaper.es"] [uri "/.git/config"] [unique_id "aq_TSpkjlKZLljG-YLqXoQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-20 12:28:56
(2 days ago)
[cb-13al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[cb-13al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 34.138.110.103 - - [20/Sep/2026:14:28:35 +0200] "GET /.aws/config HTTP/1.1" 301 739 "-" "Mozilla/5.0 (compatible; KimiBot/1.0; +https://kimi.ai/)"
...
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-20 12:26:33
(2 days ago)
Excessive multi-domain requests
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-20 12:20:31
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.138.110.103 (103.110.138.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.138.110.103 (103.110.138.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 08:20:27.073363 2026] [security2:error] [pid 9789:tid 9789] [client 34.138.110.103:34598] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "intra.es"] [uri "/.env.js"] [unique_id "aq_Pi3foD_kBntjzlw--MQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Savvii
2026-09-20 12:13:26
(2 days ago)
20 attempts against mh-misbehave-ban on mars
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
Francisco Vallejo
2026-09-20 12:11:20
(2 days ago)
[Sun Sep 20 14:11:20.579627 2026] [core:info] [pid 3147446:tid 127877391566528] [client 34.138.110.1 ...
show more
[Sun Sep 20 14:11:20.579627 2026] [core:info] [pid 3147446:tid 127877391566528] [client 34.138.110.103:49852] AH00128: File does not exist: /var/www/franvallejo/z9x8c7v6b5-debug-trigger-franvallejo.es
[Sun Sep 20 14:11:20.584481 2026] [core:info] [pid 3147446:tid 127877416744640] [client 34.138.110.103:49868] AH00128: File does not exist: /var/www/franvallejo/.aws/config
[Sun Sep 20 14:11:20.595713 2026] [core:info] [pid 3147447:tid 127877819397824] [client 34.138.110.103:49878] AH00128: File does not exist: /var/www/franvallejo/.aws/credentials
[Sun Sep 20 14:11:20.675988 2026] [core:info] [pid 3147446:tid 127877819397824] [client 34.138.110.103:49852] AH00128: File does not exist: /var/www/franvallejo/graphql, referer: https://franvallejo.es
[Sun Sep 20 14:11:20.689059 2026] [core:info] [pid 3147447:tid 127876854695616] [client 34.138.110.103:49850] AH00128: File does not exist: /var/www/franvallejo/api/openapi.json
...
show less
Brute-Force
SSH
๐ซ๐ท
masterguru
2026-09-20 11:43:46
(2 days ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-195)
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 11:18:36
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.138.110.103 (103.110.138.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.138.110.103 (103.110.138.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 07:18:30.295378 2026] [security2:error] [pid 31528:tid 31528] [client 34.138.110.103:52594] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cederberg.es"] [uri "/.env.example"] [unique_id "aq_BBgOa9zpR22N3bBmENAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-20 11:10:34
(2 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking