๐บ๐ธ
Sockets-AR
2026-10-01 05:19:23
(1 day ago)
CrowdSec: HTTP DoS detected (crowdsecurity/http-dos-swithcing-ua) at 2026-10-01T05:19:22.010Z
DDoS Attack
Web App Attack
๐บ๐ธ
Sockets-AR
2026-10-01 04:42:24
(1 day ago)
CrowdSec: HTTP DoS detected (crowdsecurity/http-dos-swithcing-ua) at 2026-10-01T04:42:24.050Z
DDoS Attack
Web App Attack
๐ง๐ช
cmbplf
2026-10-01 04:25:32
(1 day ago)
525 requests with url.path *.env
138 requests with url.path */@fs/*
Brute-Force
Bad Web Bot
๐ช๐ธ
robotstxt
2026-10-01 02:34:55
(1 day ago)
34.140.184.119 - - [01/Oct/2026:02:34:50 +0000] "GET /resources/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f ...
show more
34.140.184.119 - - [01/Oct/2026:02:34:50 +0000] "GET /resources/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f.env HTTP/1.1" 400 193 "-" "-" "-" edge="34.140.184.119"
34.140.184.119 - - [01/Oct/2026:02:34:50 +0000] "GET /static/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2fproc/self/environ HTTP/1.1" 400 193 "-" "-" "-" edge="34.140.184.119"
34.140.184.119 - - [01/Oct/2026:02:34:50 +0000] "GET /static/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f.env HTTP/1.1" 400 193 "-" "-" "-" edge="34.140.184.119"
34.140.184.119 - - [01/Oct/2026:02:34:52 +0000] "GET /api/uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f.env HTTP/1.1" 400 193 "-" "-" "-" edge="34.140.184.119"
34.140.184.119 - - [01/Oct/2026:02:34:52 +0000] "GET /api/uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2fproc/self/environ HTTP/1.1" 400 193 "-" "-" "-" edge="34.140.184.119"
...
show less
Web Spam
Web App Attack
๐บ๐ธ
Sockets-AR
2026-10-01 02:31:21
(1 day ago)
CrowdSec: sensitive file probing detected (crowdsecurity/http-sensitive-files) at 2026-10-01T02:31:2 ...
show more
CrowdSec: sensitive file probing detected (crowdsecurity/http-sensitive-files) at 2026-10-01T02:31:20.973Z
show less
Web App Attack
๐ฉ๐ช
macrob
2026-10-01 01:39:07
(1 day ago)
2026/10/01 01:39:05 [error] 1318202#1318202: *3109745 access forbidden by rule, client: 34.140.184.1 ...
show more
2026/10/01 01:39:05 [error] 1318202#1318202: *3109745 access forbidden by rule, client: 34.140.184.119, server: binixo.com.ar, request: "GET /.ssh/config HTTP/2.0", host: "binixo.com.ar", referrer: "https://www.binixo.com.ar/.ssh/config"
2026/10/01 01:39:05 [error] 1318206#1318206: *3109808 access forbidden by rule, client: 34.140.184.119, server: binixo.com.ar, request: "GET /.ssh/id_ed25519 HTTP/2.0", host: "binixo.com.ar", referrer: "https://www.binixo.com.ar/.ssh/id_ed25519"
2026/10/01 01:39:05 [error] 1318205#1318205: *3109822 access forbidden by rule, client: 34.140.184.119, server: binixo.com.ar, request: "GET /wp-content/themes/donna/js/app.js HTTP/2.0", host: "binixo.com.ar"
...
show less
Web App Attack
๐บ๐ธ
Sockets-AR
2026-09-30 22:15:48
(1 day ago)
CrowdSec: sensitive file probing detected (crowdsecurity/http-sensitive-files) at 2026-09-30T22:15:4 ...
show more
CrowdSec: sensitive file probing detected (crowdsecurity/http-sensitive-files) at 2026-09-30T22:15:47.062Z
show less
Web App Attack
๐ช๐ธ
robotstxt
2026-09-30 22:12:43
(1 day ago)
34.140.184.119 - - [30/Sep/2026:22:11:41 +0000] "GET /g1s0sqjzj8ux2ypjd1j1/ HTTP/2.0" 403 13354 "htt ...
show more
34.140.184.119 - - [30/Sep/2026:22:11:41 +0000] "GET /g1s0sqjzj8ux2ypjd1j1/ HTTP/2.0" 403 13354 "https://curso-endoteam.aymonline.events/g1s0sqjzj8ux2ypjd1j1" "Mozilla/5.0 (compatible; MoonshotBot/1.0; +https://kimi.ai/)" "-" edge="34.140.184.119"
34.140.184.119 - - [30/Sep/2026:22:11:42 +0000] "GET /jv3eplqmsm1z6o9s8izx/ HTTP/2.0" 403 13354 "https://curso-endoteam.aymonline.events/jv3eplqmsm1z6o9s8izx" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot)" "-" edge="34.140.184.119"
34.140.184.119 - - [30/Sep/2026:22:11:42 +0000] "GET /z9x8c7v6b5-debug-trigger-curso-endoteam.aymonline.events HTTP/2.0" 403 13373 "-" "Mozilla/5.0 (compatible; Bytespider; [email protected] ) AppleWebKit/537.36" "-" edge="34.140.184.119"
34.140.184.119 - - [30/Sep/2026:22:11:42 +0000] "GET /static../.env HTTP/2.0" 403 13354 "-" "Mozilla/5.0 (compatible; KimiBot/1.0; +https://kimi.ai/)" "-" edge="34.140.184.119"
34.140.184.119 - -
...
show less
Web App Attack
๐บ๐ธ
Sockets-AR
2026-09-30 16:41:56
(1 day ago)
CrowdSec: HTTP DoS detected (crowdsecurity/http-dos-swithcing-ua) at 2026-09-30T16:41:55.319Z
DDoS Attack
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 16:13:32
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.140.184.119 (119.184.140.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.140.184.119 (119.184.140.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 12:13:28.574207 2026] [security2:error] [pid 10082:tid 10082] [client 34.140.184.119:33590] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "siedersoft.com.ar"] [uri "/.htpasswd"] [unique_id "ar01KE2wrqrZDU4aeyqcDwAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-30 15:47:04
(1 day ago)
Vulnerability scan
Web App Attack
๐บ๐ธ
Sockets-AR
2026-09-30 14:26:13
(1 day ago)
CrowdSec: HTTP DoS detected (crowdsecurity/http-dos-swithcing-ua) at 2026-09-30T14:26:13.355Z
DDoS Attack
Web App Attack
Anonymous
2026-09-30 12:15:57
(1 day ago)
apache vulnerability scan
Web App Attack
๐ช๐ธ
pipeline.es
2026-09-30 11:12:00
(1 day ago)
Web scanning / probing for vulnerable paths | URL: /.env.production?raw | Evidence: volandoviajes.co ...
show more
Web scanning / probing for vulnerable paths | URL: /.env.production?raw | Evidence: volandoviajes.com.ar 34.140.184.119 - - [30/Sep/2026:13:10:48 +0200] \"GET /.env.production?raw HTTP/2.0\" 404 26587 \"-\" \"Mozilla/5.0 (compatible; MoonshotBot/1.0; +https://kimi.ai/)\" GEOIP_COUNTRY_CODE=BE 30297 | ASN: GOOGLE-CLOUD-PLATFORM | Country: BE
show less
Port Scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 10:40:06
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.140.184.119 (119.184.140.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.140.184.119 (119.184.140.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 06:39:57.734803 2026] [security2:error] [pid 12175:tid 12175] [client 34.140.184.119:39262] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.notimallinckrodt.com.ar"] [uri "/wp-config.php~"] [unique_id "arzm_SGPQfxSirjnQV12_AAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack