๐ฎ๐น
ciccio diddo
2026-09-24 22:07:42
(1 hour ago)
High Burst multiple 40X port:Tcp/80,443
Brute-Force
Web App Attack
๐ฉ๐ช
rh24
2026-09-24 21:35:55
(2 hours ago)
(badbots) Bad bot user-agent [redacted] from 34.169.36.129 (US/United States/129.36.169.34.bc.google ...
show more
(badbots) Bad bot user-agent [redacted] from 34.169.36.129 (US/United States/129.36.169.34.bc.googleusercontent.com)
show less
Hacking
๐ซ๐ท
guillaume illien
2026-09-24 17:43:29
(5 hours ago)
34.169.36.129 - - [24/Sep/2026:17:43:24 +0000] "GET /%2e%2e/.env HTTP/1.1" 400 166 "-" "-"
34.169.36 ...
show more
34.169.36.129 - - [24/Sep/2026:17:43:24 +0000] "GET /%2e%2e/.env HTTP/1.1" 400 166 "-" "-"
34.169.36.129 - - [24/Sep/2026:17:43:24 +0000] "GET /..%2f.env HTTP/1.1" 400 166 "-" "-"
34.169.36.129 - - [24/Sep/2026:17:43:24 +0000] "GET /..%2f..%2f.env HTTP/1.1" 400 166 "-" "-"
34.169.36.129 - - [24/Sep/2026:17:43:28 +0000] "GET /public/plugins/grafana-clock-panel/../../../../../../../../proc/self/environ HTTP/1.1" 400 166 "-" "-"
34.169.36.129 - - [24/Sep/2026:17:43:28 +0000] "GET /uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f.env HTTP/1.1" 400 166 "-" "-"
34.169.36.129 - - [24/Sep/2026:17:43:28 +0000] "GET /api/uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f.env HTTP/1.1" 400 166 "-" "-"
34.169.36.129 - - [24/Sep/2026:17:43:28 +0000] "GET /icons/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/proc/self/environ HTTP/1.1" 400 166 "-" "-"
...
show less
Hacking
Brute-Force
Web App Attack
SSH
๐ฉ๐ช
firestorm
2026-09-24 16:29:06
(7 hours ago)
34.169.36.129 - - [24/Sep/2026:18:29:06 +0200] "GET /..%2f.env HTTP/1.1" 400 150 "-" "-"
34.169.36.1 ...
show more
34.169.36.129 - - [24/Sep/2026:18:29:06 +0200] "GET /..%2f.env HTTP/1.1" 400 150 "-" "-"
34.169.36.129 - - [24/Sep/2026:18:29:06 +0200] "GET /%2e%2e/.env HTTP/1.1" 400 150 "-" "-"
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 13:27:05
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.169.36.129 (129.36.169.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.169.36.129 (129.36.169.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 09:26:58.088298 2026] [security2:error] [pid 3862:tid 3862] [client 34.169.36.129:39330] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "salkindsectzerproductions.starrmail.net"] [uri "/.env"] [unique_id "arUlIgjP3wQ5-JdHDRrG6AAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ด
Abuse Buster
2026-09-24 12:00:52
(11 hours ago)
34.169.36.129 - [24/Sep/2026:14:00:50 +0200] "GET /r1rnbs1e12kkbqv5rvqw HTTP/2.0" 404 5069 "-" "Mozi ...
show more
34.169.36.129 - [24/Sep/2026:14:00:50 +0200] "GET /r1rnbs1e12kkbqv5rvqw HTTP/2.0" 404 5069 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot)" Connecting ip: 34.169.36.129 Forwared for: 34.169.36.129
34.169.36.129 - [24/Sep/2026:14:00:50 +0200] "GET /build/manifest.json HTTP/2.0" 404 5069 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36" Connecting ip: 34.169.36.129 Forwared for: 34.169.36.129
34.169.36.129 - [24/Sep/2026:14:00:51 +0200] "GET /.vite/manifest.json HTTP/2.0" 403 548 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36" Connecting ip: 34.169.36.129 Forwared for: 34.169.36.129
...
show less
Web App Attack
๐ช๐ธ
bancix
2026-09-24 11:59:25
(11 hours ago)
Heimdallr NIDS: Automatic ban triggered. Reason: RST_LIMIT_EXCEEDED (10/10)
Port Scan
๐บ๐ธ
[email protected]
2026-09-24 11:26:32
(12 hours ago)
CrowdSec ban: crowdsecurity/unifi-flood-detection (duration: 71h59m51s)
Port Scan
๐ฉ๐ช
updown.io
2026-09-24 10:40:05
(13 hours ago)
{"level":"info","ts":1790246400.4370337,"logger":"http.log.access.log1","msg":"handled request","req ...
show more
{"level":"info","ts":1790246400.4370337,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"34.169.36.129","remote_port":"46374","client_ip":"34.169.36.129","proto":"HTTP/2.0","method":"GET","host":"shop.status.juicybeats.net","uri":"/assets/manifest.json","headers":{"Sec-Ch-Ua-Mobile":["?0"],"X-Nextjs-Data":["1"],"Accept-Language":["en-US,en;q=0.9"],"Accept":["*/*"],"Sec-Fetch-Dest":["script"],"X-Middleware-Subrequest":["src/middleware:nowaf:src/middleware:src/middleware:src/middleware:src/middleware:middleware:middleware:nowaf:middleware:middleware:middleware:pages/_middleware"],"User-Agent":["Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36"],"Sec-Ch-Ua-Platform":["\"Windows\""],"Priority":["u=1"],"Accept-Encoding":["gzip, deflate, br, zstd"],"Sec-Fetch-Mode":["no-cors"],"Sec-Fetch-Site":["same-origin"],"Sec-Ch-Ua":["\"Chromium\";v=\"153\", \"Brave\";v=\"153\", \"Not_A Brand\";v=\"8\""]},"tls"
...
show less
DDoS Attack
Web App Attack
๐ธ๐ฌ
Starburst SysOp Team
2026-09-24 10:17:48
(13 hours ago)
HTTP header is restricted by policy (/x-middleware-subrequest/). String match within "/content-encod ...
show more
HTTP header is restricted by policy (/x-middleware-subrequest/). String match within "/content-encoding/ /proxy/ /lock-token/ /content-range/ /if/ /x-http-method-override/ /x-http-method/ /x-method-override/ /x-middleware-subrequest/ /expect/" at TX:header_name_920450_x-middleware-subrequest. (920450-sin2-2)
show less
Bad Web Bot
๐บ๐ธ
JonathanYoung2161
2026-09-24 10:16:10
(13 hours ago)
sipconnect.simplifiedmedia.net 34.169.36.129 - - [24/Sep/2026:05:16:08 -0500] "GET /.env.old HTTP/2. ...
show more
sipconnect.simplifiedmedia.net 34.169.36.129 - - [24/Sep/2026:05:16:08 -0500] "GET /.env.old HTTP/2.0" 403 2998 "-" "Mozilla/5.0 (compatible; PanguBot/1.0; +https://www.huaweicloud.com/)"
sipconnect.simplifiedmedia.net 34.169.36.129 - - [24/Sep/2026:05:16:08 -0500] "GET /@fs/src/.env?raw?? HTTP/2.0" 403 2998 "-" "DuckAssistBot/1.1 (https://duckduckgo.com/duckassistbot)"
sipconnect.simplifiedmedia.net 34.169.36.129 - - [24/Sep/2026:05:16:08 -0500] "GET /@fs/app/.env?raw?? HTTP/2.0" 403 2998 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-SearchBot/1.0; [email protected] )"
...
show less
Brute-Force
Web App Attack
๐ฌ๐ง
noise.agency
2026-09-24 09:53:16
(13 hours ago)
34.169.36.129 (US/United States/129.36.169.34.bc.googleusercontent.com), more than 10 Apache 403 hit ...
show more
34.169.36.129 (US/United States/129.36.169.34.bc.googleusercontent.com), more than 10 Apache 403 hits
show less
Hacking
๐บ๐ธ
slay3r9903
2026-09-24 09:50:08
(13 hours ago)
Wazuh rule 100308: NPM sensitive-path storm: rule 100304 โฅ5 times in 10s from same IP
Brute-Force
Port Scan
๐ฉ๐ช
Gwyneth Llewelyn
2026-09-24 09:49:46
(13 hours ago)
2026/09/24 10:49:44 [error] 325888#325888: *1811566 access forbidden by rule, client: 34.169.36.129, ...
show more
2026/09/24 10:49:44 [error] 325888#325888: *1811566 access forbidden by rule, client: 34.169.36.129, server: slcocincubator.gwynethllewelyn.net, request: "GET /admin/.env HTTP/2.0", host: "slcocincubator.gwynethllewelyn.net"
2026/09/24 10:49:44 [error] 325888#325888: *1811589 access forbidden by rule, client: 34.169.36.129, server: slcocincubator.gwynethllewelyn.net, request: "GET /api/.env HTTP/2.0", host: "slcocincubator.gwynethllewelyn.net"
2026/09/24 10:49:44 [error] 325891#325891: *1811595 access forbidden by rule, client: 34.169.36.129, server: slcocincubator.gwynethllewelyn.net, request: "GET /backend/.env HTTP/2.0", host: "slcocincubator.gwynethllewelyn.net"
show less
Brute-Force
Web App Attack
๐ฉ๐ช
s@ch@
2026-09-24 09:00:07
(14 hours ago)
Jail: plesk-modsecurity | Web application attack (Plesk ModSecurity)
Web App Attack