🇩🇪
maxpower
2026-09-11 00:46:25
(4 minutes ago)
(junkbot) REGOLA 8 - Junk Bot Blocked 34.185.170.43 (DE/Germany/43.170.185.34.bc.googleusercontent.c ...
show more
(junkbot) REGOLA 8 - Junk Bot Blocked 34.185.170.43 (DE/Germany/43.170.185.34.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 34.185.170.43 - - [11/Sep/2026:02:46:22 +0200] "GET /proc/self/cmdline HTTP/2.0" 200 12183 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; [email protected] )" "-" host=fondazioneilcireneo.it
show less
Port Scan
🇩🇪
FeG Deutschland
2026-09-11 00:33:28
(17 minutes ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 1247
Exploited Host
Web App Attack
🇩🇪
macrob
2026-09-11 00:30:45
(20 minutes ago)
2026/09/11 00:30:43 [error] 100822#100822: *721562 access forbidden by rule, client: 34.185.170.43, ...
show more
2026/09/11 00:30:43 [error] 100822#100822: *721562 access forbidden by rule, client: 34.185.170.43, server: fastcredit.net.ua, request: "GET /.git/config HTTP/2.0", host: "fastcredit.net.ua"
2026/09/11 00:30:43 [error] 100822#100822: *721562 access forbidden by rule, client: 34.185.170.43, server: fastcredit.net.ua, request: "GET /.aws/credentials HTTP/2.0", host: "fastcredit.net.ua"
2026/09/11 00:30:43 [error] 100822#100822: *721562 access forbidden by rule, client: 34.185.170.43, server: fastcredit.net.ua, request: "GET /.aws/config HTTP/2.0", host: "fastcredit.net.ua"
...
show less
Web App Attack
🇩🇪
Skyrider
2026-09-11 00:16:01
(35 minutes ago)
Nginx: HTTP 4xx probe/scan attempts. Automated fail2ban report.
Bad Web Bot
Web App Attack
Anonymous
2026-09-11 00:11:27
(39 minutes ago)
suspicious request in access.log
Web App Attack
🇪🇸
el-brujo
2026-09-11 00:11:06
(40 minutes ago)
34.185.170.43 - - [11/Sep/2026:02:03:58 +0200] "GET /rclone.conf HTTP/2.0" 404 15909 "-" "Mozilla/5. ...
show more
34.185.170.43 - - [11/Sep/2026:02:03:58 +0200] "GET /rclone.conf HTTP/2.0" 404 15909 "-" "Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; +https://kimi.ai/)"
34.185.170.43 - - [11/Sep/2026:02:03:58 +0200] "GET /api/w/default/jobs_u/get_log_file/../../../../proc/self/environ HTTP/2.0" 404 15909 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ChatGPT-User/1.0; +https://openai.com/bot)"
34.185.170.43 - - [11/Sep/2026:02:03:58 +0200] "GET /build/manifest.json HTTP/2.0" 404 15909 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36 Edg/152.0.0.0"
34.185.170.43 - - [11/Sep/2026:02:03:58 +0200] "GET /dist/.vite/manifest.json HTTP/2.0" 404 15909 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36 Edg/152.0.0.0"
...
show less
Web App Attack
Hacking
🇫🇷
Baking333
2026-09-10 23:46:23
(1 hour ago)
[redacted] 34.185.170.43 - - [11/Sep/2026:00:46:21 +0100] "GET /.env?import&url&inline HTTP/1.1" 302 ...
show more
[redacted] 34.185.170.43 - - [11/Sep/2026:00:46:21 +0100] "GET /.env?import&url&inline HTTP/1.1" 302 1559 0/55149 "-" "Mozilla/5.0 (compatible; KimiBot/1.0; +https://[redacted]/)" [redacted] 34.185.170.43 - - [11/Sep/2026:00:46:21 +0100] "GET /.env?import&raw HTTP/1.1" 302 1559 0/42650 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot@[redacted])"
show less
Bad Web Bot
Web App Attack
🇳🇱
mieg
2026-09-10 23:45:25
(1 hour ago)
Web vulnerability probing
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-10 23:32:52
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.185.170.43 (43.170.185.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.185.170.43 (43.170.185.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 10 19:32:47.143158 2026] [security2:error] [pid 11504:tid 11504] [client 34.185.170.43:44476] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dmasoftlab.com"] [uri "/.github/.env"] [unique_id "aqM-H6S07GqJDgRyYZQEMgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
Octopuce
2026-09-10 23:18:28
(1 hour ago)
Aggressive web search of vulnerable pages: /images../.env /assets../.env /uploads../.env /.docker/.e ...
show more
Aggressive web search of vulnerable pages: /images../.env /assets../.env /uploads../.env /.docker/.env /.env.local /.env /admin/.env /backend/. ...
show less
Web App Attack
Anonymous
2026-09-10 23:13:18
(1 hour ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 34.185.170.43 (DE/Ge ...
show more
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 34.185.170.43 (DE/Germany/43.170.185.34.bc.googleusercontent.com)
show less
Bad Web Bot
🇫🇷
dynamix
2026-09-10 22:42:27
(2 hours ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2026-09-10 22:41:58
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.185.170.43 (43.170.185.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.185.170.43 (43.170.185.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 10 18:41:54.923785 2026] [security2:error] [pid 5315:tid 5315] [client 34.185.170.43:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cloudex.click"] [uri "/.env.php.bak"] [unique_id "aqMyMpAyz903cHF_h51MAwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
COMAITE
2026-09-10 22:41:48
(2 hours ago)
Suspicious URL access.
Web App Attack
🇬🇧
Marten Mark
2026-09-10 22:24:34
(2 hours ago)
34.185.170.43 - - [10/Sep/2026:22:20:09 +0000] "GET /build/manifest.json HTTP/2.0" 404 23033 "-" "Mo ...
show more
34.185.170.43 - - [10/Sep/2026:22:20:09 +0000] "GET /build/manifest.json HTTP/2.0" 404 23033 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Mobile Safari/537.36"
34.185.170.43 - - [10/Sep/2026:22:20:09 +0000] "GET /rclone.conf HTTP/2.0" 404 23033 "-" "Mozilla/5.0 (compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot)"
34.185.170.43 - - [10/Sep/2026:22:20:09 +0000] "GET /z9x8c7v6b5-debug-trigger-cfi.co HTTP/2.0" 404 23033 "-" "Mozilla/5.0 (compatible; GrokBot/1.0; +https://x.ai/)"
34.185.170.43 - - [10/Sep/2026:22:20:09 +0000] "GET /.vite/manifest.json HTTP/2.0" 404 23033 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Mobile Safari/537.36"
34.185.170.43 - - [10/Sep/2026:22:20:10 +0000] "GET /dist/manifest.json HTTP/2.0" 404 23033 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Mobile Safari/537.36"
34.185.170.43 - - [10/S
...
show less
Port Scan
Web App Attack