๐ฉ๐ช
klaus_ph
2026-09-26 10:26:46
(1 day ago)
2026-09-25 15:00:13,824 fail2ban.actions [594716]: NOTICE [ipblocklist] Ban 34.21.208.252
.. ...
show more
2026-09-25 15:00:13,824 fail2ban.actions [594716]: NOTICE [ipblocklist] Ban 34.21.208.252
...
show less
Bad Web Bot
๐ฎ๐ณ
evicky2002
2026-09-23 06:00:01
(4 days ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐ฉ๐ช
reznekcs
2026-09-23 05:03:50
(5 days ago)
Blocked by UFW firewall
Brute-Force
๐ง๐ช
voormedia
2026-09-23 02:10:47
(5 days ago)
Accessed trap at '/.env'
Web App Attack
๐ญ๐บ
kranem
2026-09-23 00:01:29
(5 days ago)
Triggered Cloudflare WAF from SG.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Protocol: HTTP/2 (GET ...
show more
Triggered Cloudflare WAF from SG.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Protocol: HTTP/2 (GET method)
Endpoint: /
Timestamp: 2026-09-22T22:17:08Z
User-Agent: Mozilla/5.0 (compatible; MistralAI-User/1.0; +https://mistral.ai/)
show less
Bad Web Bot
Anonymous
2026-09-22 23:50:24
(5 days ago)
[Wed Sep 23 01:50:23.450686 2026] [proxy_fcgi:error] [pid 575930:tid 575991] [remote 34.21.208.252:3 ...
show more
[Wed Sep 23 01:50:23.450686 2026] [proxy_fcgi:error] [pid 575930:tid 575991] [remote 34.21.208.252:36162] AH01071: Got error 'Primary script unknown'
[Wed Sep 23 01:50:23.516797 2026] [proxy_fcgi:error] [pid 575930:tid 575956] [remote 34.21.208.252:36162] AH01071: Got error 'Primary script unknown'
[Wed Sep 23 01:50:23.796884 2026] [proxy_fcgi:error] [pid 575930:tid 575967] [remote 34.21.208.252:36162] AH01071: Got error 'Primary script unknown'
...
show less
Brute-Force
Web App Attack
๐ซ๐ท
guillaume illien
2026-09-22 22:54:08
(5 days ago)
34.21.208.252 - - [22/Sep/2026:22:54:06 +0000] "GET /..%2f.env HTTP/1.1" 400 166 "-" "-"
34.21.208.2 ...
show more
34.21.208.252 - - [22/Sep/2026:22:54:06 +0000] "GET /..%2f.env HTTP/1.1" 400 166 "-" "-"
34.21.208.252 - - [22/Sep/2026:22:54:06 +0000] "GET /public/plugins/alertlist/../../../../../../../../proc/self/environ HTTP/1.1" 400 166 "-" "-"
34.21.208.252 - - [22/Sep/2026:22:54:06 +0000] "GET /api/uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2fproc/self/environ HTTP/1.1" 400 166 "-" "-"
34.21.208.252 - - [22/Sep/2026:22:54:06 +0000] "GET /..%2f..%2f.env HTTP/1.1" 400 166 "-" "-"
34.21.208.252 - - [22/Sep/2026:22:54:06 +0000] "GET /api/uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f.env HTTP/1.1" 400 166 "-" "-"
34.21.208.252 - - [22/Sep/2026:22:54:06 +0000] "GET /uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f.env HTTP/1.1" 400 166 "-" "-"
34.21.208.252 - - [22/Sep/2026:22:54:08 +0000] "GET /%2e%2e/.env HTTP/1.1" 400 166 "-" "-"
...
show less
Hacking
Brute-Force
Web App Attack
SSH
๐ณ๐ฑ
oisecnet
2026-09-22 21:03:08
(5 days ago)
Automated report: Unauthorized vulnerability scanning detected on 2026-09-22. 828 requests from this ...
show more
Automated report: Unauthorized vulnerability scanning detected on 2026-09-22. 828 requests from this IP.
show less
Port Scan
Hacking
Web App Attack
๐ญ๐บ
kranem
2026-09-22 18:01:06
(5 days ago)
Triggered Cloudflare WAF from SG.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Protocol: HTTP/2 (GET ...
show more
Triggered Cloudflare WAF from SG.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Protocol: HTTP/2 (GET method)
Endpoint: /.gitconfig
Timestamp: 2026-09-22T12:11:30Z
User-Agent: Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)
show less
Bad Web Bot
๐น๐ท
crnpekgoz
2026-09-22 15:03:34
(5 days ago)
Malicious HTTP GET request for '/@fs/app/.env?raw??' (HTTP 301) from 34.21.208.252. Threat: Web Gรผve ...
show more
Malicious HTTP GET request for '/@fs/app/.env?raw??' (HTTP 301) from 34.21.208.252. Threat: Web Gรผvenlik Aรงฤฑฤฤฑ Taramasฤฑ (.env/bot). Blocked by WardenGuard Web Shield.
show less
Web App Attack
๐ฉ๐ช
Bedios GmbH
2026-09-22 14:17:17
(5 days ago)
Login credentials theft attempt
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-22 13:33:50
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 34.21.208.252 (252.208.21.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.21.208.252 (252.208.21.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 09:33:46.761761 2026] [security2:error] [pid 27908:tid 27908] [client 34.21.208.252:34614] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.ypsisda.net"] [uri "/.htpasswd"] [unique_id "arKDugfwHXSSmh4ANqLunAAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 12:26:01
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 34.21.208.252 (252.208.21.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.21.208.252 (252.208.21.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 08:25:56.938736 2026] [security2:error] [pid 14420:tid 14420] [client 34.21.208.252:35164] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/Web.config" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.pluralmatrix.net"] [uri "/web.config"] [unique_id "arJz1FxNfgAKO5PPph2J7QAAADA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ญ๐บ
kranem
2026-09-22 12:00:37
(5 days ago)
Triggered Cloudflare WAF from SG.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Protocol: HTTP/2 (GET ...
show more
Triggered Cloudflare WAF from SG.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Protocol: HTTP/2 (GET method)
Endpoint: /build../.env
Timestamp: 2026-09-22T09:04:53Z
User-Agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-SearchBot/1.0; [email protected] )
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-22 11:36:14
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 34.21.208.252 (252.208.21.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.21.208.252 (252.208.21.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 07:36:08.131319 2026] [security2:error] [pid 13720:tid 13834] [client 34.21.208.252:51558] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.appraisalteam.net"] [uri "/.env.swp"] [unique_id "arJoKCrMyVdROKIIOGK_DwAAAoM"]
show less
Brute-Force
Bad Web Bot
Web App Attack