🇩🇪
Blexyel
2026-09-13 06:20:06
(28 minutes ago)
34.21.5.77 - - [13/Sep/2026:08:20:05 +0200] "GET /.git/config HTTP/1.1" 200 265 "-" "Mozilla/5.0 App ...
show more
34.21.5.77 - - [13/Sep/2026:08:20:05 +0200] "GET /.git/config HTTP/1.1" 200 265 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; [email protected] )" "pingusmc.org"
...
show less
Brute-Force
Web App Attack
🇩🇪
lolyay
2026-09-13 06:04:38
(43 minutes ago)
34.21.5.77 - - [13/Sep/2026:06:04:36 +0000] "GET /rclone.conf HTTP/1.1" 200 4 "-" "Mozilla/5.0 (comp ...
show more
34.21.5.77 - - [13/Sep/2026:06:04:36 +0000] "GET /rclone.conf HTTP/1.1" 200 4 "-" "Mozilla/5.0 (compatible; Hunyuan/1.0; +https://hunyuan.tencent.com/)"
34.21.5.77 - - [13/Sep/2026:06:04:37 +0000] "GET /var/run/secrets/kubernetes.io/serviceaccount/token HTTP/1.1" 200 4 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot)"
...
show less
Web App Attack
Bad Web Bot
🇺🇸
infra-monitor
2026-09-13 06:00:06
(48 minutes ago)
Automated ban via infra-monitor: suspicious-probe, wp-sensitive-paths, mgmt-path-probe, +5 more
Port Scan
Bad Web Bot
Web App Attack
🇮🇳
evicky2002
2026-09-13 06:00:01
(48 minutes ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
🇩🇰
toolbit.online
2026-09-13 05:06:38
(1 hour ago)
Automated reconnaissance behaviour detected by CrowdSec - 5 suspicious requests across application p ...
show more
Automated reconnaissance behaviour detected by CrowdSec - 5 suspicious requests across application paths. Classified as automated probing for exposed files / admin panels (scenario "http-sensitive-files", in our own server logs). Behavioural detection, auto-banned at the firewall.
show less
Bad Web Bot
Web App Attack
🇱🇹
im
2026-09-13 04:14:44
(2 hours ago)
HTTP tcp/8080 tcp/8443
Port Scan
🇬🇧
consul.to
2026-09-13 01:20:39
(5 hours ago)
Web attack/malicious scanning detected
Web App Attack
🇫🇷
✨
2026-09-13 01:07:14
(5 hours ago)
Domain : ido.org.pk
Rule : env
2026-09-13 01:03:37 ***hidden-privacy*** GET /static../.env - 443 - 3 ...
show more
Domain : ido.org.pk
Rule : env
2026-09-13 01:03:37 ***hidden-privacy*** GET /static../.env - 443 - 34.21.5.77 HTTP/2 Mozilla/5.0 (compatible; ChatGLM-Spider/1.0; https://zhipuai.cn/) - ido.org.pk 403 0 0 1233 390 106 - -
show less
Hacking
SQL Injection
🇺🇸
TPI-Abuse
2026-09-13 00:58:29
(5 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.21.5.77 (77.5.21.34.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:210730) triggered by 34.21.5.77 (77.5.21.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 20:58:24.775988 2026] [security2:error] [pid 27418:tid 27418] [client 34.21.5.77:54570] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||idledog.com|F|2"] [data ".key"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "idledog.com"] [uri "/ssl/server.key"] [unique_id "aqX1MFrHInm3EC1w8_NH_QAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-13 00:43:17
(6 hours ago)
34.21.5.77 - - [13/Sep/2026:08:43:15 +0800] "GET /__vite_rsc_findSourceMapURL?filename=file:///app/. ...
show more
34.21.5.77 - - [13/Sep/2026:08:43:15 +0800] "GET /__vite_rsc_findSourceMapURL?filename=file:///app/.env&environmentName=rsc HTTP/1.1" 404 13845 "-" "Mozilla/5.0 (compatible; KimiBot/1.0; +https://kimi.ai/)"
...
show less
Bad Web Bot
Web App Attack
🇮🇹
VHosting
2026-09-13 00:40:03
(6 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇫🇷
dynamix
2026-09-13 00:35:30
(6 hours ago)
Multiple WAF Violations
Web App Attack
🇫🇷
Zundapper
2026-09-13 00:22:52
(6 hours ago)
34.21.5.77 - - [13/Sep/2026:02:22:51 +0200] "GET /admin/login HTTP/2.0" 404 167 "-" "Mozilla/5.0 (Ma ...
show more
34.21.5.77 - - [13/Sep/2026:02:22:51 +0200] "GET /admin/login HTTP/2.0" 404 167 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
34.21.5.77 - - [13/Sep/2026:02:22:51 +0200] "GET /backoffice HTTP/2.0" 404 167 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
34.21.5.77 - - [13/Sep/2026:02:22:51 +0200] "GET /ssl/server.key HTTP/2.0" 404 106 "-" "Mozilla/5.0 (compatible; KimiBot/1.0; +https://kimi.ai/)"
34.21.5.77 - - [13/Sep/2026:02:22:51 +0200] "GET /rclone.conf HTTP/2.0" 404 106 "-" "Mozilla/5.0 (compatible; xAI-Grok/1.0; +https://x.ai/)"
34.21.5.77 - - [13/Sep/2026:02:22:51 +0200] "GET /ssl/localhost.key HTTP/2.0" 404 106 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot)"
...
show less
Web App Attack
Port Scan
🇺🇸
TPI-Abuse
2026-09-13 00:18:43
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.21.5.77 (77.5.21.34.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:210492) triggered by 34.21.5.77 (77.5.21.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 20:18:37.925243 2026] [security2:error] [pid 30588:tid 30660] [client 34.21.5.77:35232] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "idealcentralvac.com"] [uri "/__vite_rsc_findSourceMapURL"] [unique_id "aqXr3etmFS6eNkBD98McLQAAARg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 23:58:29
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.21.5.77 (77.5.21.34.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:210492) triggered by 34.21.5.77 (77.5.21.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 19:58:25.425478 2026] [security2:error] [pid 21857:tid 21857] [client 34.21.5.77:44594] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "idahostem.org"] [uri "/%2E%2E/%2E%2E/%2E%2E/%2E%2E/.env"] [unique_id "aqXnIWgIZTSkM04B5TAHKAAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack