πΊπΈ
Gabriel Camargo
2026-08-31 09:04:41
(1 day ago)
34.34.229.34 - - [31/Aug/2026:04:04:40 -0500] "GET / HTTP/1.1" 404 134 "-" "Mozilla/5.0"
34.34.229.3 ...
show more
34.34.229.34 - - [31/Aug/2026:04:04:40 -0500] "GET / HTTP/1.1" 404 134 "-" "Mozilla/5.0"
34.34.229.34 - - [31/Aug/2026:04:04:40 -0500] "GET / HTTP/1.1" 404 162 "-" "feroxbuster/2.13.1"
34.34.229.34 - - [31/Aug/2026:04:04:40 -0500] "GET /robots.txt HTTP/1.1" 404 162 "-" "feroxbuster/2.13.1"
...
show less
Brute-Force
SSH
πΊπΈ
jormaster3k
2026-08-31 05:48:37
(1 day ago)
Attack against Apache (too many 404s)
Web App Attack
π§πΎ
lns.bz
2026-08-31 04:59:34
(1 day ago)
Too many 404 requests [BY]
Web App Attack
π³πΏ
Antinson
2026-08-31 03:28:52
(1 day ago)
Requests to unauthorized or suspicious endpoints (.git, .well-known, .php, etc.)
Bad Web Bot
π¬π§
WebNiraj
2026-08-31 02:19:40
(1 day ago)
(mod_security) mod_security (id:949110) triggered by 34.34.229.34 (US/United States/-): 5 in the las ...
show more
(mod_security) mod_security (id:949110) triggered by 34.34.229.34 (US/United States/-): 5 in the last 3600 secs [SIGMA]
show less
Brute-Force
π©πͺ
F2BP
2026-08-30 15:38:25
(1 day ago)
Fail2Ban [wordpress-auth] - Observed: repeated_web_exploit_attempts (web_attack)
Target: http:80/tcp ...
show more
Fail2Ban [wordpress-auth] - Observed: repeated_web_exploit_attempts (web_attack)
Target: http:80/tcp | Activity: 15 attempts within 26039s
Timeline: 2026-08-30T08:23:21Z - 2026-08-30T15:37:20Z
Evidence:
2026-08-30T15:37:20Z 34.34.229.34 "GET /v2/.env HTTP/1.1" 404
2026-08-30T15:37:20Z 34.34.229.34 "GET /api/v1/.git/config HTTP/1.1" 404
2026-08-30T15:37:20Z 34.34.229.34 "GET /v3/.env HTTP/1.1" 404
2026-08-30T15:37:20Z 34.34.229.34 "GET /api/v2/.git/config HTTP/1.1" 404
2026-08-30T15:37:20Z 34.34.229.34 "GET /api/v1/.env HTTP/1.1" 404
2026-08-30T15:37:20Z 34.34.229.34 "GET /api/v2/.env HTTP/1.1" 404
2026-08-30T15:37:20Z 34.34.229.34 "GET /rest/.env HTTP/1.1" 404
show less
Web App Attack
π«π·
tecnicorioja
2026-08-29 22:02:36
(2 days ago)
(Mod_security)
Web App Attack
Brute-Force
Bad Web Bot
πΊπΈ
RidgeStar
2026-08-29 13:31:12
(3 days ago)
Hacking
Web App Attack
π―π΅
VXG-NET
2026-08-29 07:36:30
(3 days ago)
port=80, indicator_type=info-leak
Hacking
πͺπΈ
Francisco Vallejo
2026-08-28 19:21:57
(3 days ago)
[Fri Aug 28 21:21:55.562776 2026] [core:info] [pid 934967:tid 140579748951744] [client 34.34.229.34: ...
show more
[Fri Aug 28 21:21:55.562776 2026] [core:info] [pid 934967:tid 140579748951744] [client 34.34.229.34:59477] AH00128: File does not exist: /var/www/franvallejo/37b2bef1ba444abba8f32e546ec5dfe9
[Fri Aug 28 21:21:55.564144 2026] [core:info] [pid 934967:tid 140580159997632] [client 34.34.229.34:19213] AH00128: File does not exist: /var/www/franvallejo/a6fc13ca94184786bf1dcf689f6649f9eff8309f566c4b15a0d85cb7602d1ba5d81a7b3065f64ba88fbb5d3a562c8ae6
[Fri Aug 28 21:21:55.862968 2026] [core:info] [pid 934967:tid 140579178542784] [client 34.34.229.34:36425] AH00128: File does not exist: /var/www/franvallejo/admin7d2dbf0cdfb74492a5f3ee0ce06e3d9f
[Fri Aug 28 21:21:55.982525 2026] [core:info] [pid 934967:tid 140579782522560] [client 34.34.229.34:59477] AH00128: File does not exist: /var/www/franvallejo/admin5fd065fad3dc4205b4671dad6e350dfb297a1fddf8bd46d09ae8f67ba42004c99ab04b65047c4e64bab212efc7e59417
[Fri Aug 28 21:21:56.159947 2026] [core:info] [pid 934966:tid 140579170150080] [client 34.34.229.3
...
show less
Brute-Force
SSH
π«π·
SSH-Admin
2026-08-27 23:00:42
(4 days ago)
Probing for Exploits
Exploited Host
Web App Attack
Anonymous
2026-08-27 16:28:51
(4 days ago)
Multiple web server 400 error codes from same source ip
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-27 10:47:40
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 34.34.229.34 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 34.34.229.34 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 06:47:31.460787 2026] [security2:error] [pid 28307:tid 28307] [client 34.34.229.34:33858] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.aaabft.com"] [uri "/.htaccessd91829ca0b324ab482698bb17baec578e485be31ea964c8a8af940f9aa0ee978c985a38d0dab4e79af44b66061fbd3fb"] [unique_id "apAVw3GTyN15rcnMtvh9UAAAADA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-27 09:38:39
(5 days ago)
34.34.229.34 detected on srv01
Brute-Force
πΊπΈ
TPI-Abuse
2026-08-27 06:24:20
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 34.34.229.34 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 34.34.229.34 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 02:24:12.885826 2026] [security2:error] [pid 5285:tid 5366] [client 34.34.229.34:20766] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.133"] [uri "/.htaccessda2db2c063294ebbb1090a4173942b8b"] [unique_id "ao_YDHqAXJXwvYb4b0UD-AAAAcQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack