Anonymous
2026-10-02 06:37:21
(1 day ago)
34.40.113.98 - - [02/Oct/2026:01:37:19 -0500] "GET /.env.prod HTTP/1.1" 403 199 "-" "Mozilla/5.0 App ...
show more
34.40.113.98 - - [02/Oct/2026:01:37:19 -0500] "GET /.env.prod HTTP/1.1" 403 199 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot)" 34.40.113.98
34.40.113.98 - - [02/Oct/2026:01:37:20 -0500] "GET /.env?raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; Google-Extended; +http://www.google.com/bot.html)" 34.40.113.98
34.40.113.98 - - [02/Oct/2026:01:37:20 -0500] "GET /.env?import&raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexitybot)" 34.40.113.98
34.40.113.98 - - [02/Oct/2026:01:37:20 -0500] "GET /.env?import&url&inline HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; PanguBot/1.0; +https://www.huaweicloud.com/)" 34.40.113.98
34.40.113.98 - - [02/Oct/2026:01:37:20 -0500] "GET /.env.local?raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; cohere-ai; +https://cohere.com/crawler)" 34.40.113.98
34.40.113.98 - - [02/Oct/2026:
...
show less
Brute-Force
Bad Web Bot
Web App Attack
πΏπ¦
vanderhost
2026-10-02 04:25:25
(1 day ago)
[Laravel HoneypotPlus] Automated report - Honeypot access detected on path: /.env.js via rule: regex ...
show more
[Laravel HoneypotPlus] Automated report - Honeypot access detected on path: /.env.js via rule: regex:/^\/\.env/i
show less
Web App Attack
Bad Web Bot
π«π·
phoenix1jl96
2026-10-02 03:38:19
(1 day ago)
2026/10/02 05:38:18 [error] 3302796#3302796: *440627 open() "/home/user-data/www/default/cgi-bin/php ...
show more
2026/10/02 05:38:18 [error] 3302796#3302796: *440627 open() "/home/user-data/www/default/cgi-bin/php-cgi.exe" failed (2: No such file or directory), client: 34.40.113.98, server: box.ledemon.us, request: "POST /cgi-bin/php-cgi.exe?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input HTTP/2.0", host: "ledemon.us"
2026/10/02 05:38:18 [error] 3302796#3302796: *440627 open() "/home/user-data/www/default/cgi-bin/php" failed (2: No such file or directory), client: 34.40.113.98, server: box.ledemon.us, request: "POST /cgi-bin/php?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input HTTP/2.0", host: "ledemon.us"
...
show less
DNS Compromise
DNS Poisoning
DDoS Attack
Ping of Death
Web Spam
Email Spam
Blog Spam
Port Scan
Hacking
Brute-Force
Bad Web Bot
SSH
Web App Attack
π¦πΊ
clapper
2026-10-02 03:28:18
(1 day ago)
(mod_security) mod_security (id:980001) triggered by 34.40.113.98 (DE/Germany/98.113.40.34.bc.google ...
show more
(mod_security) mod_security (id:980001) triggered by 34.40.113.98 (DE/Germany/98.113.40.34.bc.googleusercontent.com): 5 in the last 3600 secs; ID: Clar
show less
Brute-Force
Bad Web Bot
π©πͺ
netclix.gr
2026-10-02 02:53:59
(1 day ago)
(bot_kill_mega) Aggressive Bot Blocked: OAI-SearchBot 34.40.113.98 (DE/Germany/98.113.40.34.bc.googl ...
show more
(bot_kill_mega) Aggressive Bot Blocked: OAI-SearchBot 34.40.113.98 (DE/Germany/98.113.40.34.bc.googleusercontent.com): 1 in the last 4600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 34.40.113.98 - - [02/Oct/2026:05:53:55 +0300] "GET /2fkjb0yjxiu6v6s6hn1k HTTP/2.0" 404 532 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36; compatible; OAI-SearchBot/1.4; +https://openai.com/searchbot" "-"'/error_docs/404.html' '' '/opt/psa/admin/htdocs'
show less
Port Scan
π©πͺ
Philister11
2026-10-02 02:15:46
(1 day ago)
CrowdSec: crowdsecurity/http-admin-interface-probing (DE/AS396982)
Web App Attack
Hacking
πΊπΈ
TPI-Abuse
2026-10-02 00:51:22
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.40.113.98 (98.113.40.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.40.113.98 (98.113.40.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 20:51:16.802768 2026] [security2:error] [pid 24705:tid 24705] [client 34.40.113.98:48012] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||teenybikinigirls.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "teenybikinigirls.com"] [uri "/z9x8c7v6b5-debug-trigger-teenybikinigirls.com"] [unique_id "ar8ABMOtustHT3Ld7Op7UwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π·π΄
gtheo99
2026-10-01 23:31:41
(1 day ago)
(CT) IP 34.40.113.98 (DE/Germany/98.113.40.34.bc.googleusercontent.com) found to have 171 connection ...
show more
(CT) IP 34.40.113.98 (DE/Germany/98.113.40.34.bc.googleusercontent.com) found to have 171 connections
show less
Port Scan
π©πͺ
niedson
2026-10-01 22:30:02
(1 day ago)
Automated scanning for exposed secrets: repeated requests for multiple distinct credential paths (.e ...
show more
Automated scanning for exposed secrets: repeated requests for multiple distinct credential paths (.env variants, .git metadata, .ssh private keys, .aws/credentials). Unsolicited. Reported automatically.
show less
Web App Attack
π«π·
Octopuce
2026-10-01 22:11:17
(1 day ago)
Aggressive web search of vulnerable pages: /uploads../.env /assets../.env /images../.env /js../.env ...
show more
Aggressive web search of vulnerable pages: /uploads../.env /assets../.env /images../.env /js../.env /public../.env ...
show less
Web App Attack
πͺπΈ
robotstxt
2026-10-01 21:30:07
(1 day ago)
34.40.113.98 - - [01/Oct/2026:21:30:02 +0000] "GET /static/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2fproc/ ...
show more
34.40.113.98 - - [01/Oct/2026:21:30:02 +0000] "GET /static/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2fproc/self/environ HTTP/1.1" 400 193 "-" "-" "-" edge="34.40.113.98"
34.40.113.98 - - [01/Oct/2026:21:30:02 +0000] "GET /static/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f.env HTTP/1.1" 400 193 "-" "-" "-" edge="34.40.113.98"
34.40.113.98 - - [01/Oct/2026:21:30:02 +0000] "GET /resources/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f.env HTTP/1.1" 400 193 "-" "-" "-" edge="34.40.113.98"
34.40.113.98 - - [01/Oct/2026:21:30:03 +0000] "GET /%2e%2e/.env HTTP/1.1" 400 193 "-" "-" "-" edge="34.40.113.98"
34.40.113.98 - - [01/Oct/2026:21:30:03 +0000] "GET /..%2f.env HTTP/1.1" 400 193 "-" "-" "-" edge="34.40.113.98"
...
show less
Web Spam
Web App Attack
π¬π§
gigatech
2026-10-01 21:25:03
(1 day ago)
Webserver Probing
Web App Attack
πΏπ¦
conure.sh
2026-10-01 19:53:07
(1 day ago)
csagent: score 20.4: secrets grab x1, spoofed crawler UA x1, wp-login GET x1; 1 domain(s) in 15s
Web App Attack
π©πͺ
pscriptos
2026-10-01 18:29:54
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-path-traversal-probing
Web App Attack
Hacking
πΊπΈ
TPI-Abuse
2026-10-01 17:46:05
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.40.113.98 (98.113.40.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.40.113.98 (98.113.40.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 13:46:01.420543 2026] [security2:error] [pid 18463:tid 18463] [client 34.40.113.98:40824] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.sbxyz.net"] [uri "/.htpasswd"] [unique_id "ar6cWRr5H7NzXh-WlHvhAAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack