Anonymous
2026-09-16 13:45:05
(2 days ago)
Observed scanned 10 known-sensitive endpoint(s), e.g.: /.env.backup, /.git/config, /api/.env/public/ ...
show more
Observed scanned 10 known-sensitive endpoint(s), e.g.: /.env.backup, /.git/config, /api/.env/public/.env, /api/uploads/%2e%2e%2f%2e%2e%2f.env, /assets../.env, /pi.php
show less
Bad Web Bot
Web App Attack
๐ซ๐ท
IRISIO
2026-09-16 10:49:22
(2 days ago)
scans/SQL injection/spam posts : 748 queries
Web App Attack
SQL Injection
Anonymous
2026-09-16 01:29:16
(2 days ago)
34.73.38.109 - - [15/Sep/2026:14:39:00 +0200] "GET /.bashrc HTTP/2.0" 403 268 "-" "Mozilla/5.0 (comp ...
show more
34.73.38.109 - - [15/Sep/2026:14:39:00 +0200] "GET /.bashrc HTTP/2.0" 403 268 "-" "Mozilla/5.0 (compatible; Google-Extended; +http://www.google.com/bot.html)"
show less
Web Spam
Blog Spam
Brute-Force
Web App Attack
๐ฌ๐ง
consul.to
2026-09-16 00:27:25
(2 days ago)
Web attack/malicious scanning detected
Web App Attack
๐ฎ๐ณ
evicky2002
2026-09-16 00:02:04
(2 days ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐บ๐ธ
jormaster3k
2026-09-15 22:47:55
(2 days ago)
Attack against Apache (too many 404s)
Web App Attack
๐ฉ๐ช
Marc
2026-09-15 22:46:37
(2 days ago)
34.73.38.109 - - [16/Sep/2026:00:46:37 +0200] "GET /secure HTTP/2.0" 404 291 "-" "Mozilla/5.0 (Windo ...
show more
34.73.38.109 - - [16/Sep/2026:00:46:37 +0200] "GET /secure HTTP/2.0" 404 291 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36 Edg/152.0.0.0" 34.73.38.109 - - [16/Sep/2026:00:46:37 +0200] "GET /z9x8c7v6b5-debug-trigger-risse.cloud HTTP/2.0" 404 269 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; OAI-SearchBot/1.0; +https://openai.com/searchbot)" 34.73.38.109 - - [16/Sep/2026:00:46:37 +0200] "GET /.s3cfg HTTP/2.0" 404 269 "-" "Mozilla/5.0 (compatible; Meta-ExternalAgent/1.0; +https://developers.facebook.com/docs/sharing/webmasters/crawler)"
show less
Brute-Force
๐ฉ๐ช
Guardian
2026-09-15 22:42:17
(2 days ago)
Multi abuses [2]: Unauthorized connection attempt / Port scanning (x33), Unauthorized attempt to ret ...
show more
Multi abuses [2]: Unauthorized connection attempt / Port scanning (x33), Unauthorized attempt to retrieve configuration file (x6)
34.73.38.109 [16/Sep/2026:00:42:16 +0200] "GET / HTTP/1.1"
34.73.38.109 [16/Sep/2026:00:42:16 +0200] "GET /@fs/.env?url&raw?? HTTP/1.1"
34.73.38.109 [16/Sep/2026:00:42:16 +0200] "GET /portal HTTP/1.1"
34.73.38.109 [16/Sep/2026:00:42:16 +0200] "GET /@fs/.env?raw&url?? HTTP/1.1"
34.73.38.109 [16/Sep/2026:00:42:16 +0200] "GET /console HTTP/1.1"
34.73.38.109 [16/Sep/2026:00:42:16 +0200] "GET /api%2F.env HTTP/1.1"
34.73.38.109 [16/Sep/2026:00:42:16 +0200] "GET /backoffice HTTP/1.1"
34.73.38.109 [16/Sep/2026:00:42:16 +0200] "GET /secure HTTP/1.1"
34.73.38.109 [16/Sep/2026:00:42:16 +0200] "GET /rclone.conf HTTP/1.1"
34.73.38.109 [16/Sep/2026:00:42:16 +0200] "GET /panel HTTP/1.1"
34.73.38.109 [16/Sep/2026:00:42:16 +0200] "GET /z9x8c7v6b5-debug-trigger-******.*** HTTP/1.1"
34.73.38.109 [16/Sep/2026:00:42:16 +0200] "GET /settings%2F.env HTTP/1.1"
34.73.38.109 [16/Sep/2026:00:42:16 +0200] "G
show less
Port Scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 22:13:12
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 34.73.38.109 (109.38.73.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.73.38.109 (109.38.73.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 18:13:05.470814 2026] [security2:error] [pid 1700:tid 1776] [client 34.73.38.109:59690] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||peluqueriabuhos.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "peluqueriabuhos.com"] [uri "/rclone.conf"] [unique_id "aqnC8Tmf95lptYz4Bim-qAAAAgw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐น๐ญ
MWA SOC
2026-09-15 21:28:04
(2 days ago)
Hacking
๐บ๐ธ
mnsf
2026-09-15 21:05:49
(2 days ago)
Abuse Detected (6)
Brute-Force
Web App Attack
๐ฉ๐ช
konseptit
2026-09-15 20:59:14
(2 days ago)
(mod_security) mod_security triggered on hostname [redacted] 34.73.38.109 (US/United States/109.38.7 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.73.38.109 (US/United States/109.38.73.34.bc.googleusercontent.com)
show less
SQL Injection
๐ฉ๐ช
akasolutions.de
2026-09-15 19:51:50
(2 days ago)
(mod_security) mod_security triggered on hostname [redacted] 34.73.38.109 (US/United States/109.38.7 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.73.38.109 (US/United States/109.38.73.34.bc.googleusercontent.com)
show less
SQL Injection
๐ธ๐ช
vaia.cloud
2026-09-15 19:50:03
(2 days ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 19:49:43
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 34.73.38.109 (109.38.73.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.73.38.109 (109.38.73.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 15:49:40.132246 2026] [security2:error] [pid 24603:tid 24603] [client 34.73.38.109:50450] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||muslera.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "muslera.com"] [uri "/rclone.conf"] [unique_id "aqmhVHXsIP-mBAkAPMoGNgAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack