๐ฆ๐บ
Klaverstyn
2026-10-05 23:41:24
(9 hours ago)
Persistent attacker, repeat offender
Hacking
๐บ๐ธ
snappic
2026-10-05 13:30:09
(19 hours ago)
Scanning for config [GET /config.json.js] [Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.bai ...
show more
Scanning for config [GET /config.json.js] [Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)]
show less
Bad Web Bot
Web App Attack
๐ธ๐ฌ
simpeg-adm.bandung.go.id
2026-10-05 13:24:48
(19 hours ago)
05/Oct/2026:13:24:47 +0000;34.75.37.47;"/lib/terminal-xhr.php"
05/Oct/2026:13:24:48 +0000;34.75.37.4 ...
show more
05/Oct/2026:13:24:47 +0000;34.75.37.47;"/lib/terminal-xhr.php"
05/Oct/2026:13:24:48 +0000;34.75.37.47;"/dist/.vite/manifest.json"
05/Oct/2026:13:24:48 +0000;34.75.37.47;"/.vite/manifest.json"
05/Oct/2026:13:24:48 +0000;34.75.37.47;"/6tgl6hna2x9zjjwrc5ad"
05/Oct/2026:13:24:48 +0000;34.75.37.47;"/dist/manifest.json"
05/Oct/2026:13:24:48 +0000;34.75.37.47;"/z9x8c7v6b5-debug-trigger-app.lukemunrophotography.com.au"
05/Oct/2026:13:24:48 +0000;34.75.37.47;"/q1jynssg8cvs02fzf3pd"
...
show less
Web Spam
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 05:06:59
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.75.37.47 (47.37.75.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.75.37.47 (47.37.75.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 01:06:52.660597 2026] [security2:error] [pid 28572:tid 28572] [client 34.75.37.47:40982] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rohanbyles.com.au"] [uri "/files../.env"] [unique_id "asMwbAWL5oWLbGTrDYDtuwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
Proxay Fox
2026-10-05 03:56:56
(1 day ago)
34.75.37.47 - - [05/Oct/2026:13:56:54 +1000] "GET /..%2f..%2f.env HTTP/1.1" 400 150 "-" "-" "-" 30 2 ...
show more
34.75.37.47 - - [05/Oct/2026:13:56:54 +1000] "GET /..%2f..%2f.env HTTP/1.1" 400 150 "-" "-" "-" 30 295 TLSv1.3/TLS_AES_256_GCM_SHA384 . e2904f1d001e2141cdbbe0a4064b99cc54de8e4476f1bc2ce31b784ff21afcc3
34.75.37.47 - - [05/Oct/2026:13:56:54 +1000] "GET /icons/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/proc/self/environ HTTP/1.1" 400 150 "-" "-" "-" 69 295 TLSv1.3/TLS_AES_256_GCM_SHA384 . 51627aa3e152451dff45d46660230bf17ebfafd2d87209115fc81c9e961c7288
34.75.37.47 - - [05/Oct/2026:13:56:54 +1000] "GET /api/uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2fproc/self/environ HTTP/1.1" 400 150 "-" "-" "-" 90 295 TLSv1.3/TLS_AES_256_GCM_SHA384 . 686502b2ce38fd4cae0dabbc2d109ddfd6af96fab9d47e9a58478e26242228cd
34.75.37.47 - - [05/Oct/2026:13:56:54 +1000] "GET /api/uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f.env HTTP/1.1" 400 150 "-" "-" "-" 68 295 TLSv1.3/TLS_AES_256_GCM_SHA384 . ac1febc2bcf6390130a0a4ecb92c20cf484f1f35c7bc6a06d3eba1b864b770c8
34.75.37.47 - - [05/Oct/2026:13:56:54 +1000] "GET /uplo
...
show less
Brute-Force
Web App Attack
๐ฌ๐ง
consul.to
2026-10-05 03:56:15
(1 day ago)
Web attack/malicious scanning detected
Web App Attack
๐ฆ๐บ
2000cn.com.au
2026-10-05 03:48:30
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
Anonymous
2026-10-05 02:25:48
(1 day ago)
34.75.37.47 - - [05/Oct/2026:02:25:47 +0000] "GET /@fs/app/.env?raw?? HTTP/2.0" 302 332 "-" "Mozilla ...
show more
34.75.37.47 - - [05/Oct/2026:02:25:47 +0000] "GET /@fs/app/.env?raw?? HTTP/2.0" 302 332 "-" "Mozilla/5.0 (compatible; KimiBot/1.0; +https://kimi.ai/)"
...
show less
Bad Web Bot
Web App Attack
๐ฆ๐บ
Asimar
2026-10-05 00:01:20
(1 day ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted]): (CF_ENABLE)
Bad Web Bot
๐ฆ๐บ
Klaverstyn
2026-10-04 23:40:46
(1 day ago)
Excessive HTTP request rate
Web App Attack
๐ซ๐ท
โจ
2026-10-04 23:27:21
(1 day ago)
Domain : ica.net.au
Rule : UserAgent
2026-10-04 23:21:24 203.29.11.170 GET /runtime-config.js - 443 ...
show more
Domain : ica.net.au
Rule : UserAgent
2026-10-04 23:21:24 203.29.11.170 GET /runtime-config.js - 443 - 34.75.37.47 HTTP/2 Mozilla/5.0 (compatible; Bytespider; [email protected] ) AppleWebKit/537.36 - ica.net.au 404 0 2 1098 414 218 - -
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-10-04 23:01:48
(1 day ago)
(mod_security) mod_security (id:210580) triggered by 34.75.37.47 (47.37.75.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210580) triggered by 34.75.37.47 (47.37.75.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 19:01:40.801413 2026] [security2:error] [pid 6639:tid 6639] [client 34.75.37.47:52838] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "proc/self/environ" at ARGS:file. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/08_Global_Other.conf"] [line "57"] [id "210580"] [rev "2"] [msg "COMODO WAF: OS File Access Attempt||gundiahgazette.com.au|F|2"] [data "Matched Data: proc/self/environ found within ARGS:file: /proc/self/environ"] [severity "CRITICAL"] [tag "CWAF"] [tag "Other"] [hostname "gundiahgazette.com.au"] [uri "/api/system/fileView"] [unique_id "asLa1HbJoAB9Hm39wIRYfQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
ghel
2026-10-04 22:52:42
(1 day ago)
34.75.37.47 - - [05/Oct/2026:06:52:38 +0800] "GET /dist/manifest.json HTTP/1.1" 404 127475 "-" "Mozi ...
show more
34.75.37.47 - - [05/Oct/2026:06:52:38 +0800] "GET /dist/manifest.json HTTP/1.1" 404 127475 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36 Edg/153.0.0.0"
34.75.37.47 - - [05/Oct/2026:06:52:39 +0800] "GET /9ussnfc1r8w80r4yvysb HTTP/1.1" 404 82790 "-" "Mozilla/5.0 (compatible; Google-Extended; +http://www.google.com/bot.html)"
34.75.37.47 - - [05/Oct/2026:06:52:39 +0800] "GET /bxnmauwmmfx6x6w8g7px HTTP/1.1" 404 91238 "-" "Mozilla/5.0 (compatible; Google-Extended; +http://www.google.com/bot.html)"
34.75.37.47 - - [05/Oct/2026:06:52:39 +0800] "GET /assets/manifest.json HTTP/1.1" 404 131418 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36 Edg/153.0.0.0"
34.75.37.47 - - [05/Oct/2026:06:52:41 +0800] "GET /.htpasswd HTTP/1.1" 403 406 "-" "Mozilla/5.0 (compatible; PanguBot/1.0; +https://www.huaweicloud.com/)"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-04 21:44:52
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.75.37.47 (47.37.75.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.75.37.47 (47.37.75.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 17:44:47.533884 2026] [security2:error] [pid 24077:tid 24077] [client 34.75.37.47:55816] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "comsew.com.au"] [uri "/js../.env"] [unique_id "asLIz5X0iwIF1Dfh29l_TwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-04 21:36:25
(1 day ago)
Fail2ban jail=webexploits banned IP=34.75.37.47 after 1 hits. Reason=web probing.
Brute-Force
Web App Attack