🇮🇳
evicky2002
2026-09-08 00:01:54
(1 day ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
🇺🇸
Charlesiv
2026-09-07 06:02:11
(1 day ago)
Triggered Cloudflare WAF (firewallCustom) from BE.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Prot ...
show more
Triggered Cloudflare WAF (firewallCustom) from BE.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Protocol: HTTP/2 (GET method)
Endpoint: /config.json
Timestamp: 2026-09-07T02:36:33Z
Ray ID: a372539408bf2de7
UA: Mozilla/5.0 (compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot)
show less
Bad Web Bot
🇺🇸
cwytech
2026-09-07 02:18:52
(2 days ago)
Fleet-wide ban from the Ghostfleet 👻. Triggered by scenario: crowdsecurity/http-probing.
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 02:17:44
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.79.2.37 (37.2.79.34.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:210492) triggered by 34.79.2.37 (37.2.79.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 22:17:38.950070 2026] [security2:error] [pid 25452:tid 25452] [client 34.79.2.37:45980] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "budinger.org"] [uri "/files../.env"] [unique_id "ap4ewqG2Q03CTmVRGiNa-AAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
Aetherweb Ark
2026-09-07 00:57:08
(2 days ago)
(mod_security) mod_security (id:949110) triggered by 34.79.2.37 (BE/Belgium/37.2.79.34.bc.googleuser ...
show more
(mod_security) mod_security (id:949110) triggered by 34.79.2.37 (BE/Belgium/37.2.79.34.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
🇩🇪
auridh
2026-09-07 00:17:20
(2 days ago)
WAF block: crowdsecurity/vpatch-CVE-2025-29927 from 34.79.2.37 ([REDACTED])
Web App Attack
🇳🇱
Savvii
2026-09-06 23:45:55
(2 days ago)
20 attempts against mh-misbehave-ban on ethyl
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
WPJoe
2026-09-06 23:10:41
(2 days ago)
34.79.2.37 - - [06/Sep/2026:23:10:40 +0000] "GET /.aws/credentials HTTP/1.1" 403 4348 "-" "DuckAssis ...
show more
34.79.2.37 - - [06/Sep/2026:23:10:40 +0000] "GET /.aws/credentials HTTP/1.1" 403 4348 "-" "DuckAssistBot/1.1 (https://duckduckgo.com/duckassistbot)"
34.79.2.37 - - [06/Sep/2026:23:10:40 +0000] "GET /.aws/config HTTP/1.1" 403 4347 "-" "Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; +https://kimi.ai/)"
...
show less
Web App Attack
Bad Web Bot
🇺🇸
Charlesiv
2026-09-06 22:25:06
(2 days ago)
Triggered Cloudflare WAF (firewallCustom) from BE.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Prot ...
show more
Triggered Cloudflare WAF (firewallCustom) from BE.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Protocol: HTTP/2 (GET method)
Endpoint: /staging/.env
Timestamp: 2026-09-06T14:48:38Z
Ray ID: a36e469649042a2f
UA: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot)
show less
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-06 20:22:45
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 34.79.2.37 (37.2.79.34.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:210730) triggered by 34.79.2.37 (37.2.79.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 16:22:36.973558 2026] [security2:error] [pid 25724:tid 25724] [client 34.79.2.37:35820] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||brianknudsen.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "brianknudsen.com"] [uri "/z9x8c7v6b5-debug-trigger-brianknudsen.com"] [unique_id "ap3LjJCQo8hXiX3WxdqBSQAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 18:21:50
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.79.2.37 (37.2.79.34.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:210492) triggered by 34.79.2.37 (37.2.79.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 14:21:45.674264 2026] [security2:error] [pid 29838:tid 29838] [client 34.79.2.37:57382] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "compliancedepts.com"] [uri "/.env.local"] [unique_id "ap2vOSLEZuSUDWFM-AYIrwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
sthoyer.de
2026-09-06 17:17:46
(2 days ago)
34.79.2.37 - - [06/Sep/2026:19:17:45 +0200] "GET /z9x8c7v6b5-debug-trigger-sthoyer.de HTTP/2" 302 49 ...
show more
34.79.2.37 - - [06/Sep/2026:19:17:45 +0200] "GET /z9x8c7v6b5-debug-trigger-sthoyer.de HTTP/2" 302 495 "-" "Mozilla/5.0 (compatible; ChatGLM-Spider/1.0; +https://zhipuai.cn/)"
34.79.2.37 - - [06/Sep/2026:19:17:45 +0200] "GET /.//.env HTTP/2" 302 495 "-" "Mozilla/5.0 (compatible; Qwenbot/1.0; +https://qwen.alibaba.com/)"
34.79.2.37 - - [06/Sep/2026:19:17:45 +0200] "GET /%2eenv HTTP/2" 302 495 "-" "Mozilla/5.0 (compatible; YiBot/1.0; +https://01.ai/)"
...
show less
Web App Attack
🇺🇦
Olexiy Backend
2026-09-06 16:03:20
(2 days ago)
34.79.2.37
...
Bad Web Bot
Web App Attack
🇳🇱
Site.eu
2026-09-06 15:35:46
(2 days ago)
Excessive multi-domain requests
Brute-Force
Anonymous
2026-09-06 15:10:19
(2 days ago)
XSS Attempt
Hacking