🇩🇪
Marc
2026-09-14 17:25:11
(20 hours ago)
34.81.143.47 - - [14/Sep/2026:19:25:11 +0200] "GET /login HTTP/2.0" 404 291 "-" "Mozilla/5.0 (Macint ...
show more
34.81.143.47 - - [14/Sep/2026:19:25:11 +0200] "GET /login HTTP/2.0" 404 291 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36 Edg/152.0.0.0" 34.81.143.47 - - [14/Sep/2026:19:25:11 +0200] "GET /wp-json HTTP/2.0" 404 269 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ChatGPT-User/1.0; +https://openai.com/bot)" 34.81.143.47 - - [14/Sep/2026:19:25:11 +0200] "GET /secure HTTP/2.0" 404 269 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36 Edg/152.0.0.0"
show less
Brute-Force
Anonymous
2026-09-14 13:26:03
(1 day ago)
Sep 12 23:46:17 localhost kernel: [117616290.324253] iptables_INPUT_denied: IN=eth0 OUT= MAC=f2:3c:9 ...
show more
Sep 12 23:46:17 localhost kernel: [117616290.324253] iptables_INPUT_denied: IN=eth0 OUT= MAC=f2:3c:91:84:83:95:00:00:0c:9f:f0:1e:08:00 SRC=34.81.143.47 DST=[mungedIP2] LEN=60 TOS=0x00 PREC=0x40 TTL=54 ID=4461 DF PROTO=TCP SPT=44728 DPT=8443 WINDOW=65320 RES=0x00 SYN URGP=0
Sep 12 23:46:17 localhost kernel: [117616290.324289] iptables_INPUT_denied: IN=eth0 OUT= MAC=f2:3c:91:84:83:95:00:00:0c:9f:f0:1e:08:00 SRC=34.81.143.47 DST=[mungedIP2] LEN=60 TOS=0x00 PREC=0x40 TTL=54 ID=4461 DF PROTO=TCP SPT=44728 DPT=8443 SEQ=2039776358 ACK=0 WINDOW=65320 RES=0x00 SYN URGP=0 OPT (0204058C0402080AC1FFFBED000000000103030A)
Sep 14 09:26:02 localhost kernel: [117737472.941055] iptables_INPUT_denied: IN=eth0 OUT= MAC=f2:3c:91:84:83:95:00:00:0c:9f:f0:1e:08:00 SRC=34.81.143.47 DST=[mungedIP2] LEN=60 TOS=0x00 PREC=0x40 TTL=55 ID=6379 DF PROTO=TCP SPT=41896 DPT=8443 WINDOW=65320 RES=0x00 SYN URGP=0
Sep 14 09:26:02 localhost kernel: [117737472.941078] iptables_INPUT_denied: IN=eth0 OUT= MAC=f2:3c:91:84:83:95:00:00:0c:9f:f0:1e:08
show less
Port Scan
🇧🇪
taivas.nl
2026-09-14 04:32:56
(1 day ago)
Many_bad_calls
Web App Attack
🇲🇽
octageeks.com
2026-09-14 04:12:47
(1 day ago)
Wordpress malicious attack:[octablocked]
Web App Attack
Anonymous
2026-09-13 23:11:32
(1 day ago)
[Sun Sep 13 18:07:24.463024 2026] [authz_core:error] [pid 25815] [client 34.81.143.47:35396] AH01630 ...
show more
[Sun Sep 13 18:07:24.463024 2026] [authz_core:error] [pid 25815] [client 34.81.143.47:35396] AH01630: client denied by server configuration: /var/www/api/.htpasswd
[Sun Sep 13 18:07:25.217894 2026] [authz_core:error] [pid 27013] [client 34.81.143.47:35380] AH01630: client denied by server configuration: /var/www/api/server-status
[Sun Sep 13 18:38:27.536573 2026] [authz_core:error] [pid 32138] [client 34.81.143.47:53502] AH01630: client denied by server configuration: /var/www/api/.htpasswd
[Sun Sep 13 18:38:32.147780 2026] [authz_core:error] [pid 32315] [client 34.81.143.47:53490] AH01630: client denied by server configuration: /var/www/api/server-status
[Sun Sep 13 19:11:27.267396 2026] [authz_core:error] [pid 4343] [client 34.81.143.47:44654] AH01630: client denied by server configuration: /var/www/api/server-status
[Sun Sep 13 19:11:32.019748 2026] [authz_core:error] [pid 4334] [client 34.81.143.47:47156] AH01630: client denied by server configuration: /var/www/api/.htpasswd
show less
Bad Web Bot
Web App Attack
🇮🇩
Burayot
2026-09-13 19:42:38
(1 day ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 34.81.143.47 (TW/Taiwan/47.143.81.3 ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 34.81.143.47 (TW/Taiwan/47.143.81.34.bc.googleusercontent.com): 1 in the last 3600 secs
show less
Web App Attack
🇩🇪
paissangroup
2026-09-13 18:41:24
(1 day ago)
Multiple WAF Violations
Web App Attack
🇵🇱
Niko's Stuff
2026-09-13 18:25:28
(1 day ago)
Triggered crowdsecurity/http-probing. More information at: https://app.crowdsec.net/cti/34.81.143.47
Web App Attack
Hacking
🇺🇸
WizardsToolkit
2026-09-13 17:50:47
(1 day ago)
tried to access forbidden files; attempted to access /@fs/app/.env?import&raw??
Web App Attack
🇺🇸
kosada.com
2026-09-13 17:23:27
(1 day ago)
Repeated exploit attempts, for example: /.env.local /.env (HTTP/2.0 port 443, user agent: "Mozilla/5 ...
show more
Repeated exploit attempts, for example: /.env.local /.env (HTTP/2.0 port 443, user agent: "Mozilla/5.0 (compatible; MoonshotBot/1.0; +https://kimi.ai/)")
show less
Web App Attack
🇵🇫
www.gregorymariani.com
2026-09-13 15:48:06
(1 day ago)
Web App Attack
🇫🇷
ecode hosting
2026-09-13 15:08:04
(1 day ago)
Domain : ermedmedical.com
Rule : config
2026-09-13 15:06:59 10.100.1.20 GET /.git/HEAD - 443 - 34.81 ...
show more
Domain : ermedmedical.com
Rule : config
2026-09-13 15:06:59 10.100.1.20 GET /.git/HEAD - 443 - 34.81.143.47 HTTP/2 Mozilla/5.0 (compatible; YiBot/1.0; https://01.ai/) - ermedmedical.com 404 8 0 103 432 270 - -
show less
Hacking
SQL Injection
🇺🇸
TPI-Abuse
2026-09-13 14:34:34
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.81.143.47 (47.143.81.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.81.143.47 (47.143.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 10:34:28.253211 2026] [security2:error] [pid 24088:tid 24088] [client 34.81.143.47:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "demondomain.com"] [uri "/__vite_rsc_findSourceMapURL"] [unique_id "aqa0dLraPyLbADFgFIfP1gAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
demomodule
2026-09-13 14:34:13
(1 day ago)
PrestaShop Security Module: suspicious probe path detected (/.git)
Web App Attack
🇳🇱
BlueWire Hosting
2026-09-13 14:17:54
(1 day ago)
Aggressive scanning resulting into 404
Bad Web Bot