๐ฌ๐ง
Marten Mark
2026-10-09 06:36:29
(1 day ago)
34.9.120.75 - - [09/Oct/2026:06:36:29 +0000] "GET /.env.js HTTP/2.0" 404 1450 "-" "Mozilla/5.0 Apple ...
show more
34.9.120.75 - - [09/Oct/2026:06:36:29 +0000] "GET /.env.js HTTP/2.0" 404 1450 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; [email protected] )"
...
show less
Web App Attack
Bad Web Bot
๐บ๐ธ
gamabe
2026-10-09 01:50:53
(1 day ago)
Detected crowdsecurity/http-path-traversal-probing attack pattern. Reported by CrowdSec IDS.
Port Scan
๐บ๐ธ
gamabe
2026-10-09 01:05:56
(1 day ago)
Detected crowdsecurity/http-sensitive-files attack pattern. Reported by CrowdSec IDS.
Hacking
๐บ๐ธ
gamabe
2026-10-08 23:59:44
(2 days ago)
Detected crowdsecurity/http-dos-swithcing-ua attack pattern. Reported by CrowdSec IDS.
Hacking
๐ท๐ด
iulianh
2026-10-08 23:39:15
(2 days ago)
80,443
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-10-08 22:12:43
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.9.120.75 (75.120.9.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.9.120.75 (75.120.9.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 18:12:38.304953 2026] [security2:error] [pid 8859:tid 8859] [client 34.9.120.75:55870] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mecme.co"] [uri "/js../.env"] [unique_id "asgVVlH4yQGlkN6sN9sNmwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-10-08 19:51:39
(2 days ago)
Excessive 404/403 errors
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-10-08 19:35:11
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.9.120.75 (75.120.9.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.9.120.75 (75.120.9.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 15:35:03.763651 2026] [security2:error] [pid 1888:tid 1888] [client 34.9.120.75:56372] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "h2ofall.co"] [uri "/.htpasswd"] [unique_id "asfwZwkgtPLBC81AyPv0RgAAADc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 19:17:16
(2 days ago)
(mod_security) mod_security (id:210580) triggered by 34.9.120.75 (75.120.9.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210580) triggered by 34.9.120.75 (75.120.9.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 15:17:10.882575 2026] [security2:error] [pid 20702:tid 20702] [client 34.9.120.75:60478] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "proc/self/environ" at ARGS:apis. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/08_Global_Other.conf"] [line "57"] [id "210580"] [rev "2"] [msg "COMODO WAF: OS File Access Attempt||globalhotels.com.co|F|2"] [data "Matched Data: proc/self/environ found within ARGS:apis: ../../../../../../proc/self/environ"] [severity "CRITICAL"] [tag "CWAF"] [tag "Other"] [hostname "globalhotels.com.co"] [uri "/api/console/api_server"] [unique_id "asfsNhG5Vyi6lfJns4uI9QAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
ELYAZ
2026-10-08 18:12:07
(2 days ago)
(y3) Failed access -byebye- from 34.9.120.75 (US/United States/75.120.9.34.bc.googleusercontent.com) ...
show more
(y3) Failed access -byebye- from 34.9.120.75 (US/United States/75.120.9.34.bc.googleusercontent.com): (CF_ENABLE)
show less
Hacking
๐ฌ๐ง
consul.to
2026-10-08 18:10:10
(2 days ago)
Web attack/malicious scanning detected
Web App Attack
๐ฌ๐ง
Marten Mark
2026-10-08 17:34:53
(2 days ago)
34.9.120.75 - - [08/Oct/2026:17:34:48 +0000] "POST /lib/terminal-xhr.php HTTP/2.0" 404 110 "-" "Mozi ...
show more
34.9.120.75 - - [08/Oct/2026:17:34:48 +0000] "POST /lib/terminal-xhr.php HTTP/2.0" 404 110 "-" "Mozilla/5.0 (compatible; Google-Extended; +http://www.google.com/bot.html)"
34.9.120.75 - - [08/Oct/2026:17:34:49 +0000] "POST /icecoder/lib/terminal-xhr.php HTTP/2.0" 404 110 "-" "Mozilla/5.0 (compatible; KimiBot/1.0; +https://kimi.ai/)"
34.9.120.75 - - [08/Oct/2026:17:34:49 +0000] "GET /z9x8c7v6b5-debug-trigger-cfi.co HTTP/2.0" 404 23131 "-" "Mozilla/5.0 (compatible; xAI-Grok/1.0; +https://x.ai/)"
34.9.120.75 - - [08/Oct/2026:17:34:49 +0000] "GET /.vite/manifest.json HTTP/2.0" 404 23131 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Mobile Safari/537.36"
34.9.120.75 - - [08/Oct/2026:17:34:49 +0000] "GET /myrk1awgj3yjkuwrgxhr HTTP/2.0" 404 23131 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
34.9.120.75 - - [08/Oct/2026:17:34:50 +0000] "GET /dist/.vite/manifest.json HTTP/2.0" 404 23131 "-" "Mozilla/5.0 (Linux;
...
show less
Port Scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 17:33:10
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.9.120.75 (75.120.9.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.9.120.75 (75.120.9.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 13:33:05.803417 2026] [security2:error] [pid 31413:tid 31413] [client 34.9.120.75:41732] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ccancun.co"] [uri "/backend/.env"] [unique_id "asfT0Tj0ndY_9oRgYxRSYgAAACg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Victor Lรณpez
2026-10-08 17:27:15
(2 days ago)
buscaempresas.co 34.9.120.75 - - [08/Oct/2026:12:27:14 -0500] "GET /userfiles?path=../../.env HTTP/2 ...
show more
buscaempresas.co 34.9.120.75 - - [08/Oct/2026:12:27:14 -0500] "GET /userfiles?path=../../.env HTTP/2.0" 403 6709 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexitybot)" MISS
buscaempresas.co 34.9.120.75 - - [08/Oct/2026:12:27:14 -0500] "GET /userfiles?path=../../../.env HTTP/2.0" 403 6709 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot" MISS
buscaempresas.co 34.9.120.75 - - [08/Oct/2026:12:27:14 -0500] "GET /userfiles?path=../../../../.env HTTP/2.0" 403 6709 "-" "Mozilla/5.0 (compatible; DeepSeekBot/1.0; +https://www.deepseek.com/)" MISS
...
show less
Hacking
Web App Attack
๐บ๐ธ
snappic
2026-10-08 17:23:14
(2 days ago)
Scanning for config [GET /config.json.js] [Mozilla/5.0 (compatible; MoonshotBot/1.0; +https://kimi.a ...
show more
Scanning for config [GET /config.json.js] [Mozilla/5.0 (compatible; MoonshotBot/1.0; +https://kimi.ai/)]
show less
Bad Web Bot
Web App Attack