๐ซ๐ท
SpaceHost-Server
2026-10-09 22:23:19
(8 hours ago)
Brute-Force
Web App Attack
๐ฌ๐ง
Marten Mark
2026-10-09 06:30:33
(1 day ago)
34.90.193.237 - - [09/Oct/2026:06:30:20 +0000] "GET /.vite/manifest.json HTTP/2.0" 404 1460 "-" "Moz ...
show more
34.90.193.237 - - [09/Oct/2026:06:30:20 +0000] "GET /.vite/manifest.json HTTP/2.0" 404 1460 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Mobile Safari/537.36"
34.90.193.237 - - [09/Oct/2026:06:30:20 +0000] "POST /lib/terminal-xhr.php HTTP/2.0" 404 1448 "-" "Mozilla/5.0 (compatible; PanguBot/1.0; +https://www.huaweicloud.com/)"
34.90.193.237 - - [09/Oct/2026:06:30:20 +0000] "POST /lib/terminal-xhr.php HTTP/2.0" 404 1448 "-" "Mozilla/5.0 (compatible; PanguBot/1.0; +https://www.huaweicloud.com/)"
34.90.193.237 - - [09/Oct/2026:06:30:20 +0000] "GET /build/manifest.json HTTP/2.0" 404 1460 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Mobile Safari/537.36"
34.90.193.237 - - [09/Oct/2026:06:30:20 +0000] "GET /build/manifest.json HTTP/2.0" 404 1460 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Mobile Safari/537.36"
34.90.193.237 - - [09/Oct/2026
...
show less
Port Scan
Web App Attack
๐บ๐ธ
gamabe
2026-10-09 01:38:55
(1 day ago)
Detected crowdsecurity/http-sensitive-files attack pattern. Reported by CrowdSec IDS.
Hacking
๐บ๐ธ
gamabe
2026-10-08 22:32:31
(1 day ago)
Detected crowdsecurity/http-dos-swithcing-ua attack pattern. Reported by CrowdSec IDS.
Hacking
๐บ๐ธ
snappic
2026-10-08 22:30:12
(1 day ago)
Scanning for config [GET /config.json.js] [Mozilla/5.0 (compatible; PanguBot/1.0; +https://www.huawe ...
show more
Scanning for config [GET /config.json.js] [Mozilla/5.0 (compatible; PanguBot/1.0; +https://www.huaweicloud.com/)]
show less
Bad Web Bot
Web App Attack
๐ซ๐ท
SpaceHost-Server
2026-10-08 22:22:01
(1 day ago)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 21:12:31
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.90.193.237 (237.193.90.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.90.193.237 (237.193.90.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 17:12:25.523531 2026] [security2:error] [pid 30774:tid 30774] [client 34.90.193.237:38964] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jussetcotradinglimited.co"] [uri "/.htpasswd"] [unique_id "asgHORNJj-mpc_Mt-B2QYQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 20:35:22
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.90.193.237 (237.193.90.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.90.193.237 (237.193.90.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 16:35:19.108140 2026] [security2:error] [pid 8420:tid 8420] [client 34.90.193.237:34266] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "healthpointphysicians.co"] [uri "/.htpasswd"] [unique_id "asf-h69H8ZdnXbe3noHbFQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 19:35:59
(1 day ago)
(mod_security) mod_security (id:218420) triggered by 34.90.193.237 (237.193.90.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:218420) triggered by 34.90.193.237 (237.193.90.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 15:35:54.245259 2026] [security2:error] [pid 24927:tid 24927] [client 34.90.193.237:35752] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i)php://(std(in|out|err)|(in|out)put|fd|memory|temp|filter)" at ARGS_NAMES:\\xadd allow_url_include=1 \\xadd auto_prepend_file=php://input. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/21_PHP_PHPGen.conf"] [line "22"] [id "218420"] [rev "2"] [msg "COMODO WAF: PHP Injection Attack: I/O Stream Found||epetsure.co|F|2"] [data "Matched Data: php://input found within ARGS_NAMES:\\x5cxadd allow_url_include=1 \\x5cxadd auto_prepend_file=php://input: \\xadd allow_url_include=1 \\xadd auto_prepend_file=php://input"] [severity "CRITICAL"] [tag "CWAF"] [tag "PHPGen"] [hostname "epetsure.co"] [uri "/index.php"] [unique_id "asfwmtoNIc7cSxrhiBiB2QAAACw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Savvii
2026-10-08 19:07:36
(1 day ago)
20 attempts against mh-misbehave-ban on redirect
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 19:04:36
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.90.193.237 (237.193.90.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.90.193.237 (237.193.90.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 15:04:32.577796 2026] [security2:error] [pid 16566:tid 16566] [client 34.90.193.237:42134] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cuul.co"] [uri "/.htpasswd"] [unique_id "asfpQJmVGsw3g5KXMB0oTgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
IndigoRidge
2026-10-08 18:43:57
(1 day ago)
34.90.193.237 - - [08/Oct/2026:14:43:55 -0400] "GET /@fs/app/.env?raw?? HTTP/1.1" 404 81559 "-" "Duc ...
show more
34.90.193.237 - - [08/Oct/2026:14:43:55 -0400] "GET /@fs/app/.env?raw?? HTTP/1.1" 404 81559 "-" "DuckAssistBot/1.1 (https://duckduckgo.com/duckassistbot)"
34.90.193.237 - - [08/Oct/2026:14:43:55 -0400] "GET /@fs/src/.env?raw?? HTTP/1.1" 404 81559 "-" "Mozilla/5.0 (compatible; KimiBot/1.0; +https://kimi.ai/)"
34.90.193.237 - - [08/Oct/2026:14:43:55 -0400] "GET /@fs/../.env?raw?? HTTP/1.1" 404 81557 "-" "Mozilla/5.0 (compatible; Bytespider; [email protected] ) AppleWebKit/537.36"
...
show less
Web App Attack
๐ฌ๐ง
Marten Mark
2026-10-08 18:37:13
(1 day ago)
34.90.193.237 - - [08/Oct/2026:18:37:07 +0000] "POST /lib/terminal-xhr.php HTTP/2.0" 404 110 "-" "Mo ...
show more
34.90.193.237 - - [08/Oct/2026:18:37:07 +0000] "POST /lib/terminal-xhr.php HTTP/2.0" 404 110 "-" "Mozilla/5.0 (compatible; YiBot/1.0; +https://01.ai/)"
34.90.193.237 - - [08/Oct/2026:18:37:07 +0000] "POST /icecoder/lib/terminal-xhr.php HTTP/2.0" 404 110 "-" "Mozilla/5.0 (compatible; Qwenbot/1.0; +https://qwen.alibaba.com/)"
34.90.193.237 - - [08/Oct/2026:18:37:08 +0000] "GET /flazb4qvza09l06fopkb HTTP/2.0" 404 23131 "-" "Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; +https://kimi.ai/)"
34.90.193.237 - - [08/Oct/2026:18:37:08 +0000] "GET /dist/.vite/manifest.json HTTP/2.0" 404 23131 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Mobile Safari/537.36"
34.90.193.237 - - [08/Oct/2026:18:37:08 +0000] "GET /z9x8c7v6b5-debug-trigger-cfi.co HTTP/2.0" 404 23131 "-" "Mozilla/5.0 (compatible; KimiBot/1.0; +https://kimi.ai/)"
34.90.193.237 - - [08/Oct/2026:18:37:09 +0000] "GET /.vite/manifest.json HTTP/2.0" 404 23131 "-" "Mozilla/5.0 (Linux; Android
...
show less
Port Scan
Web App Attack
๐ฒ๐พ
Rizzy
2026-10-08 18:36:01
(1 day ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐ฌ๐ง
consul.to
2026-10-08 18:29:19
(1 day ago)
Web attack/malicious scanning detected
Web App Attack