π§π¬
alnaasd
2026-08-10 13:27:07
(1 week ago)
WAF block action triggered by rule set "Version Control - Information Disclosure" (48 occurrences ob ...
show more
WAF block action triggered by rule set "Version Control - Information Disclosure" (48 occurrences observed).
show less
Web App Attack
π«π·
GEDAL
2026-08-10 05:21:37
(1 week ago)
Fail2ban webexploits @ <hostname> : 34.91.41.218 - - [04/Aug/2026:22:12:49 +0200] "GET /.git/config ...
show more
Fail2ban webexploits @ <hostname> : 34.91.41.218 - - [04/Aug/2026:22:12:49 +0200] "GET /.git/config HTTP/2.0" 301 162 "-" "anthropic-ai"
show less
Brute-Force
SSH
πΊπΈ
lavnet.net
2026-08-08 10:46:49
(1 week ago)
34.91.41.218 - - [08/Aug/2026:10:46:49 +0000] "GET /wp-json HTTP/2.0" 404 1901 "-" "Mozilla/5.0 Appl ...
show more
34.91.41.218 - - [08/Aug/2026:10:46:49 +0000] "GET /wp-json HTTP/2.0" 404 1901 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; GPTBot/1.3; +https://openai.com/gptbot)"
34.91.41.218 - - [08/Aug/2026:10:46:49 +0000] "GET /.github/workflows/deploy.yml HTTP/2.0" 404 1855 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; GPTBot/1.3; +https://openai.com/gptbot)"
34.91.41.218 - - [08/Aug/2026:10:46:49 +0000] "GET /.gitlab-ci.yml HTTP/2.0" 404 1855 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; GPTBot/1.3; +https://openai.com/gptbot)"
34.91.41.218 - - [08/Aug/2026:10:46:49 +0000] "GET /.gitconfig HTTP/2.0" 404 1855 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; GPTBot/1.3; +https://openai.com/gptbot)"
34.91.41.218 - - [08/Aug/2026:10:46:49 +0000] "GET /z9x8c7v6b5-debug-trigger-a0a0.org HTTP/2.0" 404 1855 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; GPTBot/1.3; +https://openai.com/gptbot)"
34.
...
show less
Brute-Force
π©πͺ
Blexyel
2026-08-08 10:41:10
(1 week ago)
34.91.41.218 - - [08/Aug/2026:12:41:09 +0200] "GET /.git/config HTTP/1.1" 200 265 "-" "Mozilla/5.0 ( ...
show more
34.91.41.218 - - [08/Aug/2026:12:41:09 +0200] "GET /.git/config HTTP/1.1" 200 265 "-" "Mozilla/5.0 (compatible; cohere-ai/1.0; +https://cohere.com)" "pingusmc.org"
...
show less
Brute-Force
Web App Attack
π³π±
melroy89
2026-08-08 10:27:57
(1 week ago)
34.91.41.218 - - [08/Aug/2026:12:27:47 +0200] "GET / HTTP/1.1" 403 9 "-" "Mozilla/5.0 (Macintosh; I ...
show more
34.91.41.218 - - [08/Aug/2026:12:27:47 +0200] "GET / HTTP/1.1" 403 9 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Safari/537.36" "ci.melroy.org" 0.000
34.91.41.218 - - [08/Aug/2026:12:27:47 +0200] "GET /rclone.conf HTTP/1.1" 403 9 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; Claude-SearchBot/1.0; +mailto:[email protected] " "ci.melroy.org" 0.000
34.91.41.218 - - [08/Aug/2026:12:27:47 +0200] "GET /z9x8c7v6b5-debug-trigger-ci.melroy.org HTTP/1.1" 403 9 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; Claude-SearchBot/1.0; +mailto:[email protected] " "ci.melroy.org" 0.000
34.91.41.218 - - [08/Aug/2026:12:27:48 +0200] "POST /graphql HTTP/1.1" 403 9 "https://ci.melroy.org" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Safari/537.36" "ci.melroy.org" 0.000
34.91.41.218 - - [08/Aug/2026:12:27:48 +0200] "POST /api/graph
...
show less
Web App Attack
π©πͺ
Teufel100
2026-08-08 09:51:20
(1 week ago)
ModSecurity rejected a query
Brute-Force
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-08 09:44:37
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.91.41.218 (218.41.91.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.91.41.218 (218.41.91.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 08 05:44:31.125943 2026] [security2:error] [pid 3112164:tid 3112164] [client 34.91.41.218:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.wiszen.org"] [uri "/.env.staging"] [unique_id "anb6f2ErjnPypX-9acKscAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-07 21:10:24
(1 week ago)
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: NL, Attack patterns: Word ...
show more
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: NL, Attack patterns: WordPress scanning, Backup file probing, Cloud secrets probing
show less
Bad Web Bot
Web App Attack
πΊπΈ
EvilTurkey
2026-08-07 12:17:11
(1 week ago)
Web app attack against financial institution website.
Web App Attack
Hacking
πΊπΈ
pixiekat
2026-08-07 03:19:38
(1 week ago)
[Fri Aug 07 03:19:36.999749 2026] [authz_core:error] [pid 689176:tid 689178] [client 34.91.41.218:39 ...
show more
[Fri Aug 07 03:19:36.999749 2026] [authz_core:error] [pid 689176:tid 689178] [client 34.91.41.218:39872] AH01630: client denied by server configuration: /var/www/vhosts/chatbot-app/public/
[Fri Aug 07 03:19:37.101209 2026] [authz_core:error] [pid 689176:tid 689180] [client 34.91.41.218:39872] AH01630: client denied by server configuration: /var/www/vhosts/chatbot-app/public/manage
[Fri Aug 07 03:19:37.209549 2026] [authz_core:error] [pid 689176:tid 689179] [client 34.91.41.218:39872] AH01630: client denied by server configuration: /var/www/vhosts/chatbot-app/public/admin
[Fri Aug 07 03:19:37.315996 2026] [authz_core:error] [pid 689204:tid 689215] [client 34.91.41.218:39898] AH01630: client denied by server configuration: /var/www/vhosts/chatbot-app/public/z9x8c7v6b5-debug-trigger-chatbot.dcinetwork.org
[Fri Aug 07 03:19:37.316198 2026] [authz_core:error] [pid 689204:tid 689223] [client 34.91.41.218:39910] AH01630: client denied by server configuration: /var/www/vhosts/chatbot-app/publi
...
show less
Brute-Force
πΊπΈ
WellSpring
2026-08-07 02:34:58
(1 week ago)
good bot honeypot on covenanthosting.org/api/.env β WellSpr.ing/NetSentinel civic-AI security layer
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-08-07 02:13:07
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.91.41.218 (218.41.91.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.91.41.218 (218.41.91.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 06 22:13:03.761592 2026] [security2:error] [pid 1485891:tid 1485891] [client 34.91.41.218:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.empoweruamerica.org"] [uri "/admin/.env"] [unique_id "anU_L_QioZxIhpNg6qAKmQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
LoneRider
2026-08-07 02:09:31
(1 week ago)
[07/Aug/2026:04:09:31.024221 +0200] anU-W0cFtEPrQeQUBnFq9AAAAAI 34.91.41.218 50226 127.0.0.1 7081
[0 ...
show more
[07/Aug/2026:04:09:31.024221 +0200] anU-W0cFtEPrQeQUBnFq9AAAAAI 34.91.41.218 50226 127.0.0.1 7081
[07/Aug/2026:04:09:31.154806 +0200] anU-W8i2ZXBFtWcQOCAI5AAAAAA 34.91.41.218 50268 127.0.0.1 7081
[07/Aug/2026:04:09:31.168096 +0200] anU-Wwtqm4O9IyxHFVHhBQAAAAU 34.91.41.218 50330 127.0.0.1 7081
...
show less
Hacking
π©πͺ
macrob
2026-08-07 01:40:51
(1 week ago)
2026/08/07 01:40:50 [error] 3654678#3654678: *453483135 access forbidden by rule, client: 34.91.41.2 ...
show more
2026/08/07 01:40:50 [error] 3654678#3654678: *453483135 access forbidden by rule, client: 34.91.41.218, server: fn.binixo.es, request: "GET /.ssh/id_dsa HTTP/2.0", host: "cpanel.pitup.org"
2026/08/07 01:40:50 [error] 3654675#3654675: *453483142 access forbidden by rule, client: 34.91.41.218, server: fn.binixo.es, request: "GET /.ssh/authorized_keys HTTP/2.0", host: "cpanel.pitup.org"
2026/08/07 01:40:50 [error] 3654674#3654674: *453483146 access forbidden by rule, client: 34.91.41.218, server: fn.binixo.es, request: "GET /.ssh/config HTTP/2.0", host: "cpanel.pitup.org"
...
show less
Web App Attack
π©πͺ
Tha_14
2026-08-07 01:29:43
(1 week ago)
Multiple erroneous requests
Web App Attack