Anonymous
2026-09-12 12:40:28
(33 minutes ago)
Web App Attack
Brute-Force
Exploited Host
Web App Attack
🇩🇪
maxpower
2026-09-12 12:21:59
(52 minutes ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 104.198.234.231 (US/United States/231.23 ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 104.198.234.231 (US/United States/231.234.198.104.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 104.198.234.231 - - [12/Sep/2026:14:21:56 +0200] "GET /config/env/aws_credentials.env HTTP/2.0" 200 4823 "-" "Mozilla/5.0 (compatible; MoonshotBot/1.0; +https://kimi.ai/)" "104.198.234.231" host=ctpescara.it
show less
Port Scan
🇺🇸
interbiznw.com
2026-09-12 12:19:02
(55 minutes ago)
malicious-web-requests-vulnerability-scanning
Hacking
Brute-Force
Exploited Host
Web App Attack
Anonymous
2026-09-12 11:59:14
(1 hour ago)
104.198.234.231 - - [12/Sep/2026:13:59:04 +0200] "GET /build/manifest.json HTTP/1.1" 404 30086
104.1 ...
show more
104.198.234.231 - - [12/Sep/2026:13:59:04 +0200] "GET /build/manifest.json HTTP/1.1" 404 30086
104.198.234.231 - - [12/Sep/2026:13:59:05 +0200] "GET /dist/.vite/manifest.json HTTP/1.1" 404 30086
104.198.234.231 - - [12/Sep/2026:13:59:05 +0200] "GET /dist/manifest.json HTTP/1.1" 404 30086
104.198.234.231 - - [12/Sep/2026:13:59:06 +0200] "GET /__vite_rsc_findSourceMapURL?filename=file:///proc/self/environ&environmentName=rsc HTTP/1.1" 404 29450
104.198.234.231 - - [12/Sep/2026:13:59:06 +0200] "GET /__vite_rsc_findSourceMapURL?filename=file:///root/.aws/credentials&environmentName=rsc HTTP/1.1" 404 29450
104.198.234.231 - - [12/Sep/2026:13:59:05 +0200] "POST /graphql HTTP/1.1" 404 29450
104.198.234.231 - - [12/Sep/2026:13:59:07 +0200] "GET /@fs/var/run/secrets/kubernetes.io/serviceaccount/ca.crt?raw?? HTTP/1.1" 404 29450
104.198.234.231 - - [12/Sep/2026:13:59:06 +0200] "GET /__vite_rsc_findSourceMapURL?filename=file:///app/.env&environmentName=rsc HTTP/1.1" 404 29450
104.198.234.231 - - [
...
show less
Web Spam
Web App Attack
🇳🇱
e.fierstra
2026-09-12 11:34:48
(1 hour ago)
excessive HTTP 404 errors
Bad Web Bot
🇧🇪
taivas.nl
2026-09-12 11:32:09
(1 hour ago)
Bad_requests
Bad Web Bot
🇩🇪
burlacu.org
2026-09-12 11:09:03
(2 hours ago)
Nginx multi-log analysis detected: attack_pattern. Evidence: Attack pattern with code injection atte ...
show more
Nginx multi-log analysis detected: attack_pattern. Evidence: Attack pattern with code injection attempt. Blocked automatically.
show less
Hacking
Web App Attack
🇬🇧
consul.to
2026-09-12 10:13:16
(3 hours ago)
Web attack/malicious scanning detected
Web App Attack
🇳🇱
Alboweb B.V.
2026-09-12 10:11:02
(3 hours ago)
Bad web bot activity detected by Fail2Ban in plesk-apache-badbot jail
Bad Web Bot
🇫🇷
COMAITE
2026-09-12 10:06:24
(3 hours ago)
Suspicious URL access.
Web App Attack
🇺🇸
countdownmail.com
2026-09-12 10:03:02
(3 hours ago)
Extensive web application scanning for vulnerabilities. High volume automated attack.
Bad Web Bot
Web App Attack
🇪🇸
pipeline.es
2026-09-12 09:52:18
(3 hours ago)
Web scanning / probing for vulnerable paths | URL: /.env.development?raw | Evidence: 104.198.234.231 ...
show more
Web scanning / probing for vulnerable paths | URL: /.env.development?raw | Evidence: 104.198.234.231 - - [12/Sep/2026:11:51:25 +0200] \"GET /.env.development?raw HTTP/1.1\" 404 120516 \"-\" \"Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; OAI-SearchBot/1.0; +https://openai.com/searchbot)\" GEOIP_COUNTRY_CODE=US | ASN: GOOGLE-CLOUD-PLATFORM | Country: US
show less
Port Scan
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 09:38:57
(3 hours ago)
(mod_security) mod_security (id:210730) triggered by 104.198.234.231 (231.234.198.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210730) triggered by 104.198.234.231 (231.234.198.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 05:38:52.428712 2026] [security2:error] [pid 12268:tid 12268] [client 104.198.234.231:52664] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||cortona.ws|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "cortona.ws"] [uri "/rclone.conf"] [unique_id "aqUdrOXyt2X1ojLgT3orawAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
paissangroup
2026-09-12 09:31:31
(3 hours ago)
Multiple WAF Violations
Web App Attack
Anonymous
2026-09-12 09:30:01
(3 hours ago)
suspicious request in access.log
Web App Attack