🇿🇦
conure.sh
2026-09-12 12:09:02
(17 hours ago)
csagent: score 21.6: 404 noise floor x8, secrets grab x2; 2 domain(s) in 6s
Web App Attack
🇸🇬
nayumi
2026-09-12 07:35:11
(22 hours ago)
CrowdSec detection: crowdsecurity/http-probing | Service: http, http, http, http, http, http, http, ...
show more
CrowdSec detection: crowdsecurity/http-probing | Service: http, http, http, http, http, http, http, http, http, http, http
show less
Web App Attack
🇳🇱
Savvii
2026-09-12 04:17:56
(1 day ago)
20 attempts against mh_ha-misbehave-ban on comet
Brute-Force
Bad Web Bot
Web App Attack
🇺🇦
URAN Publishing Service
2026-09-11 23:29:01
(1 day ago)
[12/Sep/2026:02:29:01 +0300] -- 104.199.145.31 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET ...
show more
[12/Sep/2026:02:29:01 +0300] -- 104.199.145.31 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET /rclone.conf HTTP/1.1
show less
Bad Web Bot
Web App Attack
🇩🇪
Marc
2026-09-11 16:54:33
(1 day ago)
104.199.145.31 - - [11/Sep/2026:18:54:32 +0200] "GET //.env HTTP/2.0" 404 291 "-" "Mozilla/5.0 (comp ...
show more
104.199.145.31 - - [11/Sep/2026:18:54:32 +0200] "GET //.env HTTP/2.0" 404 291 "-" "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)" 104.199.145.31 - - [11/Sep/2026:18:54:32 +0200] "GET /api/.env/public/.env HTTP/2.0" 404 269 "-" "Mozilla/5.0 (compatible; YouBot/1.0; +https://you.com/bot)" 104.199.145.31 - - [11/Sep/2026:18:54:32 +0200] "GET /auth HTTP/2.0" 404 269 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Safari/537.36"
show less
Brute-Force
🇦🇺
Scrapline
2026-09-11 16:45:37
(1 day ago)
[Fail2Ban] nginx-scraper: banned after 5 failures
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 16:40:33
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.199.145.31 (31.145.199.104.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 104.199.145.31 (31.145.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 12:40:26.293552 2026] [security2:error] [pid 30622:tid 30622] [client 104.199.145.31:54628] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "radiawa.email"] [uri "/.env"] [unique_id "aqQu-qiHrFjUSc-v9QRfSgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇸🇪
nekopavel
2026-09-11 16:23:09
(1 day ago)
104.199.145.31 - - [11/Sep/2026:18:23:07 +0200]"GET /dashboard%2F.env HTTP/2.0" 444 0"-" pavel.gg "C ...
show more
104.199.145.31 - - [11/Sep/2026:18:23:07 +0200]"GET /dashboard%2F.env HTTP/2.0" 444 0"-" pavel.gg "CCBot/2.0 (https://commoncrawl.org/faq/)""0.000" "-""Taipei" "TW"
104.199.145.31 - - [11/Sep/2026:18:23:07 +0200]"GET /api%2F.env HTTP/2.0" 200 1482"-" pavel.gg "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Safari/605.1.15 (Applebot/0.1)""0.000" "-""Taipei" "TW"
104.199.145.31 - - [11/Sep/2026:18:23:07 +0200]"GET /settings%2F.env HTTP/2.0" 200 1482"-" pavel.gg "Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; +https://kimi.ai/)""0.000" "-""Taipei" "TW"
...
show less
Hacking
Bad Web Bot
Web App Attack
🇩🇪
ghostwarriors
2026-09-11 16:20:21
(1 day ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
🇩🇪
yitzhaq
2026-09-11 16:19:27
(1 day ago)
104.199.145.31 - - [11/Sep/2026:18:19:24 +0200] "GET /wp-config.php.bak HTTP/2.0" 404 294 "-" "Mozil ...
show more
104.199.145.31 - - [11/Sep/2026:18:19:24 +0200] "GET /wp-config.php.bak HTTP/2.0" 404 294 "-" "Mozilla/5.0 (compatible; xAI-Grok/1.0; +https://x.ai/)"
104.199.145.31 - - [11/Sep/2026:18:19:24 +0200] "GET /wp-config.php.old HTTP/2.0" 404 294 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexitybot)"
104.199.145.31 - - [11/Sep/2026:18:19:24 +0200] "GET /pages/index.astro.mjs.map HTTP/2.0" 404 294 "-" "Mozilla/5.0 (compatible; GrokBot/1.0; +https://x.ai/)"
104.199.145.31 - - [11/Sep/2026:18:19:24 +0200] "GET /_astro/pages/index.astro.mjs.map HTTP/2.0" 404 294 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
104.199.145.31 - - [11/Sep/2026:18:19:24 +0200] "GET /userfiles?path=../../../../.env HTTP/2.0" 404 294 "-" "Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; +https://kimi.ai/)"
104.199.145.31 - - [11/Sep/2026:18:19:24 +0200] "GET /userfiles?path=../../../.env HTTP/2.0" 404 294 "-" "Mozilla/5
show less
Web App Attack
Brute-Force
🇺🇸
TPI-Abuse
2026-09-11 16:15:15
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.199.145.31 (31.145.199.104.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 104.199.145.31 (31.145.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 12:15:09.700467 2026] [security2:error] [pid 15742:tid 15876] [client 104.199.145.31:59764] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "moidawg.gg"] [uri "/.htpasswd"] [unique_id "aqQpDbhIUPMMdKPy8NrpaQAAANI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇱🇻
garmtech.com
2026-09-11 15:53:41
(1 day ago)
Attempted access to sensitive endpoint (/.vscode/launch.json) detected. Automated scan or unauthoriz ...
show more
Attempted access to sensitive endpoint (/.vscode/launch.json) detected. Automated scan or unauthorized probing.
show less
Web App Attack
🇬🇧
consul.to
2026-09-11 15:35:02
(1 day ago)
Web attack/malicious scanning detected
Web App Attack