🇩🇪
Grossmann-Gruppe
2026-08-26 06:44:55
(2 weeks ago)
Plesk Fail2Ban: plesk-modsecurity
Hacking
Brute-Force
🇩🇪
arnisolutions
2026-08-19 12:02:17
(2 weeks ago)
Vulnerability scanning (requests for admin panels, shells, backup files etc.) against a production s ...
show more
Vulnerability scanning (requests for admin panels, shells, backup files etc.) against a production server. Observed on 6 day(s) between 2026-08-14 and 2026-08-18 (UTC).
show less
Web App Attack
Hacking
🇩🇪
Grossmann-Gruppe
2026-08-15 10:05:29
(3 weeks ago)
Plesk Fail2Ban: plesk-modsecurity
Hacking
Brute-Force
🇮🇳
evicky2002
2026-08-14 06:00:12
(3 weeks ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
🇭🇺
NyaljBe
2026-08-13 07:08:00
(3 weeks ago)
34.107.37.81 - - [09/Aug/2026:10:47:18 +0200] "GET /firebase-service-account.json HTTP/1.1" 404 153 ...
show more
34.107.37.81 - - [09/Aug/2026:10:47:18 +0200] "GET /firebase-service-account.json HTTP/1.1" 404 153 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; GPTBot/1.3; +https://openai.com/gptbot)"
34.107.37.81 - - [09/Aug/2026:10:47:18 +0200] "GET /.docker/config.json HTTP/1.1" 404 153 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; GPTBot/1.3; +https://openai.com/gptbot)"
34.107.37.81 - - [09/Aug/2026:10:47:18 +0200] "GET /Dockerfile HTTP/1.1" 404 153 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; GPTBot/1.3; +https://openai.com/gptbot)"
34.107.37.81 - - [09/Aug/2026:10:47:18 +0200] "GET /.github/.env HTTP/1.1" 404 153 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; GPTBot/1.3; +https://openai.com/gptbot)"
34.107.37.81 - - [09/Aug/2026:10:47:18 +0200] "GET /firebase-adminsdk.json HTTP/1.1" 404 153 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; GPTBot/1.3; +https://openai.com/gptbot)"
show less
Web App Attack
🇩🇪
Grossmann-Gruppe
2026-08-12 18:06:50
(3 weeks ago)
Plesk Fail2Ban: plesk-modsecurity
Hacking
Brute-Force
🇬🇧
openstrike.co.uk
2026-08-10 05:13:41
(4 weeks ago)
56 attacks on env grabbing URLs, config grabbing URLs (type 2), PHP URLs, password grabbing URLs, VC ...
show more
56 attacks on env grabbing URLs, config grabbing URLs (type 2), PHP URLs, password grabbing URLs, VC URLs:
GET /@fs/.env?raw?? HTTP/1.1
GET /config/firebase-admin.json HTTP/1.1
GET /.env.php.bak HTTP/1.1
GET /.aws/credentials HTTP/1.1
GET /.git/HEAD HTTP/1.1
show less
Hacking
Web App Attack
🇭🇺
DumaNet
2026-08-10 02:41:00
(4 weeks ago)
Web app attack attempts, scanning for vulnerability.
Date: 2026 Aug 09. 13:22:04
Source IP: 34.107 ...
show more
Web app attack attempts, scanning for vulnerability.
Date: 2026 Aug 09. 13:22:04
Source IP: 34.107.37.81
Portion of the log(s):
34.107.37.81 - [09/Aug/2026:13:22:04 +0200] "GET /manage HTTP/1.1" 404 555 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Mobile Safari/537.36"
34.107.37.81 - [09/Aug/2026:13:22:04 +0200] "GET /console HTTP/1.1" 404 555 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Mobile Safari/537.36"
34.107.37.81 - [09/Aug/2026:13:22:04 +0200] "GET /workspace HTTP/1.1" 404 555 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Mobile Safari/537.36"
34.107.37.81 - [09/Aug/2026:13:22:03 +0200] "GET /admin HTTP/1.1" 404 555 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Mobile Safari/537.36"
34.107.37.81 - [09/Aug/2026:13:22:03 +0200] "POST /v1/graphql HTTP/1.1" 404 555 "https://[removed].rdn.hu"
show less
Web App Attack
🇭🇺
DumaNet
2026-08-10 01:54:00
(4 weeks ago)
Web app attack attempts, scanning for vulnerability.
Date: 2026 Aug 09. 13:00:22
Source IP: 34.107 ...
show more
Web app attack attempts, scanning for vulnerability.
Date: 2026 Aug 09. 13:00:22
Source IP: 34.107.37.81
Portion of the log(s):
34.107.37.81 - [09/Aug/2026:13:00:22 +0200] "GET /admin/.env HTTP/1.1" 404 153 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; GPTBot/1.3; +https://openai.com/gptbot)"
34.107.37.81 - [09/Aug/2026:13:00:22 +0200] "POST /api/graphql HTTP/1.1" 404 555 "https://[removed].rdn.hu" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Mobile Safari/537.36"
34.107.37.81 - [09/Aug/2026:13:00:22 +0200] "GET /portal HTTP/1.1" 404 555 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Mobile Safari/537.36"
34.107.37.81 - [09/Aug/2026:13:00:22 +0200] "GET /app HTTP/1.1" 404 555 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Mobile Safari/537.36"
34.107.37.81 - [09/Aug/2026:13:00:22 +0200] "GET /auth/login HTTP/1.1" 404 555 "-" "Mo
show less
Web App Attack
🇭🇺
DumaNet
2026-08-10 01:28:00
(4 weeks ago)
Web app attack attempts, scanning for vulnerability.
Date: 2026 Aug 09. 09:33:40
Source IP: 34.107 ...
show more
Web app attack attempts, scanning for vulnerability.
Date: 2026 Aug 09. 09:33:40
Source IP: 34.107.37.81
Portion of the log(s):
34.107.37.81 - [09/Aug/2026:09:33:40 +0200] "GET /.env.example HTTP/1.1" 404 153 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; GPTBot/1.3; +https://openai.com/gptbot)"
34.107.37.81 - [09/Aug/2026:09:33:40 +0200] "POST /api/graphql HTTP/1.1" 404 555 "http://[removed].rdn.hu" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Mobile Safari/537.36"
34.107.37.81 - [09/Aug/2026:09:33:40 +0200] "GET /api/.env HTTP/1.1" 404 153 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; GPTBot/1.3; +https://openai.com/gptbot)"
34.107.37.81 - [09/Aug/2026:09:33:40 +0200] "GET /admin/.env HTTP/1.1" 404 153 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; GPTBot/1.3; +https://openai.com/gptbot)"
34.107.37.81 - [09/Aug/2026:09:33:40 +0200] "GET /.env.old HTTP/1.1" 404 153 "-" "Mozilla/5.0 Apple
show less
Web App Attack
🇭🇺
DumaNet
2026-08-10 01:10:00
(4 weeks ago)
Web app attack attempts, scanning for vulnerability.
Date: 2026 Aug 09. 09:20:30
Source IP: 34.107 ...
show more
Web app attack attempts, scanning for vulnerability.
Date: 2026 Aug 09. 09:20:30
Source IP: 34.107.37.81
Portion of the log(s):
34.107.37.81 - [09/Aug/2026:09:20:30 +0200] "GET /api/.env HTTP/1.1" 404 153 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; GPTBot/1.3; +https://openai.com/gptbot)"
34.107.37.81 - [09/Aug/2026:09:20:30 +0200] "GET /.gitlab-ci.yml HTTP/1.1" 404 153 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; GPTBot/1.3; +https://openai.com/gptbot)"
34.107.37.81 - [09/Aug/2026:09:20:30 +0200] "GET /.env.backup HTTP/1.1" 404 153 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; GPTBot/1.3; +https://openai.com/gptbot)"
34.107.37.81 - [09/Aug/2026:09:20:30 +0200] "POST /v1/graphql HTTP/1.1" 404 555 "http://[removed].rdn.hu" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Mobile Safari/537.36"
34.107.37.81 - [09/Aug/2026:09:20:29 +0200] "GET /.env.example HTTP/1.1" 404 153 "-" "Mozilla
show less
Web App Attack
🇩🇪
updown.io
2026-08-09 13:13:43
(4 weeks ago)
{"level":"info","ts":1786281221.8749132,"logger":"http.log.access.log0","msg":"handled request","req ...
show more
{"level":"info","ts":1786281221.8749132,"logger":"http.log.access.log0","msg":"handled request","request":{"remote_ip":"34.107.37.81","remote_port":"43082","client_ip":"34.107.37.81","proto":"HTTP/2.0","method":"POST","host":"ipis.status.updown.io","uri":"/graphql","headers":{"Content-Type":["application/json"],"Content-Length":["86"],"Sec-Ch-Ua-Platform":["\"Android\""],"Sec-Fetch-Mode":["cors"],"Accept":["*/*"],"Sec-Ch-Ua":["\"Not=A?Brand\";v=\"99\", \"Microsoft Edge\";v=\"151\", \"Chromium\";v=\"151\""],"Cookie":["REDACTED"],"Sec-Fetch-Site":["same-origin"],"Referer":["https://ipis.status.updown.io"],"User-Agent":["Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Mobile Safari/537.36 EdgA/151.0.0.0"],"Sec-Fetch-Dest":["empty"],"Priority":["u=1, i"],"Origin":["https://ipis.status.updown.io"],"Accept-Language":["en-US,en;q=0.9"],"Accept-Encoding":["gzip, deflate, br, zstd"],"Sec-Ch-Ua-Mobile":["?1"]},"tls":{"resumed":false,"version":772,"ciphe
...
show less
DDoS Attack
Web App Attack
🇩🇪
Gwyneth Llewelyn
2026-08-09 13:11:28
(4 weeks ago)
2026/08/09 14:11:26 [error] 57176#57176: *325818 access forbidden by rule, client: 34.107.37.81, ser ...
show more
2026/08/09 14:11:26 [error] 57176#57176: *325818 access forbidden by rule, client: 34.107.37.81, server: gwynethllewelyn.net, request: "GET /.env HTTP/2.0", host: "gwynethllewelyn.net"
34.107.37.81 - - [09/Aug/2026:14:11:26 +0100] "GET /.env HTTP/2.0" 403 1048 "-" "Mozilla/5.0 (compatible; cohere-ai/1.0; +https://cohere.com)"
2026/08/09 14:11:26 [error] 57177#57177: *325828 access forbidden by rule, client: 34.107.37.81, server: gwynethllewelyn.net, request: "GET /api/.env HTTP/2.0", host: "gwynethllewelyn.net"
show less
Brute-Force
Web App Attack
🇺🇸
interbiznw.com
2026-08-09 12:46:03
(4 weeks ago)
malicious-web-requests-vulnerability-scanning
Hacking
Brute-Force
Exploited Host
Web App Attack
🇫🇮
Kimmo Rieskaniemi
2026-08-09 12:45:07
(4 weeks ago)
CrowdSec triggered crowdsecurity/http-sensitive-files
Web App Attack
Hacking