๐ท๐ด
andreighitan
2026-06-01 00:00:00
(3 months ago)
Coordinated GCP credential-harvesting campaign against 84.46.253.134. Targeted GCP service account k ...
show more
Coordinated GCP credential-harvesting campaign against 84.46.253.134. Targeted GCP service account keys + Firebase credentials. ZAC Bayern ref BY0257-500359-26/8.
show less
Brute-Force
๐จ๐ญ
leo1305
2026-05-29 10:16:58
(3 months ago)
CrowdSec detection | scenario: http-probing
Port Scan
Web App Attack
๐ฎ๐น
ivanbiagi7
2026-05-28 01:22:06
(3 months ago)
(localhost/crowdsec) crowdsecurity/http-sensitive-files by ip 34.11.27.129 (US/396982) : 4h ban on I ...
show more
(localhost/crowdsec) crowdsecurity/http-sensitive-files by ip 34.11.27.129 (US/396982) : 4h ban on Ip 34.11.27.129
show less
Web App Attack
๐ฉ๐ช
David Ferneding
2026-05-27 11:22:10
(3 months ago)
Blocked by UFW (TCP on 80)
Source port: 45608
TTL: 58
Packet length: 60
TOS: 0x00
This report (for ...
show more
Blocked by UFW (TCP on 80)
Source port: 45608
TTL: 58
Packet length: 60
TOS: 0x00
This report (for 34.11.27.129) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
Web App Attack
๐บ๐ธ
antlac1
2026-05-27 08:00:28
(3 months ago)
crowdsecurity/http-probing
Brute-Force
Web App Attack
๐จ๐ฆ
john doe
2026-05-26 23:24:45
(3 months ago)
SentinelBot: Env File Hunting, Backup File Hunt (score: 70)
Bad Web Bot
๐บ๐ธ
cwytech
2026-05-26 20:37:24
(3 months ago)
Fleet-wide ban from the Ghostfleet ๐ป. Triggered by scenario: crowdsecurity/http-sensitive-files.
Bad Web Bot
Web App Attack
๐ฌ๐ง
pinguin
2026-05-26 12:37:59
(3 months ago)
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: LOG
Protocol: HTTP/2 (GET method)
...
show more
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: LOG
Protocol: HTTP/2 (GET method)
Endpoint: /info.php
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
Anonymous
2026-05-26 06:04:31
(3 months ago)
34.11.27.129 - - [26/May/2026:08:04:30 +0200] "GET /.env HTTP/1.1" 404 10317 "-" "Mozilla/5.0 (Windo ...
show more
34.11.27.129 - - [26/May/2026:08:04:30 +0200] "GET /.env HTTP/1.1" 404 10317 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"
...
show less
Brute-Force
Web App Attack
Anonymous
2026-05-26 05:28:14
(3 months ago)
34.11.27.129 - - [26/May/2026:05:28:14 +0000] "GET /.env HTTP/1.1" 404 7909 "-" "Mozilla/5.0 (Window ...
show more
34.11.27.129 - - [26/May/2026:05:28:14 +0000] "GET /.env HTTP/1.1" 404 7909 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"
...
show less
Brute-Force
Web App Attack
๐ฉ๐ช
markawes
2026-05-25 11:40:30
(3 months ago)
[markis] Auto banned by Fail2Ban. Reason: Malicious web scan / attempted access to sensitive paths. ...
show more
[markis] Auto banned by Fail2Ban. Reason: Malicious web scan / attempted access to sensitive paths. Evidence:
34.11.27.129 - - [25/May/2026:12:40:28 +0100] "GET /.env HTTP/1.1" 404 431 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"
34.11.27.129 - - [25/May/2026:12:40:29 +0100] "GET /.git/config HTTP/1.1" 404 431 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"
34.11.27.129 - - [25/May/2026:12:40:29 +0100] "GET /wp-config.php.bak HTTP/1.1" 404 431 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"
show less
Port Scan
Hacking
Web App Attack
๐ฌ๐ง
consul.to
2026-05-24 09:28:51
(3 months ago)
Web attack/malicious scanning detected
Web App Attack
๐ฉ๐ช
Ba-Yu
2026-05-24 07:41:12
(3 months ago)
General hacking/exploits/scanning
Web Spam
Hacking
Brute-Force
Exploited Host
Web App Attack
๐ท๐ด
andreighitan
2026-05-24 00:00:00
(3 months ago)
Confirmed attack against vmi1352037.contaboserver.net (84.46.253.134). Banned by fail2ban โ webshell ...
show more
Confirmed attack against vmi1352037.contaboserver.net (84.46.253.134). Banned by fail2ban โ webshell probe credential harvesting or brute force. Sustained cyberattack campaign April-May 2026. ZAC Bayern ref BY0257-500359-26/8.
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-22 21:26:55
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 34.11.27.129 (129.27.11.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.11.27.129 (129.27.11.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 22 17:26:52.008335 2026] [security2:error] [pid 529:tid 529] [client 34.11.27.129:39726] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.steamheat.tech"] [uri "/.env"] [unique_id "ahDKHPjJrPL4-tyBO3M3PAAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack