๐ฐ๐ท
Seung Seog Han
2026-09-17 15:30:03
(2 hours ago)
Brute-force attack detected
Brute-Force
SSH
๐ฉ๐ช
XICTRON
2026-09-17 14:40:07
(3 hours ago)
ModSecurity rule violation detected by Fail2Ban
Web App Attack
๐บ๐ธ
gamabe
2026-09-17 14:10:47
(3 hours ago)
Detected crowdsecurity/http-dos-swithcing-ua attack pattern. Reported by CrowdSec IDS.
Hacking
๐ณ๐ฑ
Alt255
2026-09-17 11:09:16
(6 hours ago)
[cb-13al] Excessive 404 errors (web scanning): 30 suspicious requests detected by fail2ban jail apac ...
show more
[cb-13al] Excessive 404 errors (web scanning): 30 suspicious requests detected by fail2ban jail apache-404. Example: 34.138.144.142 - - [17/Sep/2026:13:09:08 +0200] "GET /ssl/server.key HTTP/2.0" 404 1855 "-" "Mozilla/5.0 (compatible; GrokBot/1.0; +https://x.ai/)"
34.138.144.142 - - [17/Sep/2026:13:09:08 +0200] "GET /dist/.vite/manifest.json HTTP/2.0" 404 1855 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36"
34.138.144.142 - - [17/Sep/2026:13:09:08 +0200] "GET /dist/manifest.json HTTP/2.0" 404 1855 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36"
34.138.144.142 - - [17/Sep/2026:13:09:08 +0200] "GET /build/manifest.json HTTP/2.0" 404 1855 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Geck
...
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
rh24
2026-09-17 10:58:47
(6 hours ago)
(secretscan) Secret-Scanner (env/git/ssh/credentials) from 34.138.144.142 (US/United States/142.144. ...
show more
(secretscan) Secret-Scanner (env/git/ssh/credentials) from 34.138.144.142 (US/United States/142.144.138.34.bc.googleusercontent.com)
show less
Hacking
๐ณ๐ฑ
e.fierstra
2026-09-17 10:33:04
(7 hours ago)
excessive HTTP 404 errors
Bad Web Bot
Anonymous
2026-09-17 09:23:01
(8 hours ago)
34.138.144.142 - - [17/Sep/2026:11:22:56 +0200] "GET /static/manifest.json HTTP/1.1" 404 65202
34.13 ...
show more
34.138.144.142 - - [17/Sep/2026:11:22:56 +0200] "GET /static/manifest.json HTTP/1.1" 404 65202
34.138.144.142 - - [17/Sep/2026:11:22:56 +0200] "GET /graphql HTTP/1.1" 404 65162
34.138.144.142 - - [17/Sep/2026:11:22:56 +0200] "GET /manifest.json HTTP/1.1" 404 65180
34.138.144.142 - - [17/Sep/2026:11:22:56 +0200] "GET /assets/manifest.json HTTP/1.1" 404 65202
34.138.144.142 - - [17/Sep/2026:11:22:56 +0200] "GET /asset-manifest.json HTTP/1.1" 404 65198
34.138.144.142 - - [17/Sep/2026:11:22:56 +0200] "GET /dist/manifest.json HTTP/1.1" 404 65196
34.138.144.142 - - [17/Sep/2026:11:22:56 +0200] "GET /webpack-stats.json HTTP/1.1" 404 65195
34.138.144.142 - - [17/Sep/2026:11:22:56 +0200] "GET /private-key HTTP/1.1" 404 65174
34.138.144.142 - - [17/Sep/2026:11:22:58 +0200] "GET /v1/graphql HTTP/1.1" 404 60338
34.138.144.142 - - [17/Sep/2026:11:23:00 +0200] "GET /__vite_rsc_findSourceMapURL?filename=file:///app/.env&environmentName=rsc?filename=file%3A%2F%2F%2Fapp%2F.env&environmentName=rsc HTTP/
...
show less
Web Spam
Web App Attack
๐ซ๐ท
tecnoacquisti.com
2026-09-17 08:08:34
(9 hours ago)
PrestaShop Security Module: suspicious probe path detected (/.env)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-17 08:00:49
(9 hours ago)
(mod_security) mod_security (id:243320) triggered by 34.138.144.142 (142.144.138.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:243320) triggered by 34.138.144.142 (142.144.138.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 04:00:41.703548 2026] [security2:error] [pid 26468:tid 26468] [client 34.138.144.142:52714] ModSecurity: Access denied with code 403 (phase 2). String match "/.profile" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "6630"] [id "243320"] [rev "1"] [msg "COMODO WAF: Information disclosure vulnerability in Cloud Foundry PHP Buildpack (aka php-buildpack) before 4.3.18 and PHP Buildpack Cf-release before 242, as used in Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.6.38 and 1.7.x before 1.7.19 and other products (CVE-2016-6639)||takemehomedogrescue.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "takemehomedogrescue.org"] [uri "/.profile"] [unique_id "aqueKSZS1vMU6lbQmHYVugAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
gamabe
2026-09-17 07:40:00
(10 hours ago)
Detected crowdsecurity/http-sensitive-files attack pattern. Reported by CrowdSec IDS.
Hacking
๐ณ๐ฑ
Savvii
2026-09-17 07:16:40
(10 hours ago)
20 attempts against mh-misbehave-ban on solar
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
jormaster3k
2026-09-17 06:15:25
(11 hours ago)
Attack against Apache (too many 404s)
Web App Attack
๐ฎ๐ณ
evicky2002
2026-09-17 06:00:05
(11 hours ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-09-17 05:28:40
(12 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.138.144.142 (142.144.138.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 34.138.144.142 (142.144.138.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 01:28:32.475141 2026] [security2:error] [pid 4464:tid 4464] [client 34.138.144.142:0] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||portfoliolighting.net|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "portfoliolighting.net"] [uri "/rclone.conf"] [unique_id "aqt6gI5mOpaYGZ8E4VvB9wAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Eric
2026-09-17 05:26:46
(12 hours ago)
[Thu Sep 17 05:26:42.938063 2026] [security2:error] [pid 774600:tid 774600] [client 34.138.144.142:0 ...
show more
[Thu Sep 17 05:26:42.938063 2026] [security2:error] [pid 774600:tid 774600] [client 34.138.144.142:0] [client 34.138.144.142] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "pop-the-slots.com"] [uri "/rclone.conf"] [unique_id "aqt6EiXTPMUZ9CezknywXQAAACI"]
[Thu Sep 17 05:26:43.301178 2026] [security2:error] [pid 796551:tid 796551] [client 34.138.144.142:0] [client 34.138.144.142] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [
...
show less
Hacking
Web App Attack