๐บ๐ธ
cwytech
2026-09-20 14:04:23
(2 days ago)
Fleet-wide ban from the Ghostfleet ๐ป. Triggered by scenario: cwy/tactical-rmm-lockdown-high.
Hacking
Anonymous
2026-09-20 12:47:36
(2 days ago)
PSCSERV WPSCAN 34.139.46.75
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-09-20 12:16:10
(2 days ago)
Web attack/malicious scanning detected
Web App Attack
๐ง๐พ
lns.bz
2026-09-20 12:00:14
(2 days ago)
Too many 404 requests [BY]
Web App Attack
Anonymous
2026-09-20 12:00:02
(2 days ago)
suspicious request in access.log
Web App Attack
๐ซ๐ฎ
diego021
2026-09-20 11:51:46
(2 days ago)
34.139.46.75 pythonpirate.tech - [20/Sep/2026:06:51:45 -0500] "GET /env.js HTTP/2.0" 404 158 "-" "Mo ...
show more
34.139.46.75 pythonpirate.tech - [20/Sep/2026:06:51:45 -0500] "GET /env.js HTTP/2.0" 404 158 "-" "Mozilla/5.0 (compatible; xAI-Grok/1.0; +https://x.ai/)"
34.139.46.75 pythonpirate.tech - [20/Sep/2026:06:51:45 -0500] "GET /z9x8c7v6b5-debug-trigger-pythonpirate.tech HTTP/2.0" 404 158 "-" "Mozilla/5.0 (compatible; YiBot/1.0; +https://01.ai/)"
34.139.46.75 pythonpirate.tech - [20/Sep/2026:06:51:45 -0500] "GET /api/settings HTTP/2.0" 404 158 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; GPTBot/1.4; +https://openai.com/gptbot"
34.139.46.75 pythonpirate.tech - [20/Sep/2026:06:51:45 -0500] "GET /app/.env HTTP/2.0" 404 158 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexitybot)"
...
show less
Web App Attack
๐ฏ๐ต
S.O.B.A. Dev.
2026-09-20 10:10:48
(3 days ago)
Web vulnerability scanning
Brute-Force
Web Spam
Web App Attack
๐ฎ๐น
CoreTech srl
2026-09-20 09:28:56
(3 days ago)
cloudlinux2 fail2ban: 2026-09-20 11:23:55,328 fail2ban.filter [1597]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-09-20 11:23:55,328 fail2ban.filter [1597]: INFO [plesk-modsecurity] Found 34.139.46.75 - 2026-09-20 11:23:55cloudlinux2 fail2ban: 2026-09-20 11:23:55,309 fail2ban.filter [1597]: INFO [plesk-modsecurity] Found 34.139.46.75 - 2026-09-20 11:23:55cloudlinux2 fail2ban: 2026-09-20 11:23:55,399 fail2ban.actions [1597]: NOTICE [plesk-modsecurity] Ban 34.139.46.75cloudlinux2 fail2ban: 2026-09-20 11:23:55,411 fail2ban.filter [1597]: INFO [plesk-modsecurity] Found 34.139.46.75 - 2026-09-20 11:23:55cloudlinux2 fail2ban: 2026-09-20 11:23:55,192 fail2ban.filter [1597]: INFO [plesk-modsecurity] Found 34.139.46.75 - 2026-09-20 11:23:55cloudlinux2 fail2ban: 2026-09-20 11:23:55,407 fail2ban.filter [1597]: INFO [recidive] Found 34.139.46.75 - 2026-09-20 11:23:55cloudlinux2 fail2ban: 2026-09-20 11:24:13,040 fail2ban.filter [1597]: INFO [plesk-modsecurity] Found 79.51.140.129 - 2026-09-20 11:24:12cloudlinux2 fail2ban: 2026-09-20 1
show less
Web App Attack
๐บ๐ธ
LotPhantom
2026-09-20 08:14:13
(3 days ago)
2026-09-20T08:14:13.532999+00:00 bridginggaps kernel: [UFW BLOCK] IN=eth0 OUT= MAC=2e:bc:64:1d:2c:e1 ...
show more
2026-09-20T08:14:13.532999+00:00 bridginggaps kernel: [UFW BLOCK] IN=eth0 OUT= MAC=2e:bc:64:1d:2c:e1:fe:00:00:00:01:01:08:00 SRC=34.139.46.75 DST=157.230.217.55 LEN=60 TOS=0x00 PREC=0x00 TTL=56 ID=26135 DF PROTO=TCP SPT=39114 DPT=8080 WINDOW=65320 RES=0x00 SYN URGP=0
2026-09-20T08:14:13.533046+00:00 bridginggaps kernel: [UFW BLOCK] IN=eth0 OUT= MAC=2e:bc:64:1d:2c:e1:fe:00:00:00:01:01:08:00 SRC=34.139.46.75 DST=157.230.217.55 LEN=60 TOS=0x00 PREC=0x00 TTL=56 ID=64595 DF PROTO=TCP SPT=49748 DPT=8443 WINDOW=65320 RES=0x00 SYN URGP=0
...
show less
Port Scan
Hacking
๐ซ๐ฎ
tjs
2026-09-16 12:35:00
(6 days ago)
web attack
Hacking
Web App Attack
๐ฟ๐ฆ
conure.sh
2026-09-16 12:07:39
(6 days ago)
csagent: score 20.5: secrets grab x2, 404 noise floor x2; 1 domain(s) in 1s
Web App Attack
๐ง๐ช
Saec
2026-09-16 01:42:08
(1 week ago)
Honeypot caught: /.env.old via aad.saec.me. UA: Mozilla/5.0 (compatible; Baiduspider/2.0; +http://ww ...
show more
Honeypot caught: /.env.old via aad.saec.me. UA: Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html).
show less
Port Scan
Brute-Force
Bad Web Bot
Web App Attack
IoT Targeted
๐บ๐ธ
antlac1
2026-09-15 21:21:41
(1 week ago)
crowdsecurity/http-path-traversal-probing
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 21:20:27
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 34.139.46.75 (75.46.139.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.139.46.75 (75.46.139.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 17:20:23.591082 2026] [security2:error] [pid 24589:tid 24589] [client 34.139.46.75:46074] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||weyoungrenovations.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "weyoungrenovations.com"] [uri "/rclone.conf"] [unique_id "aqm2lzRwc3qbxUitTnX6XQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
gamabe
2026-09-15 20:40:59
(1 week ago)
Detected crowdsecurity/http-sensitive-files attack pattern. Reported by CrowdSec IDS.
Hacking