Anonymous
2026-08-30 05:15:07
(1 day ago)
CVE-2025-30208 - ViteJS Traversal Exploit - HTTP(Request)
Hacking
Anonymous
2026-08-30 04:06:52
(1 day ago)
Suspicious URL access.
Hacking
๐ณ๐ฑ
ipoac.nl
2026-08-30 01:27:40
(1 day ago)
ipoac.nl:443 34.140.188.226 - - [30/Aug/2026:03:27:38 +0200] 203.26.133.254:443 "GET /static../.aws/ ...
show more
ipoac.nl:443 34.140.188.226 - - [30/Aug/2026:03:27:38 +0200] 203.26.133.254:443 "GET /static../.aws/credentials HTTP/1.1" 403 3550 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot*anthropic.com)"
show less
Bad Web Bot
๐ณ๐ฑ
Savvii
2026-08-30 01:04:35
(1 day ago)
20 attempts against mh-misbehave-ban on star
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฟ
SystemAdmin
2026-08-30 00:22:17
(1 day ago)
Doing bad things...
Bad Web Bot
๐ณ๐ด
jad-abuse
2026-08-29 23:56:39
(1 day ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: env_probe ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: env_probe, path_traversal, git_exposure, aws_creds, actuator, source_backup, ai_secrets, ssh_keys. Observed by 1 sensor(s); 1212 hits.
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 21:56:22
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.140.188.226 (226.188.140.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.140.188.226 (226.188.140.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 17:56:17.480105 2026] [security2:error] [pid 32153:tid 32163] [client 34.140.188.226:46452] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.201"] [uri "/static../.env"] [unique_id "apNVgZcHDB9ANi7Hk06JMgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
backslash
2026-08-29 19:27:00
(1 day ago)
block ruleset WAF detection and high score on abuseIPDB 149EB1B42C242111FADBBC2EF8F90219570691E1
Bad Web Bot
๐ฉ๐ช
dpsbs
2026-08-29 18:03:10
(1 day ago)
multiple ips intrustions detected
Hacking
Anonymous
2026-08-29 17:49:02
(1 day ago)
LH-Watcher: HONEYPOT FAKE_ID [Bytespider]
Hacking
SSH
Bad Web Bot
Anonymous
2026-08-29 09:27:11
(2 days ago)
denied traffic to a honeypot network. destination port 8443.
Port Scan
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-29 05:33:06
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.140.188.226 (226.188.140.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.140.188.226 (226.188.140.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 01:32:59.798674 2026] [security2:error] [pid 24511:tid 24511] [client 34.140.188.226:27542] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.204"] [uri "/static../.env"] [unique_id "apJvC4PWKdi-qOGQAZEEhgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-29 03:30:16
(2 days ago)
| A web attack returned code 200 (success).
Web App Attack
Hacking
SQL Injection
๐ต๐ฑ
webadmin
2026-08-28 18:48:17
(2 days ago)
34.140.188.226 - - [28/Aug/2026:20:48:13 +0200] "GET /assets../../../etc/passwd HTTP/1.1" 400 150 "- ...
show more
34.140.188.226 - - [28/Aug/2026:20:48:13 +0200] "GET /assets../../../etc/passwd HTTP/1.1" 400 150 "-" "-" (mis.sai.com.pl, / mis.sai.com.pl,)
34.140.188.226 - - [28/Aug/2026:20:48:13 +0200] "GET /assets../../../.env HTTP/1.1" 400 150 "-" "-" (mis.sai.com.pl, / mis.sai.com.pl,)
34.140.188.226 - - [28/Aug/2026:20:48:16 +0200] "GET /assets../../../etc/passwd HTTP/1.1" 400 150 "-" "-" (ribb.online / ribb.online)
34.140.188.226 - - [28/Aug/2026:20:48:17 +0200] "GET /assets../../../etc/passwd HTTP/1.1" 400 150 "-" "-" (mis.sai.com.pl, / mis.sai.com.pl,)
34.140.188.226 - - [28/Aug/2026:20:48:17 +0200] "GET /assets../../../.env HTTP/1.1" 400 150 "-" "-" (mis.sai.com.pl, / mis.sai.com.pl,)
show less
Web App Attack
๐ต๐ฑ
swiszczu
2026-08-28 17:52:13
(2 days ago)
Fail2Ban automatic report:
Multiple forbidden requests in short amount of time:
34.140.188.226 - - [ ...
show more
Fail2Ban automatic report:
Multiple forbidden requests in short amount of time:
34.140.188.226 - - [28/Aug/2026:19:52:11 +0200] "GET /__aws_leak_probe_73b74cd7__ HTTP/1.1" 403 555 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_4 like Mac OS X) AppleWebKit/537.36 (KHTML, like Gecko; compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot) Chrome/147.0.1305.227 Mobile Safari/537.36" "-"
34.140.188.226 - - [28/Aug/2026:19:52:11 +0200] "GET /media../.env HTTP/1.1" 403 555 "-" "Mozilla/5.0 (Linux; Android 12; Pixel 6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.7600.10 Mobile Safari/537.36; compatible; Claude-User/1.0; [email protected] " "-"
34.140.188.226 - - [28/Aug/2026:19:52:12 +0200] "GET /.env.local HTTP/1.1" 403 555 "-" "Mozilla/5.0 (Linux; Android 13; Pixel 7) AppleWebKit/537.36 (KHTML, like Gecko; com
show less
Hacking
Web App Attack