๐ง๐ท
Peregrine
2026-09-20 03:10:42
(1 day ago)
Fail2Ban Jail: tomcat-honeypot | Evidence: 34.143.221.193 172.70.208.85 - - [16/Sep/2026:23:29:55 -0 ...
show more
Fail2Ban Jail: tomcat-honeypot | Evidence: 34.143.221.193 172.70.208.85 - - [16/Sep/2026:23:29:55 -0300] "GET /@fs/app/.env?raw?? HTTP/1.1" 404 414
34.143.221.193 172.70.208.85 - - [16/Sep/2026:23:29:56 -0300] "GET /@fs/src/.env?raw?? HTTP/1.1" 404 414
34.143.221.193 172.70.208.125 - - [16/Sep/2026:23:29:56 -0300] "GET /@fs/..%252f..%252f..%252f..%252f..%252froot/.env?raw?? HTTP/1.1" 404 414
34.143.221.193 172.70.208.85 - - [16/Sep/2026:23:29:56 -0300] "GET /@fs/../.env?raw?? HTTP/1.1" 404 414
34.143.221.193 172.70.208.125 - - [16/Sep/2026:23:29:56 -0300] "GET /_nuxt/../.env HTTP/1.1" 404 414
34.143.221.193 172.70.208.85 - - [16/Sep/2026:23:29:56 -0300] "GET /static../.env HTTP/1.1" 404 414
show less
Bad Web Bot
๐ซ๐ท
SpaceHost-Server
2026-09-19 22:20:32
(1 day ago)
Brute-Force
Web App Attack
๐ซ๐ท
Bbelguise
2026-09-19 15:31:32
(2 days ago)
34.143.221.193 account.belguise.net - [18/Sep/2026:10:33:26 +0200] "GET / HTTP/2.0" 403 158 "-" "Moz ...
show more
34.143.221.193 account.belguise.net - [18/Sep/2026:10:33:26 +0200] "GET / HTTP/2.0" 403 158 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Mobile Safari/537.36"
34.143.221.193 account.belguise.net - [18/Sep/2026:10:33:26 +0200] "GET /api/.env HTTP/2.0" 403 158 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; OAI-SearchBot/1.0; +https://openai.com/searchbot)"
34.143.221.193 account.belguise.net - [18/Sep/2026:10:33:26 +0200] "GET /z9x8c7v6b5-debug-trigger-account.belguise.net HTTP/2.0" 403 158 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; [email protected] )"
34.143.221.193 account.belguise.net - [18/Sep/2026:10:33:26 +0200] "GET /.github/workflows/deploy.yml HTTP/2.0" 403 158 "-" "Mozilla/5.0 (compatible; Bravebot/1.0; +https://brave.com/search/)"
34.143.221.193 account.belguise.net - [18/Sep/2026:10:33:26 +0200] "GET /.aws/credentials HTTP/2.0" 403 158 "-" "CCBot/2.0 (https
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
hostmach
2026-09-19 13:50:17
(2 days ago)
(cpanel) Failed cPanel login from 34.143.221.193 (SG/Singapore/193.221.143.34.bc.googleusercontent.c ...
show more
(cpanel) Failed cPanel login from 34.143.221.193 (SG/Singapore/193.221.143.34.bc.googleusercontent.com): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CPANEL; Logs: [2026-09-19 09:50:13 -0400] info [cpaneld] 34.143.221.193 - - "GET /.idea/WebServers.xml HTTP/1.1" FAILED LOGIN cpaneld: login attempt without username
[2026-09-19 09:50:13 -0400] info [cpaneld] 34.143.221.193 - - "GET /z9x8c7v6b5-debug-trigger-cpanel.tdnx.net HTTP/1.1" FAILED LOGIN cpaneld: login attempt without username
[2026-09-19 09:50:13 -0400] info [cpaneld] 34.143.221.193 - - "GET /.vscode/launch.json HTTP/1.1" FAILED LOGIN cpaneld: login attempt without username
[2026-09-19 09:50:15 -0400] info [cpaneld] 34.143.221.193 - - "GET /.ssh/config HTTP/1.1" FAILED LOGIN cpaneld: login attempt without username
[2026-09-19 09:50:15 -0400] info [cpaneld] 34.143.221.193 - - "GET /.ssh/known_hosts HTTP/1.1" FAILED LOGIN cpaneld: login attempt without username
show less
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-09-19 13:41:49
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.143.221.193 (193.221.143.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.143.221.193 (193.221.143.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 09:41:43.248609 2026] [security2:error] [pid 6589:tid 6589] [client 34.143.221.193:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.portfoliolighting.net"] [uri "/__vite_rsc_findSourceMapURL"] [unique_id "aq6RF5QMCBe91JzAxyH2rgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-09-19 13:30:04
(2 days ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐บ๐ธ
Charlesiv
2026-09-19 10:05:53
(2 days ago)
Triggered Cloudflare WAF (firewallCustom) from SG.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Prot ...
show more
Triggered Cloudflare WAF (firewallCustom) from SG.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Protocol: HTTP/2 (GET method)
Endpoint: /config/firebase-admin.json
Timestamp: 2026-09-19T03:17:07Z
Ray ID: a3d56f7f2945252c
UA: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexitybot)
show less
Bad Web Bot
๐ฌ๐ง
thetomtaylor.co.uk
2026-09-19 00:08:01
(2 days ago)
Fail2Ban - [WAF]ModSecurity OWASP CRS rule violation on nginx-modsecurity ... [ice01,ice02,wa01,wa02 ...
show more
Fail2Ban - [WAF]ModSecurity OWASP CRS rule violation on nginx-modsecurity ... [ice01,ice02,wa01,wa02]
show less
Hacking
SQL Injection
Web App Attack
๐บ๐ธ
interbiznw.com
2026-09-18 22:44:31
(2 days ago)
malicious-web-requests-vulnerability-scanning
Hacking
Brute-Force
Exploited Host
Web App Attack
๐ฌ๐ง
thetomtaylor.co.uk
2026-09-18 22:22:02
(2 days ago)
Fail2Ban - [WAF]ModSecurity rule violation on modsecurity ... [wa01,wa02]
Hacking
SQL Injection
Web App Attack
๐ต๐ฑ
sefinek.net
2026-09-18 22:19:31
(2 days ago)
Triggered Cloudflare WAF (firewallCustom) from SG.
Action: BLOCK | Protocol: HTTP/2 (GET) | Endpoint ...
show more
Triggered Cloudflare WAF (firewallCustom) from SG.
Action: BLOCK | Protocol: HTTP/2 (GET) | Endpoint: /actuator | UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Safari/605.1.15 (Applebot/0.1) โข Generated by: github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
Charlesiv
2026-09-18 20:04:00
(3 days ago)
Triggered Cloudflare WAF (firewallCustom) from SG.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Prot ...
show more
Triggered Cloudflare WAF (firewallCustom) from SG.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Protocol: HTTP/2 (GET method)
Endpoint: /sendgrid.env
Timestamp: 2026-09-18T18:39:32Z
Ray ID: a3d27953890d3f81
UA: DuckAssistBot/1.1 (https://duckduckgo.com/duckassistbot)
show less
Bad Web Bot
๐ฉ๐ช
pscriptos
2026-09-18 18:54:26
(3 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐ฉ๐ช
Hagen Schoebel
2026-09-18 18:52:28
(3 days ago)
Blocked by CrowdSec - crowdsecurity/http-probing (SG)
Port Scan
Brute-Force
Web App Attack
SSH
๐ฉ๐ช
pscriptos
2026-09-18 18:30:13
(3 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/appsec-vpatch
Web App Attack