Anonymous
2026-09-16 01:37:30
(5 days ago)
Aggressive web scan
Web App Attack
Anonymous
2026-09-16 01:24:58
(5 days ago)
XSS Attempt
Hacking
🇬🇧
andypiper
2026-09-16 01:00:31
(5 days ago)
CrowdSec ban for AbuseIPDB Top List
Brute-Force
Web App Attack
🇫🇷
✨
2026-09-16 00:16:11
(5 days ago)
Domain : pleskcontrolpanel
Rule : config
2026-09-16 00:12:29 W3SVC2 Host-ND-89-64 ***hidden-privacy* ...
show more
Domain : pleskcontrolpanel
Rule : config
2026-09-16 00:12:29 W3SVC2 Host-ND-89-64 ***hidden-privacy*** GET /.git-credentials - 8443 - 108.162.237.43 HTTP/2.0 Mozilla/5.0 (compatible; Hunyuan/1.0; https://hunyuan.tencent.com/) - - 126.manjairao.com:8443 404 0 2 1288 609 781 - 34.148.112.4
show less
Hacking
SQL Injection
🇮🇳
evicky2002
2026-09-16 00:02:04
(5 days ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
🇺🇸
TPI-Abuse
2026-09-15 22:20:31
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 34.148.112.4 (4.112.148.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.148.112.4 (4.112.148.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 18:20:25.595956 2026] [security2:error] [pid 1291:tid 1291] [client 34.148.112.4:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "yggdrasil.org"] [uri "/.env.old"] [unique_id "aqnEqbHDAq5ND2Hd0108OAAAAAQ"], referer: http://yggdrasil.org:8080/.env.old
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
Secure Gateway®️
2026-09-15 22:00:33
(5 days ago)
Report By Secure Gateway Security Team: Potential CSRF Attack Detected
Hacking
🇺🇸
ALSCO®️
2026-09-15 22:00:33
(5 days ago)
Report By ALSCO Security Team: Unauthorized Connection Attempt
Hacking
🇺🇸
TPI-Abuse
2026-09-15 21:54:49
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 34.148.112.4 (4.112.148.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.148.112.4 (4.112.148.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 17:54:40.747360 2026] [security2:error] [pid 25144:tid 25144] [client 34.148.112.4:44180] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wholesalelivelobsters.com"] [uri "/%2E%2E/%2E%2E/%2E%2E/%2E%2E/.env"] [unique_id "aqm-oHJ16SkE1WgwbOnQCgAAACY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
WebNiraj
2026-09-15 21:47:51
(5 days ago)
(mod_security) mod_security (id:949110) triggered by 34.148.112.4 (US/United States/4.112.148.34.bc. ...
show more
(mod_security) mod_security (id:949110) triggered by 34.148.112.4 (US/United States/4.112.148.34.bc.googleusercontent.com): 5 in the last 3600 secs [SIGMA]
show less
Brute-Force
🇳🇱
Alt255
2026-09-15 21:18:29
(5 days ago)
[ti-14al] Web exploit scanning: 2 suspicious requests detected by fail2ban jail <name>. Example: 34. ...
show more
[ti-14al] Web exploit scanning: 2 suspicious requests detected by fail2ban jail <name>. Example: 34.148.112.4 - - [15/Sep/2026:23:18:28 +0200] "GET /.env.production HTTP/1.1" 301 6370 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexitybot)"
34.148.112.4 - - [15/Sep/2026:23:18:28 +0200] "GET /.env.local HTTP/1.1" 301 6365 "-" "Mozilla/5.0 (compatible; YouBot/1.0; +https://you.com/bot)"
...
show less
Bad Web Bot
Web App Attack
🇸🇪
vaia.cloud
2026-09-15 20:55:03
(5 days ago)
crowdsecurity/http-admin-interface-probing
Brute-Force
Web App Attack
🇷🇴
clauss
2026-09-15 20:49:59
(5 days ago)
34.148.112.4 - - [15/Sep/2026:23:49:58 +0300] "GET /.vscode/launch.json HTTP/2.0" 301 0 "-" "Mozilla ...
show more
34.148.112.4 - - [15/Sep/2026:23:49:58 +0300] "GET /.vscode/launch.json HTTP/2.0" 301 0 "-" "Mozilla/5.0 (compatible; Hunyuan/1.0; +https://hunyuan.tencent.com/)"
34.148.112.4 - - [15/Sep/2026:23:49:59 +0300] "GET /.vscode/launch.json HTTP/2.0" 404 8414 "https://tribut.ro/.vscode/launch.json" "Mozilla/5.0 (compatible; Hunyuan/1.0; +https://hunyuan.tencent.com/)"
...
show less
Web App Attack
🇺🇸
CDO
2026-09-15 19:42:00
(5 days ago)
URL Injection attempt detected. Automated web attack.
Hacking
Bad Web Bot
Web App Attack
🇪🇸
robotstxt
2026-09-15 19:37:00
(5 days ago)
34.148.112.4 - - [15/Sep/2026:19:36:43 +0000] "GET /__vite_rsc_findSourceMapURL?filename=file:///app ...
show more
34.148.112.4 - - [15/Sep/2026:19:36:43 +0000] "GET /__vite_rsc_findSourceMapURL?filename=file:///app/.env&environmentName=rsc HTTP/2.0" 403 20 "https://starship.xyz/__vite_rsc_findSourceMapURL?filename=file:///app/.env&environmentName=rsc" "CCBot/2.0 (https://commoncrawl.org/faq/)" "-" edge="34.148.112.4"
34.148.112.4 - - [15/Sep/2026:19:36:43 +0000] "GET /z9x8c7v6b5-debug-trigger-starship.xyz HTTP/2.0" 403 20 "https://starship.xyz/z9x8c7v6b5-debug-trigger-starship.xyz" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; GPTBot/1.3; +https://openai.com/gptbot)" "-" edge="34.148.112.4"
34.148.112.4 - - [15/Sep/2026:19:36:43 +0000] "GET /@fs/.env?import&?raw?? HTTP/2.0" 403 20 "https://starship.xyz/@fs/.env?import&?raw??" "Mozilla/5.0 (compatible; xAI-Grok/1.0; +https://x.ai/)" "-" edge="34.148.112.4"
34.148.112.4 - - [15/Sep/2026:19:36:43 +0000] "GET /__vite_rsc_findSourceMapURL?filename=file:///proc/self/environ&environmentName=rsc HTTP/2.0" 403 20 "https://starship.xyz/__v
...
show less
Web App Attack