๐บ๐ธ
daveoctober
2026-10-10 17:46:04
(47 minutes ago)
October Sentinel: honeypot triggered
Bad Web Bot
Web App Attack
๐ฉ๐ช
Hazzard
2026-10-10 17:12:50
(1 hour ago)
(mod_security) mod_security triggered on hostname [redacted]): (CF_ENABLE)
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-10-10 17:05:46
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.152.48.34 (34.48.152.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.152.48.34 (34.48.152.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 13:05:38.848423 2026] [security2:error] [pid 19904:tid 19904] [client 34.152.48.34:58734] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wyndover.photo"] [uri "/@fs/app/.env"] [unique_id "aspwYuXOlyrkRkXn0oFzEQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-10 16:20:13
(2 hours ago)
| Multiple common web attacks from same source ip. (multiple servers)
Web App Attack
Hacking
SQL Injection
๐ฌ๐ง
consul.to
2026-10-10 16:01:28
(2 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐ฒ๐พ
Rizzy
2026-10-10 15:52:02
(2 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐บ๐ธ
TAY
2026-10-10 15:46:14
(2 hours ago)
34.152.48.34 - - [10/Oct/2026:23:46:08 +0800] "GET /@fs/../.env?raw?? HTTP/1.1" 404 48520 "-" "Mozil ...
show more
34.152.48.34 - - [10/Oct/2026:23:46:08 +0800] "GET /@fs/../.env?raw?? HTTP/1.1" 404 48520 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; OAI-AdsBot/1.0; +https://openai.com/adsbot"
34.152.48.34 - - [10/Oct/2026:23:46:10 +0800] "GET /@fs/../.env?import&raw?? HTTP/1.1" 404 48520 "-" "Mozilla/5.0 (compatible; Meta-ExternalAgent/1.0; +https://developers.facebook.com/docs/sharing/webmasters/crawler)"
34.152.48.34 - - [10/Oct/2026:23:46:12 +0800] "GET /media../.env HTTP/1.1" 404 48442 "-" "Mozilla/5.0 (compatible; MoonshotBot/1.0; +https://kimi.ai/)"
34.152.48.34 - - [10/Oct/2026:23:46:12 +0800] "GET /files../.env HTTP/1.1" 404 48442 "-" "Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; +https://kimi.ai/)"
34.152.48.34 - - [10/Oct/2026:23:46:12 +0800] "GET /static../.env HTTP/1.1" 404 48442 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-SearchBot/1.0; [email protected] )"
34.152.48.34 - - [10/Oct/2026:23:46:12 +0800] "GET /assets../.env HTT
...
show less
Brute-Force
๐ฎ๐น
zenmorro
2026-10-02 14:48:48
(1 week ago)
Honeypot hit (homeassistant:8123) โ scanner-path: /console. Automated report from honeypot infrastru ...
show more
Honeypot hit (homeassistant:8123) โ scanner-path: /console. Automated report from honeypot infrastructure
show less
Port Scan
Web App Attack
๐ฉ๐ช
maxpower
2026-10-02 14:05:33
(1 week ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 34.152.48.34 (CA/Canada/34.48.152.34.bc. ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 34.152.48.34 (CA/Canada/34.48.152.34.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 34.152.48.34 - - [02/Oct/2026:16:05:26 +0200] "GET /config.env HTTP/2.0" 403 0 "-" "Mozilla/5.0 (compatible; DeepSeekBot/1.0; +https://www.deepseek.com/)" "34.152.48.34" host=insegnesolution.it
show less
Port Scan
๐ฉ๐ช
paissangroup
2026-10-02 12:46:52
(1 week ago)
Multiple WAF Violations
Web App Attack
๐ฉ๐ช
maxpower
2026-10-02 12:46:38
(1 week ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 34.152.48.34 (CA/Canada/34.48.152.34.bc. ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 34.152.48.34 (CA/Canada/34.48.152.34.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 34.152.48.34 - - [02/Oct/2026:14:46:31 +0200] "GET /.ssh/id_ed25519 HTTP/2.0" 403 0 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-SearchBot/1.0; [email protected] )" "34.152.48.34" host=www.insegnesolution.it
show less
Port Scan
๐ฉ๐ช
maxpower
2026-10-02 11:44:16
(1 week ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 34.152.48.34 (CA/Canada/34.48.152.34.bc. ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 34.152.48.34 (CA/Canada/34.48.152.34.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 34.152.48.34 - - [02/Oct/2026:13:44:06 +0200] "GET /@fs/root/.aws/credentials?raw?? HTTP/2.0" 429 41 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; GPTBot/1.4; +https://openai.com/gptbot" "34.152.48.34" host=villapardi.it
show less
Port Scan
๐ฉ๐ช
maxpower
2026-10-02 08:45:05
(1 week ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 34.152.48.34 (CA/Canada/34.48.152.34.bc. ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 34.152.48.34 (CA/Canada/34.48.152.34.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 34.152.48.34 - - [02/Oct/2026:10:44:59 +0200] "GET /secrets.yml HTTP/2.0" 403 0 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexitybot)" "34.152.48.34" host=www.liverpoolitalia.it
show less
Port Scan
๐ง๐ช
cmbplf
2026-10-02 08:42:09
(1 week ago)
100 requests with url.path *credentials.json
Brute-Force
Bad Web Bot
๐ฉ๐ช
Sรฉfora Srl
2026-10-02 07:00:15
(1 week ago)
crowdsecurity/http-sensitive-files detected by CrowdSec
Web App Attack