๐ฉ๐ช
raph
2026-09-20 12:38:49
(11 minutes ago)
[LIB DIR] crawler /vendor/*, /node_modules/*, /laravel/*, etc.
Bad Web Bot
Web App Attack
๐ฉ๐ช
webanyone
2026-09-20 12:32:38
(17 minutes ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
๐ฉ๐ช
pscriptos
2026-09-20 11:44:10
(1 hour ago)
This IP was detected by CrowdSec triggering crowdsecurity/appsec-vpatch
Web App Attack
๐ฉ๐ช
itsolon
2026-09-20 11:36:12
(1 hour ago)
[20/Sep/2026:13:36:10 +0200] 178990417012.078666 34.156.130.80 0 217.154.7.177 443
[20/Sep/2026:13:3 ...
show more
[20/Sep/2026:13:36:10 +0200] 178990417012.078666 34.156.130.80 0 217.154.7.177 443
[20/Sep/2026:13:36:11 +0200] 178990417128.713377 34.156.130.80 0 217.154.7.177 443
[20/Sep/2026:13:36:11 +0200] 178990417197.064232 34.156.130.80 0 217.154.7.177 443
[20/Sep/2026:13:36:11 +0200] 178990417148.855482 34.156.130.80 0 217.154.7.177 443
[20/Sep/2026:13:36:11 +0200] 178990417112.768656 34.156.130.80 0 217.154.7.177 443
...
show less
Port Scan
Hacking
Brute-Force
Web App Attack
๐ซ๐ท
Octopuce
2026-09-20 11:15:36
(1 hour ago)
Aggressive web search of vulnerable pages: /api/v1/config/ /openapi.json /api/openapi.json /swagger. ...
show more
Aggressive web search of vulnerable pages: /api/v1/config/ /openapi.json /api/openapi.json /swagger.json /docker-compose.yml ...
show less
Web App Attack
๐ซ๐ท
LRob
2026-09-20 11:04:02
(1 hour ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /internal/.env | 2026-09-20 11:04 UTC
show less
Hacking
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-09-20 10:50:09
(1 hour ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
๐ฉ๐ช
yitzhaq
2026-09-20 10:36:34
(2 hours ago)
34.156.130.80 - - [20/Sep/2026:12:36:32 +0200] "GET /actuator/configprops HTTP/2.0" 404 296 "-" "Moz ...
show more
34.156.130.80 - - [20/Sep/2026:12:36:32 +0200] "GET /actuator/configprops HTTP/2.0" 404 296 "-" "Mozilla/5.0 (compatible; GrokBot/1.0; +https://x.ai/)"
34.156.130.80 - - [20/Sep/2026:12:36:32 +0200] "GET /firebase-adminsdk.json HTTP/2.0" 404 296 "-" "Mozilla/5.0 (compatible; Hunyuan/1.0; +https://hunyuan.tencent.com/)"
34.156.130.80 - - [20/Sep/2026:12:36:32 +0200] "GET /serverless.yaml HTTP/2.0" 404 296 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Safari/605.1.15 (Applebot/0.1)"
34.156.130.80 - - [20/Sep/2026:12:36:32 +0200] "GET /.svn/entries HTTP/2.0" 403 298 "-" "Mozilla/5.0 (compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot)"
34.156.130.80 - - [20/Sep/2026:12:36:32 +0200] "GET /terraform.tfstate HTTP/2.0" 403 298 "-" "Mozilla/5.0 (compatible; Qwenbot/1.0; +https://qwen.alibaba.com/)"
34.156.130.80 - - [20/Sep/2026:12:36:32 +0200] "GET /.ssh/id_ed25519 HTTP/2.0" 404 296 "-" "Mozilla/5.0 (compatib
show less
Web App Attack
Hacking
๐ฌ๐ง
NotCool
2026-09-20 10:33:18
(2 hours ago)
(CRAWLDELAY) Generic Bot Crawl-delay Violation 34.156.130.80 (BE/Belgium/80.130.156.34.bc.googleuser ...
show more
(CRAWLDELAY) Generic Bot Crawl-delay Violation 34.156.130.80 (BE/Belgium/80.130.156.34.bc.googleusercontent.com): 50 in the last 3600 secs
show less
Bad Web Bot
๐ณ๐ฑ
Savvii
2026-09-20 10:30:38
(2 hours ago)
20 attempts against mh-misbehave-ban on redirect
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
ca
2026-09-20 10:17:23
(2 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-crawl-non_statics
Web App Attack
Bad Web Bot
๐บ๐ธ
abenage
2026-09-20 10:17:10
(2 hours ago)
34.156.130.80 - - [20/Sep/2026:04:17:09 -0600] "GET /wp-json HTTP/2.0" 404 162 "-" "Mozilla/5.0 Appl ...
show more
34.156.130.80 - - [20/Sep/2026:04:17:09 -0600] "GET /wp-json HTTP/2.0" 404 162 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot"
show less
Bad Web Bot
Web App Attack
๐ฌ๐ง
bensmithurst
2026-09-20 10:16:37
(2 hours ago)
34.156.130.80 - - [20/Sep/2026:10:16:36 +0000] "GET /@fs/..%2f..%2f..%2f..%2f..%2froot/.env HTTP/1.1 ...
show more
34.156.130.80 - - [20/Sep/2026:10:16:36 +0000] "GET /@fs/..%2f..%2f..%2f..%2f..%2froot/.env HTTP/1.1" 400 150 "-" "-"
34.156.130.80 - - [20/Sep/2026:10:16:36 +0000] "GET /@fs/..%2f..%2f..%2f..%2f..%2fproc/self/environ HTTP/1.1" 400 150 "-" "-"
34.156.130.80 - - [20/Sep/2026:10:16:36 +0000] "GET /..%2f.env HTTP/1.1" 400 150 "-" "-"
34.156.130.80 - - [20/Sep/2026:10:16:36 +0000] "GET /%2e%2e/.env HTTP/1.1" 400 150 "-" "-"
34.156.130.80 - - [20/Sep/2026:10:16:37 +0000] "GET /..%2f..%2f.env HTTP/1.1" 400 150 "-" "-"
... [host=LAN***]
show less
Web App Attack
๐ฎ๐น
VHosting
2026-09-20 10:15:04
(2 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 10:06:29
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.156.130.80 (80.130.156.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.156.130.80 (80.130.156.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 06:06:24.768513 2026] [security2:error] [pid 2666053:tid 2666053] [client 34.156.130.80:57402] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "adn-media.net"] [uri "/.env.production"] [unique_id "aq-wINMHZOR6vuGS1GLW8AAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack