Anonymous
2026-09-16 07:07:25
(4 days ago)
IncogNET WAF local CrowdSec decision. Scenario=crowdsecurity/http-sensitive-files; Action=ban; Event ...
show more
IncogNET WAF local CrowdSec decision. Scenario=crowdsecurity/http-sensitive-files; Action=ban; Events=5; Hosts=incognet.io; Paths=/.aws/config,/.aws/credentials,/.env,/.git/HEAD,/.git/config; Country=US; ASN=396982 GOOGLE-CLOUD-PLATFORM
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 06:12:49
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.16.114.1 (1.114.16.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.16.114.1 (1.114.16.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 02:12:41.409678 2026] [security2:error] [pid 23255:tid 23255] [client 34.16.114.1:45694] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "melton.space"] [uri "/appearance/../../.env"] [unique_id "aqozWcfPut8ohd19QC1VRgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
MaxSmartCode
2026-09-16 06:07:07
(4 days ago)
Credential brute-force attacks on webpage.
Brute-Force
SSH
Anonymous
2026-09-16 06:04:26
(4 days ago)
IncogNET WAF local CrowdSec decision. Scenario=crowdsecurity/http-crawl-non_statics; Action=ban; Eve ...
show more
IncogNET WAF local CrowdSec decision. Scenario=crowdsecurity/http-crawl-non_statics; Action=ban; Events=44; Hosts=incognet.io; Paths=/.docker/config.json,/Dockerfile,/firebase-service-account.json,/secrets.yml,/service-account.json,/service_account.json; Country=US; ASN=396982 GOOGLE-CLOUD-PLATFORM
show less
Bad Web Bot
๐ฎ๐น
[email protected]
2026-09-16 05:54:28
(4 days ago)
34.16.114.1 - - [16/Sep/2026:02:50:43 +0200] "GET /.env?raw HTTP/2.0" 404 269 "-" "Mozilla/5.0 (comp ...
show more
34.16.114.1 - - [16/Sep/2026:02:50:43 +0200] "GET /.env?raw HTTP/2.0" 404 269 "-" "Mozilla/5.0 (compatible; xAI-Grok/1.0; +https://x.ai/)"
show less
Web App Attack
Hacking
๐ณ๐ฑ
ConsulHosting
2026-09-16 05:46:36
(4 days ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack
๐ฉ๐ช
netclix.gr
2026-09-16 05:32:42
(4 days ago)
(aggressive_scan) Aggressive Web Exploit Scan 34.16.114.1 (US/United States/1.114.16.34.bc.googleuse ...
show more
(aggressive_scan) Aggressive Web Exploit Scan 34.16.114.1 (US/United States/1.114.16.34.bc.googleusercontent.com): 5 in the last 4600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 34.16.114.1 - - [16/Sep/2026:08:32:30 +0300] "GET /app_dev.php HTTP/2.0" 404 808 "-" "Mozilla/5.0 (compatible; PanguBot/1.0; +https://www.huaweicloud.com/)"
34.16.114.1 - - [16/Sep/2026:08:32:31 +0300] "GET /info.php HTTP/2.0" 404 808 "-" "Mozilla/5.0 (compatible; YiBot/1.0; +https://01.ai/)"
34.16.114.1 - - [16/Sep/2026:08:32:31 +0300] "GET /test.php HTTP/2.0" 404 808 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot)"
34.16.114.1 - - [16/Sep/2026:08:32:31 +0300] "GET /pi.php HTTP/2.0" 404 808 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
34.16.114.1 - - [16/Sep/2026:08:32:31 +0300] "GET /i.php HTTP/2.0" 404 808 "-" "Mozilla/5.0 (compatible; Bravebot/1.0; +https://brave.com/search/)"
show less
Port Scan
๐ฌ๐ง
openstrike.co.uk
2026-09-16 05:14:10
(4 days ago)
173 attacks on password/key grabbing URLs, env grabbing URLs (type 2), PHP URLs, env grabbing URLs, ...
show more
173 attacks on password/key grabbing URLs, env grabbing URLs (type 2), PHP URLs, env grabbing URLs, config grabbing URLs (type 2), directory traversals, VC URLs:
GET /id_dsa HTTP/1.1
GET /proc/self/cmdline HTTP/1.1
POST /icecoder/lib/terminal-xhr.php HTTP/1.1
GET /.env.docker HTTP/1.1
GET /src/amplifyconfiguration.json HTTP/1.1
GET /..%2f..%2f.env HTTP/1.1
GET /.git/HEAD HTTP/1.1
show less
Hacking
Web App Attack
๐ฉ๐ช
larse99
2026-09-16 05:11:56
(4 days ago)
Detected Scanning / Hacking activity
Port Scan
Hacking
๐ฉ๐ช
MarkGGN
2026-09-16 05:11:29
(4 days ago)
Web attack. 34.16.114.1 - - [16/Sep/2026:07:11:28 +0200] "GET /auth/login HTTP/2.0" 404 20 "-" "Mozi ...
show more
Web attack. 34.16.114.1 - - [16/Sep/2026:07:11:28 +0200] "GET /auth/login HTTP/2.0" 404 20 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36"
34.16.114.1 - - [16/Sep/2026:07:11:28 +0200] "GET /admin/login HTTP/2.0" 404 20 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36"
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 05:09:04
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.16.114.1 (1.114.16.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.16.114.1 (1.114.16.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 01:08:46.628872 2026] [security2:error] [pid 6761:tid 6761] [client 34.16.114.1:50566] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "l3l4.com"] [uri "/__vite_rsc_findSourceMapURL"] [unique_id "aqokXjflKaP59n0tBoiSLAAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
koinkash.org
2026-09-16 05:03:20
(4 days ago)
They are fraudulent. Malicious threat actor requesting php file /document.php
Web App Attack
Anonymous
2026-09-16 05:00:35
(4 days ago)
IncogNET WAF local CrowdSec decision. Scenario=crowdsecurity/http-path-traversal-probing; Action=ban ...
show more
IncogNET WAF local CrowdSec decision. Scenario=crowdsecurity/http-path-traversal-probing; Action=ban; Events=4; Hosts=incognet.io; Paths=/@fs/../.env?raw??,/_nuxt/../.env,/media../.env,/static../.env; Country=US; ASN=396982 GOOGLE-CLOUD-PLATFORM
show less
Port Scan
Web App Attack
๐ฌ๐ง
Mendip_Defender
2026-09-16 04:35:18
(4 days ago)
34.16.114.1 - - [16/Sep/2026:05:35:32 +0100] "GET /admin HTTP/1.1" 404 6497 "-" "Mozilla/5.0 (Linux; ...
show more
34.16.114.1 - - [16/Sep/2026:05:35:32 +0100] "GET /admin HTTP/1.1" 404 6497 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Mobile Safari/537.36"
34.16.114.1 - - [16/Sep/2026:05:35:32 +0100] "GET /admin/login HTTP/1.1" 404 6497 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Mobile Safari/537.36"
34.16.114.1 - - [16/Sep/2026:05:35:32 +0100] "GET /users/login HTTP/1.1" 404 6497 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Mobile Safari/537.36"
...
show less
Hacking
Web App Attack
Anonymous
2026-09-16 04:34:18
(4 days ago)
34.16.114.1 - - [16/Sep/2026:04:34:18 +0000] "GET /api/proc/self/environ HTTP/2.0" 404 64 "https:// ...
show more
34.16.114.1 - - [16/Sep/2026:04:34:18 +0000] "GET /api/proc/self/environ HTTP/2.0" 404 64 "https://ivonne.ca/api/w/admins/jobs_u/get_log_file/../../../../proc/self/environ" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; [email protected] )" "34.16.114.1" "-"
...
show less
Web App Attack