🇨🇦
Mediashaker
2026-08-29 20:23:07
(19 hours ago)
(CT) IP 34.16.228.47 (US/United States/47.228.16.34.bc.googleusercontent.com) found to have 649 conn ...
show more
(CT) IP 34.16.228.47 (US/United States/47.228.16.34.bc.googleusercontent.com) found to have 649 connections
show less
DDoS Attack
🇩🇪
gadix
2026-08-29 20:04:10
(19 hours ago)
[29/Aug/2026:22:04:07.514119 +0200] apM7N16D-YwRYTr2msLCNAAAAAk 34.16.228.47 43376 127.0.0.1 7081
[2 ...
show more
[29/Aug/2026:22:04:07.514119 +0200] apM7N16D-YwRYTr2msLCNAAAAAk 34.16.228.47 43376 127.0.0.1 7081
[29/Aug/2026:22:04:07.691564 +0200] apM7N0Y8mFcL-yhHbzi0kQAAAAM 34.16.228.47 43392 127.0.0.1 7081
[29/Aug/2026:22:04:07.866606 +0200] apM7N5iNcSOYkeqXlprxlgAAAAI 34.16.228.47 43424 127.0.0.1 7081
...
show less
Web App Attack
Anonymous
2026-08-29 16:54:00
(23 hours ago)
Event Type: Attempted Administrator Privilege Gain
Signature: ET WEB_SPECIFIC_APPS Vite Arbitrary F ...
show more
Event Type: Attempted Administrator Privilege Gain
Signature: ET WEB_SPECIFIC_APPS Vite Arbitrary File Read Via raw parameter (CVE-2025-30208)
Severity: high
Source IP: 34.16.228.47
Event Type: Web Application Attack
Signature: ET HUNTING HTTP URI Path Normalization Bypasses & Escapes M1
Severity: high
Source IP: 34.16.228.47
show less
Web App Attack
Hacking
🇫🇷
Stara
2026-08-29 14:11:36
(1 day ago)
ModSecurity detected web attack - .env/config probing or SQLi/Code injection (Rule 949110)
Brute-Force
SSH
Web App Attack
🇺🇸
Mainpine
2026-08-29 12:43:46
(1 day ago)
[Sat Aug 29 12:43:43.858430 2026] [proxy_fcgi:error] [pid 3651845:tid 3651962] [client 34.16.228.47: ...
show more
[Sat Aug 29 12:43:43.858430 2026] [proxy_fcgi:error] [pid 3651845:tid 3651962] [client 34.16.228.47:41330] AH01071: Got error 'Primary script unknown'
[Sat Aug 29 12:43:45.382837 2026] [proxy_fcgi:error] [pid 3651888:tid 3652017] [client 34.16.228.47:41472] AH01071: Got error 'Primary script unknown'
[Sat Aug 29 12:43:45.398785 2026] [proxy_fcgi:error] [pid 3651888:tid 3651999] [client 34.16.228.47:41514] AH01071: Got error 'Primary script unknown'
...
show less
Web App Attack
🇳🇿
Antinson
2026-08-29 12:27:45
(1 day ago)
Scraping with a high error ratio and request rate
Bad Web Bot
Anonymous
2026-08-29 08:20:04
(1 day ago)
| A web attack returned code 200 (success).
Web App Attack
Hacking
SQL Injection
🇸🇪
Esko
2026-08-28 22:03:17
(1 day ago)
34.16.228.47 - - [28/Aug/2026:22:03:17 +0000] "GET /static../.env HTTP/1.1" 488 0 "-" "Mozilla/5.0 ( ...
show more
34.16.228.47 - - [28/Aug/2026:22:03:17 +0000] "GET /static../.env HTTP/1.1" 488 0 "-" "Mozilla/5.0 (Linux; Android 15; SM-S918B) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.5557.192 Mobile Safari/537.36; compatible; GPTBot/1.4; +https://openai.com/gptbot"
show less
Web App Attack
🇩🇪
Nightreaver
2026-08-28 21:43:29
(1 day ago)
34.16.228.47 - - [28/Aug/2026:23:43:29 0200] "GET /aws/credentials HTTP/1.1" 404 438 "-" "Mozilla/5 ...
show more
34.16.228.47 - - [28/Aug/2026:23:43:29 0200] "GET /aws/credentials HTTP/1.1" 404 438 "-" "Mozilla/5.0 (compatible; Slackbot-LinkExpanding/1.0; https://api.slack.com/robots)"
34.16.228.47 - - [28/Aug/2026:23:43:29 0200] "GET /@fs/root/.aws/credentials?raw?? HTTP/1.1" 404 438 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ChatGPT-User/1.0; https://openai.com/bot)"
34.16.228.47 - - [28/Aug/2026:23:43:29 0200] "GET /@fs/home/ec2-user/.aws/credentials?raw?? HTTP/1.1" 404 438 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:150.7) Gecko/20100101 Firefox/150.7; compatible; Applebot/0.1; http://www.apple.com/go/applebot"
34.16.228.47 - - [28/Aug/2026:23:43:29 0200] "GET /media../etc/passwd HTTP/1.1" 404 438 "-" "Mozilla/5.0 (compatible; GrokBot/1.0; https://x.ai/grokbot)"
34.16.228.47 - - [28/Aug/2026:23:43:29 0200] "GET /@fs/proc/self/environ?raw?? HTTP/1.1" 404 438 "-" "Mozilla/5.0 (compatible; facebookexternalhit/1.1; http://www.facebook.com/externalhit_uatext.php)"[...]
show less
Bad Web Bot
Web App Attack
🇩🇪
juutis
2026-08-28 21:43:12
(1 day ago)
Multiple WAF abuses - IP blocked
Hacking
Brute-Force
Web App Attack
🇪🇸
pipeline.es
2026-08-28 21:35:55
(1 day ago)
Web scanning / probing for vulnerable paths | URL: /.aws/credentials~ | Evidence: portadembarque.com ...
show more
Web scanning / probing for vulnerable paths | URL: /.aws/credentials~ | Evidence: portadembarque.com 34.16.228.47 - - [28/Aug/2026:23:34:13 +0200] \"GET /.aws/credentials~ HTTP/1.1\" 404 20958 \"http://213.201.48.218:80/.aws/credentials~\" \"Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexity-user)\" GEOIP_COUNTRY_CODE=US | ASN: GOOGLE-CLOUD-PLATFORM | Country: US
show less
Port Scan
Web App Attack
🇫🇷
omartin
2026-08-28 21:10:00
(1 day ago)
Critical Vulnerability Scan detected
Hacking
Brute-Force
Exploited Host
Web App Attack
🇺🇸
decisionconcepts
2026-08-28 20:05:03
(1 day ago)
34.16.228.47 - - [28/Aug/2026:13:05:01 -0700] "GET /static../.env HTTP/1.1" 403 199 "-" "Mozilla/5.0 ...
show more
34.16.228.47 - - [28/Aug/2026:13:05:01 -0700] "GET /static../.env HTTP/1.1" 403 199 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko; compatible; GrokBot/1.0; +https://x.ai/grokbot) Chrome/126.0.2266.41 Safari/537.36 Edg/126.0.2266.41"
34.16.228.47 - - [28/Aug/2026:13:05:01 -0700] "GET /media../.env HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; Twitterbot/1.0)"
show less
Brute-Force
SSH
Anonymous
2026-08-28 18:50:33
(1 day ago)
Unauthorised traffic to honeypot
Port Scan
🇭🇰
i553041
2026-08-28 18:30:28
(1 day ago)
34.16.228.47 - - [29/Aug/2026:02:30:27 +0800] "GET /.env.local HTTP/1.1" 301 169 "-" "Mozilla/5.0 Ap ...
show more
34.16.228.47 - - [29/Aug/2026:02:30:27 +0800] "GET /.env.local HTTP/1.1" 301 169 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; OAI-SearchBot/1.3; +https://openai.com/searchbot)" "-"
34.16.228.47 - - [29/Aug/2026:02:30:27 +0800] "GET /@fs/etc/passwd?import&raw?? HTTP/1.1" 301 169 "-" "Mozilla/5.0 (compatible; GPTBot/1.4; +https://openai.com/gptbot)" "-"
34.16.228.47 - - [29/Aug/2026:02:30:27 +0800] "GET /.mcp.json HTTP/1.1" 301 169 "-" "Mozilla/5.0 (compatible; TelegramBot/1.0)" "-"
34.16.228.47 - - [29/Aug/2026:02:30:27 +0800] "GET /media../etc/passwd HTTP/1.1" 301 169 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14_5) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.0 Safari/605.1.15; compatible; GrokBot/1.0; +https://x.ai/grokbot" "-"
34.16.228.47 - - [29/Aug/2026:02:30:27 +0800] "GET /?file=../../../../etc/passwd HTTP/1.1" 301 169 "-" "Mozilla/5.0 (compatible; Slackbot-LinkExpanding/1.0; +https://api.slack.com/robots)" "-"
...
show less
Brute-Force
SSH