🇩🇪
pscriptos
2026-09-13 09:46:11
(4 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
🇫🇷
guillaume illien
2026-09-13 09:19:46
(4 hours ago)
34.181.159.199 - - [13/Sep/2026:09:19:46 +0000] "GET /..%2f.env HTTP/1.1" 400 166 "-" "-"
34.181.159 ...
show more
34.181.159.199 - - [13/Sep/2026:09:19:46 +0000] "GET /..%2f.env HTTP/1.1" 400 166 "-" "-"
34.181.159.199 - - [13/Sep/2026:09:19:46 +0000] "GET /%2e%2e/.env HTTP/1.1" 400 166 "-" "-"
34.181.159.199 - - [13/Sep/2026:09:19:46 +0000] "GET /..%2f..%2f.env HTTP/1.1" 400 166 "-" "-"
34.181.159.199 - - [13/Sep/2026:09:19:46 +0000] "GET /public/plugins/alertlist/../../../../../../../../proc/self/environ HTTP/1.1" 400 166 "-" "-"
34.181.159.199 - - [13/Sep/2026:09:19:46 +0000] "GET /api/uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2fproc/self/environ HTTP/1.1" 400 166 "-" "-"
34.181.159.199 - - [13/Sep/2026:09:19:46 +0000] "GET /api/uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f.env HTTP/1.1" 400 166 "-" "-"
34.181.159.199 - - [13/Sep/2026:09:19:46 +0000] "GET /uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f.env HTTP/1.1" 400 166 "-" "-"
...
show less
Hacking
Brute-Force
Web App Attack
SSH
🇫🇷
guillaume illien
2026-09-13 08:26:49
(5 hours ago)
34.181.159.199 - - [13/Sep/2026:08:26:47 +0000] "GET /..%2f.env HTTP/1.1" 400 166 "-" "-"
34.181.159 ...
show more
34.181.159.199 - - [13/Sep/2026:08:26:47 +0000] "GET /..%2f.env HTTP/1.1" 400 166 "-" "-"
34.181.159.199 - - [13/Sep/2026:08:26:48 +0000] "GET /%2e%2e/.env HTTP/1.1" 400 166 "-" "-"
34.181.159.199 - - [13/Sep/2026:08:26:48 +0000] "GET /..%2f..%2f.env HTTP/1.1" 400 166 "-" "-"
34.181.159.199 - - [13/Sep/2026:08:26:49 +0000] "GET /public/plugins/alertlist/../../../../../../../../proc/self/environ HTTP/1.1" 400 166 "-" "-"
34.181.159.199 - - [13/Sep/2026:08:26:49 +0000] "GET /api/uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f.env HTTP/1.1" 400 166 "-" "-"
34.181.159.199 - - [13/Sep/2026:08:26:49 +0000] "GET /api/uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2fproc/self/environ HTTP/1.1" 400 166 "-" "-"
34.181.159.199 - - [13/Sep/2026:08:26:49 +0000] "GET /icons/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/proc/self/environ HTTP/1.1" 400 166 "-" "-"
...
show less
Hacking
Brute-Force
Web App Attack
SSH
🇫🇷
IRISIO
2026-09-13 08:21:22
(5 hours ago)
scans/SQL injection/spam posts : 219 queries
Web App Attack
SQL Injection
🇩🇪
updown.io
2026-09-13 08:14:31
(5 hours ago)
{"level":"info","ts":1789287267.8724065,"logger":"http.log.access.log1","msg":"handled request","req ...
show more
{"level":"info","ts":1789287267.8724065,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"34.181.159.199","remote_port":"42628","client_ip":"34.181.159.199","proto":"HTTP/2.0","method":"GET","host":"admin.status.juicybeats.net","uri":"/.github/workflows/deploy.yml","headers":{"User-Agent":["Mozilla/5.0 (compatible; Bytespider; [email protected] ) AppleWebKit/537.36"],"Accept-Encoding":["gzip"],"Accept":["*/*"],"Cookie":["REDACTED"],"X-Middleware-Subrequest":["src/middleware:nowaf:src/middleware:src/middleware:src/middleware:src/middleware:middleware:middleware:nowaf:middleware:middleware:middleware:pages/_middleware"],"X-Nextjs-Data":["1"]},"tls":{"resumed":false,"version":772,"cipher_suite":4865,"proto":"h2","server_name":"admin.status.juicybeats.net","ech":false}},"bytes_read":0,"user_id":"","duration":0.000189852,"size":0,"status":429,"resp_headers":{"Server":["Caddy"],"Alt-Svc":["h3=\":443\"; ma=2592000"],"Retry-After":["1"]}}
{"level":"info
...
show less
DDoS Attack
Web App Attack
🇬🇧
noise.agency
2026-09-13 07:16:01
(6 hours ago)
34.181.159.199 (US/United States/199.159.181.34.bc.googleusercontent.com), more than 10 Apache 403 h ...
show more
34.181.159.199 (US/United States/199.159.181.34.bc.googleusercontent.com), more than 10 Apache 403 hits
show less
Hacking
🇺🇸
abenage
2026-09-13 07:04:32
(7 hours ago)
34.181.159.199 - - [13/Sep/2026:01:04:31 -0600] "GET /secure HTTP/2.0" 404 564 "-" "Mozilla/5.0 (Win ...
show more
34.181.159.199 - - [13/Sep/2026:01:04:31 -0600] "GET /secure HTTP/2.0" 404 564 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36 Edg/152.0.0.0"
show less
Bad Web Bot
Web App Attack
🇩🇪
raph
2026-09-13 06:18:30
(7 hours ago)
[PROTECTED PATHS] crawler credentials.ini, aws.ini, aws.yml, etc.
Bad Web Bot
Web App Attack
🇩🇪
pscriptos
2026-09-13 06:05:08
(8 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/appsec-vpatch
Web App Attack
🇩🇪
itsolon
2026-09-13 06:00:38
(8 hours ago)
[13/Sep/2026:08:00:36 +0200] 178927923691.546775 34.181.159.199 0 217.154.7.177 443
[13/Sep/2026:08: ...
show more
[13/Sep/2026:08:00:36 +0200] 178927923691.546775 34.181.159.199 0 217.154.7.177 443
[13/Sep/2026:08:00:38 +0200] 178927923829.356132 34.181.159.199 0 217.154.7.177 443
[13/Sep/2026:08:00:38 +0200] 178927923871.957503 34.181.159.199 0 217.154.7.177 443
[13/Sep/2026:08:00:38 +0200] 178927923861.924240 34.181.159.199 0 217.154.7.177 443
[13/Sep/2026:08:00:38 +0200] 17892792380.231085 34.181.159.199 0 217.154.7.177 443
...
show less
Port Scan
Hacking
Brute-Force
Web App Attack
🇫🇷
dynamix
2026-09-13 05:52:23
(8 hours ago)
Multiple WAF Violations
Web App Attack
🇩🇪
ghostwarriors
2026-09-13 05:50:07
(8 hours ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
🇩🇪
yitzhaq
2026-09-13 05:24:31
(8 hours ago)
34.181.159.199 - - [13/Sep/2026:07:24:28 +0200] "GET /dashboard%2F.env HTTP/2.0" 404 296 "-" "Mozill ...
show more
34.181.159.199 - - [13/Sep/2026:07:24:28 +0200] "GET /dashboard%2F.env HTTP/2.0" 404 296 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ChatGPT-User/1.0; +https://openai.com/bot)"
34.181.159.199 - - [13/Sep/2026:07:24:28 +0200] "POST /api/graphql HTTP/2.0" 404 296 "https://[site]" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36"
34.181.159.199 - - [13/Sep/2026:07:24:28 +0200] "GET /api%2F.env HTTP/2.0" 404 296 "-" "Mozilla/5.0 (compatible; xAI-Grok/1.0; +https://x.ai/)"
34.181.159.199 - - [13/Sep/2026:07:24:28 +0200] "GET /@fs/.env?url&raw?? HTTP/2.0" 404 296 "-" "Mozilla/5.0 (compatible; YouBot/1.0; +https://you.com/bot)"
34.181.159.199 - - [13/Sep/2026:07:24:28 +0200] "GET /settings%2F.env HTTP/2.0" 404 296 "-" "Mozilla/5.0 (compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot)"
34.181.159.199 - - [13/Sep/2026:07:24:28 +0200] "GET /manifestos/hovedisde.htm HTTP/2.0" 200 1332 "-
show less
Web App Attack
Hacking
🇳🇱
Savvii
2026-09-13 05:20:12
(8 hours ago)
20 attempts against mh-misbehave-ban on redirect
Brute-Force
Bad Web Bot
Web App Attack
🇨🇭
ca
2026-09-13 05:10:54
(9 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-path-traversal-probing
Web App Attack
Hacking