🇮🇩
sockominfo
2026-09-13 05:00:53
(2 hours ago)
Active Response: IP 34.186.122.25 Blocked via Firewall Drop. Threat Score: 3.9/10 (LOW). Confidence: ...
show more
Active Response: IP 34.186.122.25 Blocked via Firewall Drop. Threat Score: 3.9/10 (LOW). Confidence: 30%. CVSS v3.1: 0/10 (None). CVSS Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:N. Bayesian Probability: 34%. MITRE ATT&CK: T1016 (System Network Configuration Discovery). Tactic: TA0001. Freshness: Very Fresh. Source Reputation: UNKNOWN. Methodology: CVSS 3.1 + Bayesian + Temporal + Environmental + MITRE ATT&CK + OWASP. Standards: ISO/IEC 27065:2022, NIST SP 800-30, IEEE S&P 2020. Reported by TangerangKota-CSIRT
show less
Hacking
Web App Attack
🇺🇸
RAP
2026-09-13 01:14:34
(5 hours ago)
2026-09-13 01:14:34 UTC Unauthorized activity to TCP port 8443. Web App
Port Scan
Web App Attack
🇺🇸
Rip
2026-09-13 00:05:24
(7 hours ago)
Automated reconnaissance against web infrastructure.
Web App Attack
🇩🇪
kivitendo.de
2026-09-12 21:37:00
(9 hours ago)
[Sat Sep 12 23:37:07.175021 2026] [access_compat:error] [pid 159960:tid 159978] [client 34.186.122.2 ...
show more
[Sat Sep 12 23:37:07.175021 2026] [access_compat:error] [pid 159960:tid 159978] [client 34.186.122.25:35702] AH01797: client denied by server configuration: /var/www/kivitendo-erp/.git/HEAD
[Sat Sep 12 23:37:07.930833 2026] [access_compat:error] [pid 159959:tid 160009] [client 34.186.122.25:35784] AH01797: client denied by server configuration: /var/www/kivitendo-erp/config/.env
...
show less
Brute-Force
Web App Attack
🇳🇱
Savvii
2026-09-12 20:10:38
(10 hours ago)
15 attempts against mh-modsecurity-ban on pf221102
Brute-Force
Web App Attack
Anonymous
2026-09-12 20:02:59
(11 hours ago)
34.186.122.25 - - [12/Sep/2026:22:02:50 +0200] "GET /__aws_leak_probe_45bee873__ HTTP/1.1" 403 460 " ...
show more
34.186.122.25 - - [12/Sep/2026:22:02:50 +0200] "GET /__aws_leak_probe_45bee873__ HTTP/1.1" 403 460 "-" "Mozilla/5.0 (Linux; Android 15; SM-S918B) AppleWebKit/537.36 (KHTML, like Gecko; compatible; GrokBot/1.0; +https://x.ai/grokbot) Chrome/130.0.4132
show less
Web Spam
Blog Spam
Brute-Force
Web App Attack
🇧🇪
cmbplf
2026-09-12 17:38:04
(13 hours ago)
299 requests with url.path *.aws/*
255 requests with url.path */@fs/*
132 requests with url.path ...
show more
299 requests with url.path *.aws/*
255 requests with url.path */@fs/*
132 requests with url.path *credentials.json
125 requests with url.path *.azure/*
102 requests with url.path */proc/*
show less
Brute-Force
Bad Web Bot
🇳🇿
Antinson
2026-09-12 17:15:21
(13 hours ago)
Scraping with a high error ratio and request rate
Bad Web Bot
🇺🇸
IndigoRidge
2026-09-12 16:57:52
(14 hours ago)
34.186.122.25 - - [12/Sep/2026:12:57:49 -0400] "GET /media../.env HTTP/1.1" 404 37099 "-" "Mozilla/5 ...
show more
34.186.122.25 - - [12/Sep/2026:12:57:49 -0400] "GET /media../.env HTTP/1.1" 404 37099 "-" "Mozilla/5.0 (Linux; Android 14; Pixel 8) AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexity-user) Chrome/122.0.416.173 Mobile Safari/537.36"
34.186.122.25 - - [12/Sep/2026:12:57:50 -0400] "GET /static../.env HTTP/1.1" 404 37099 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Discordbot/2.0; +https://discordapp.com)"
34.186.122.25 - - [12/Sep/2026:12:57:50 -0400] "GET /@fs/root/.aws/credentials?raw?? HTTP/1.1" 404 37099 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:143.11) Gecko/20100101 Firefox/143.11; compatible; ChatGPT-User/1.0; +https://openai.com/bot"
...
show less
Web App Attack
Anonymous
2026-09-12 14:01:42
(17 hours ago)
denied traffic to a honeypot network. destination port 8443.
Port Scan
Hacking
🇺🇸
TPI-Abuse
2026-09-12 10:50:53
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.186.122.25 (25.122.186.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.186.122.25 (25.122.186.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 06:50:47.355778 2026] [security2:error] [pid 11448:tid 11448] [client 34.186.122.25:54492] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.151"] [uri "/static../.env"] [unique_id "aqUuh2TfFQeQ-mskUueiSgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
MPL
2026-09-12 09:49:18
(21 hours ago)
tcp/multiple (8 or more attempts)
Port Scan
🇩🇪
paissangroup
2026-09-12 09:14:04
(21 hours ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 08:37:35
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.186.122.25 (25.122.186.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.186.122.25 (25.122.186.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 04:37:28.053236 2026] [security2:error] [pid 26063:tid 26063] [client 34.186.122.25:1554] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.221"] [uri "/static../.env"] [unique_id "aqUPSKmfQoVqrHpJRhaj0AAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
myintarweb
2026-09-12 05:43:58
(1 day ago)
34.186.122.25 - - [12/Sep/2026:06:43:57 +0100] 443 "GET /.env.local HTTP/1.1" 403 2017 "-" "Mozilla/ ...
show more
34.186.122.25 - - [12/Sep/2026:06:43:57 +0100] 443 "GET /.env.local HTTP/1.1" 403 2017 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.3256.219 Safari/537.36 Edg/109.0.3256.219; compatible; meta-externalagent/1.1; +https://developers.facebook.com/docs/sharing/webmasters/crawler"
34.186.122.25 - - [12/Sep/2026:06:43:57 +0100] 443 "GET /.env HTTP/1.1" 403 2017 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/130.0.2797.162 Safari/537.36; compatible; GPTBot/1.4; +https://openai.com/gptbot"
34.186.122.25 - - [12/Sep/2026:06:43:57 +0100] 443 "GET /.env HTTP/1.1" 404 26692 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Applebot/0.1; +http://www.apple.com/go/applebot)"
...
show less
Hacking
Bad Web Bot
Web App Attack