ππΊ
DumaNet
2026-08-08 21:58:00
(1 month ago)
Web app attack attempts, scanning for vulnerability.
Date: 2026 Aug 08. 09:18:32
Source IP: 34.20. ...
show more
Web app attack attempts, scanning for vulnerability.
Date: 2026 Aug 08. 09:18:32
Source IP: 34.20.248.33
Portion of the log(s):
34.20.248.33 - [08/Aug/2026:09:18:32 +0200] "GET /id_ecdsa HTTP/1.1" 404 153 "-" "Mozilla/5.0 (compatible; cohere-ai/1.0; +https://cohere.com)"
34.20.248.33 - [08/Aug/2026:09:18:32 +0200] "GET /.env.backup HTTP/1.1" 404 153 "-" "Mozilla/5.0 (compatible; cohere-ai/1.0; +https://cohere.com)"
34.20.248.33 - [08/Aug/2026:09:18:32 +0200] "GET /.env.local HTTP/1.1" 404 153 "-" "Mozilla/5.0 (compatible; cohere-ai/1.0; +https://cohere.com)"
34.20.248.33 - [08/Aug/2026:09:18:32 +0200] "GET /.env.example HTTP/1.1" 404 153 "-" "Mozilla/5.0 (compatible; cohere-ai/1.0; +https://cohere.com)"
34.20.248.33 - [08/Aug/2026:09:18:32 +0200] "POST /v1/graphql HTTP/1.1" 404 555 "http://[removed].netbox.ovh" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36"
34.20.248.33 - [08/Aug/2026:09:18:32 +0200] "GET /.gitconfig HTTP/1.1" 404 153
show less
Web App Attack
ππΊ
DumaNet
2026-08-08 21:25:00
(1 month ago)
Web app attack attempts, scanning for vulnerability.
Date: 2026 Aug 08. 09:04:09
Source IP: 34.20. ...
show more
Web app attack attempts, scanning for vulnerability.
Date: 2026 Aug 08. 09:04:09
Source IP: 34.20.248.33
Portion of the log(s):
34.20.248.33 - [08/Aug/2026:09:04:09 +0200] "GET /server.key HTTP/1.1" 404 153 "-" "Mozilla/5.0 (compatible; cohere-ai/1.0; +https://cohere.com)"
34.20.248.33 - [08/Aug/2026:09:04:09 +0200] "GET /id_ed25519 HTTP/1.1" 404 153 "-" "Mozilla/5.0 (compatible; cohere-ai/1.0; +https://cohere.com)"
34.20.248.33 - [08/Aug/2026:09:04:09 +0200] "GET /id_ecdsa HTTP/1.1" 404 153 "-" "Mozilla/5.0 (compatible; cohere-ai/1.0; +https://cohere.com)"
34.20.248.33 - [08/Aug/2026:09:04:09 +0200] "GET /id_dsa HTTP/1.1" 404 153 "-" "Mozilla/5.0 (compatible; cohere-ai/1.0; +https://cohere.com)"
34.20.248.33 - [08/Aug/2026:09:04:09 +0200] "GET /id_rsa HTTP/1.1" 404 153 "-" "Mozilla/5.0 (compatible; cohere-ai/1.0; +https://cohere.com)"
34.20.248.33 - [08/Aug/2026:09:04:09 +0200] "GET /.vscode/launch.json HTTP/1.1" 404 153 "-" "Mozilla/5.0 (compatible; cohere-ai/1.0; +https://cohere.com)"
show less
Web App Attack
πΊπΈ
Lezetho
2026-08-08 16:00:21
(1 month ago)
DDoS, WebSpam, Web Attack, and Brute-force blocked by Cloudflare
DDoS Attack
Email Spam
Hacking
Brute-Force
π©πͺ
klaus_ph
2026-08-08 11:29:26
(1 month ago)
...
Bad Web Bot
π§πͺ
cmbplf
2026-08-08 09:27:55
(1 month ago)
218 requests with url.path *.env
105 requests with url.path *.ssh/*
Brute-Force
Bad Web Bot
π©πͺ
Lino Project
2026-08-08 07:48:12
(1 month ago)
CrowdSec abuse IP report (host SRV-2) Scenario: crowdsecurity/http-probing
Hacking
π΅π±
Budyn
2026-08-08 07:41:48
(1 month ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit Block. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: budyn.ovh | URI: /config/.env | UA: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; Claude-SearchBot/1.0; +mailto:[email protected] | BODY: [Empty / GET Request]
show less
Hacking
Web App Attack
π©πͺ
maxpower
2026-08-08 07:22:18
(1 month ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 34.20.248.33 (US/United States/33.248.20 ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 34.20.248.33 (US/United States/33.248.20.34.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 34.20.248.33 - - [08/Aug/2026:09:22:12 +0200] "GET /.aws/credentials HTTP/2.0" 429 41 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; Claude-User/1.0; +mailto:[email protected] " "-" host=mail.frleone.ovh
show less
Port Scan
π§πͺ
Saec
2026-08-08 07:16:01
(1 month ago)
Jarvis auto-ban: CF top attacker on saec.ovh (27 hits, US)
Port Scan
Web App Attack
π©πͺ
maxpower
2026-08-08 07:03:46
(1 month ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 34.20.248.33 (US/United States/33.248.20 ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 34.20.248.33 (US/United States/33.248.20.34.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 34.20.248.33 - - [08/Aug/2026:09:03:40 +0200] "GET /secrets.json HTTP/2.0" 429 41 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ClaudeBot/1.0; +mailto:[email protected] " "-" host=mail.elektra.ovh
show less
Port Scan
π΅π±
srebrakowski.com
2026-08-08 06:54:08
(1 month ago)
crowdsec/crowdsecurity/appsec-vpatch
Brute-Force
π΅π±
Roper123
2026-08-08 06:52:59
(1 month ago)
Web app attack
Web App Attack
π³π±
WeCloudit-Anti-Abuse
2026-08-08 06:48:23
(1 month ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
π«π·
Nop Nop
2026-08-08 06:45:36
(1 month ago)
CrowdSec ban: crowdsecurity/http-probing
Port Scan
πΊπΈ
RamSet
2026-08-08 06:43:05
(1 month ago)
[swy] HTTP-Probe on port 443 (via domain). 246 distinct paths probed in 8s. Sustained 252 req/min, 2 ...
show more
[swy] HTTP-Probe on port 443 (via domain). 246 distinct paths probed in 8s. Sustained 252 req/min, 230 nonexistent paths (404). Paths: /.aws/credentials, /.aws/config, /.git/config, /.git-credentials, /.git/HEAD, /.env, /.env.example, /.env.production, /.env.backup, /.env.local, /api/.env, /.env.bak, /.env.old, /config/.env, /backend/.env, /admin/.env, /.github/.env, /.htpasswd, /.vscode/launch.json, /.svn/entries, /.ssh/id_rsa, /.ssh/id_ed25519, /.ssh/config, /.ssh/id_ecdsa, /.ssh/authorized_keys, /.ssh/id_dsa, /.ssh/known_hosts, /.openclaw/.env, /.hermes/.env, /wp-config.php.bak, /wp-config.php.old, /config/.env.php, /laravel/.env, /.env.php.bak, /core/.env, /.env.dev, /public/.env, /.env.swp, /web/.env, /actuator/env, /.env.test, /.env.staging, /config.env, /.env.development, /sendgrid.env, /app/.env, /frontend/.env, /src/.env, /dev/.env, /server/.env, /production/.env, /docker/.env, /.env.docker, /.env.production.bak, /.env.prod.bak, /staging/.env, /@fs/.env?raw??, β¦
show less
Bad Web Bot
Web App Attack