Anonymous
2026-09-21 18:52:09
(1 day ago)
WordPress Sensitive System Files Information Disclosure.
Hacking
๐ฎ๐ฑ
spd.co.il
2026-09-19 04:02:23
(3 days ago)
Web application attack detected
Hacking
Web App Attack
Anonymous
2026-09-18 06:29:40
(4 days ago)
IP banned by Fail2Ban due to multiple malicious requests on Nginx
Brute-Force
SSH
Web App Attack
๐ฎ๐ณ
evicky2002
2026-09-18 06:00:02
(4 days ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
Anonymous
2026-09-17 06:18:47
(5 days ago)
Web directory scan: 10 requests in 20s (Last path: '/static../.azure/credentials').
Hacking
Web App Attack
๐จ๐ญ
dalslab ltd
2026-09-17 06:11:21
(5 days ago)
34.204.194.129 - - [17/Sep/2026:08:11:11 +0200] "GET /assets../../../etc/passwd HTTP/1.1" 400 154 "- ...
show more
34.204.194.129 - - [17/Sep/2026:08:11:11 +0200] "GET /assets../../../etc/passwd HTTP/1.1" 400 154 "-" "-"
34.204.194.129 - - [17/Sep/2026:08:11:19 +0200] "POST /proxy HTTP/1.1" 405 556 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko; compatible; Amzn-SearchBot/1.0; +https://developer.amazon.com/support/amazonbot) Chrome/91.0.4655.194 Safari/537.36 Edg/91.0.4655.194"
34.204.194.129 - - [17/Sep/2026:08:11:19 +0200] "POST /api/fetch HTTP/1.1" 405 556 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.3794.64 Safari/537.36 Edg/109.0.3794.64; compatible; ClaudeBot/1.0; [email protected] "
34.204.194.129 - - [17/Sep/2026:08:11:19 +0200] "POST /api/preview HTTP/1.1" 405 556 "-" "Mozilla/5.0 (Windows NT 11.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko; compatible; facebookexternalhit/1.1; +http://www.facebook.com/externalhit_uatext.php) Chrome/120.0.494.13 Safari/537.36"
34.204.194.129 - - [17/Sep/2
...
show less
Web Spam
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-17 06:11:11
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 34.204.194.129 (ec2-34-204-194-129.compute-1.am ...
show more
(mod_security) mod_security (id:210492) triggered by 34.204.194.129 (ec2-34-204-194-129.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 02:11:07.580575 2026] [security2:error] [pid 25984:tid 25984] [client 34.204.194.129:9196] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.168"] [uri "/static../.env"] [unique_id "aquEe6230nCAAmyOQdVoFQAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ญ๐ท
vzderic
2026-09-17 06:11:00
(5 days ago)
Bad Web Bot
Web App Attack
๐บ๐ธ
jormaster3k
2026-09-17 06:05:11
(5 days ago)
Attack against Apache (too many 404s)
Web App Attack
๐ฌ๐ง
E_Y soc
2026-09-17 06:02:00
(5 days ago)
Vite Arbitrary File Read
Web App Attack
Port Scan
Anonymous
2026-09-17 05:51:12
(5 days ago)
Bot / seems abusive / Apache connections: 33
DDoS Attack
Web Spam
Bad Web Bot
Web App Attack
๐ฆ๐น
piqwjdas
2026-09-17 05:09:05
(5 days ago)
{"transaction":{"client_ip":"34.204.194.129","time_stamp":"Thu Sep 17 07:08:54 2026","server_id":"46 ...
show more
{"transaction":{"client_ip":"34.204.194.129","time_stamp":"Thu Sep 17 07:08:54 2026","server_id":"46824fc494f03034e6b98e26d7a2d7a06b25f0b7","client_port":12530,"host_ip":"212.186.116.154","host_port":80,"unique_id":"178962173421.904707","is_interrupted":false,"request":{"method":"GET","http_version":"1.1","hostname":"212.186.116.154","uri":"/","headers":{"User-Agent":"Mozilla/5.0 (X11; Linux x86_64; rv:133.1) Gecko/20100101 Firefox/133.1; compatible; Applebot/0.1; +http://www.apple.com/go/applebot","Host":"212.186.116.154:80","Accept-Encoding":"gzip","Connection":"close"}},"response":{"http_code":403,"headers":{"Server":"nginx\u0000","Date":"Thu, 17 Sep 2026 05:08:54 GMT","Content-Length":"146","Content-Type":"text/html","Connection":"close"}},"producer":{"modsecurity":"ModSecurity v3.0.16 (Linux)","connector":"ModSecurity-nginx v1.0.4","secrules_engine":"Enabled","components":["OWASP_CRS/4.30.0-dev\""]},"messages":[{"message":"Host header is a numeric IP address","details":{"match":"M
...
show less
Web App Attack
๐ฉ๐ช
jotoma.de
2026-09-17 05:03:14
(5 days ago)
[Thu Sep 17 07:02:29.564375 2026] [authz_core:error] [pid 761466:tid 761546] [client 34.204.194.129: ...
show more
[Thu Sep 17 07:02:29.564375 2026] [authz_core:error] [pid 761466:tid 761546] [client 34.204.194.129:44506] AH01630: client denied by server configuration: /var/www/analytics.jotoma.de/config/.env
[Thu Sep 17 07:02:36.168217 2026] [authz_core:error] [pid 761466:tid 761552] [client 34.204.194.129:44506] AH01630: client denied by server configuration: /var/www/analytics.jotoma.de/config
[Thu Sep 17 07:03:13.809387 2026] [authz_core:error] [pid 761465:tid 761558] [client 34.204.194.129:12108] AH01630: client denied by server configuration: /var/www/analytics.jotoma.de/config/jenkins.xml
...
show less
Web Spam
Brute-Force
๐จ๐ฆ
internetworld
2026-09-17 05:02:21
(5 days ago)
34.204.194.129 - - [17/Sep/2026:05:02:19 +0000] "GET /static../.env HTTP/1.1" 200 326 "-" "Mozilla/5 ...
show more
34.204.194.129 - - [17/Sep/2026:05:02:19 +0000] "GET /static../.env HTTP/1.1" 200 326 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14_5) AppleWebKit/537.36 (KHTML, like Gecko; compatible; TelegramBot/1.0) Chrome/133.0.8916.215 Safari/537.36 Edg/133.0.8916.215"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
donarev419
2026-09-17 05:02:09
(5 days ago)
Connection to port 3000 with data transfer.
Data preview: GET / HTTP/1.1
User-Agent: Mozilla/5.0 (W ...
show more
Connection to port 3000 with data transfer.
Data preview: GET / HTTP/1.1
User-Agent: Mozilla/5.0 (Windows NT 11.0; Win64; x64) AppleWebKit/537.36 (KHTML, lik
show less
Port Scan
Hacking