Anonymous
2026-09-25 22:21:13
(15 minutes ago)
34.21.109.29 - - [25/Sep/2026:19:21:11 -0300] "GET /actuator/env HTTP/2.0" 444 0 "-" "Mozilla/5.0 (c ...
show more
34.21.109.29 - - [25/Sep/2026:19:21:11 -0300] "GET /actuator/env HTTP/2.0" 444 0 "-" "Mozilla/5.0 (compatible; PanguBot/1.0; +https://www.huaweicloud.com/)"
34.21.109.29 - - [25/Sep/2026:19:21:12 -0300] "POST /api/graphql HTTP/2.0" 404 548 "https://topvitrine.com.br" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36"
34.21.109.29 - - [25/Sep/2026:19:21:12 -0300] "GET /actuator/beans HTTP/2.0" 444 0 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot"
34.21.109.29 - - [25/Sep/2026:19:21:12 -0300] "GET /actuator/mappings HTTP/2.0" 444 0 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot"
34.21.109.29 - - [25/Sep/2026:19:21:12 -0300] "GET /actuator/configprops HTTP/2.0" 444 0 "-" "Mozilla/5.0 (compatible; MoonshotBot/1.0; +https://kimi.ai/)"
...
show less
Port Scan
๐ฌ๐ง
consul.to
2026-09-25 18:07:32
(4 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐ง๐ท
Halux
2026-09-25 16:24:33
(6 hours ago)
34.21.109.29 Probing protected path or service
Web App Attack
๐บ๐ธ
agenciahypelab.com.br
2026-09-25 14:49:46
(7 hours ago)
WordPress login brute-force detectado e bloqueado pelo CSF/LFD. Trigger: LF_TRIGGER
Brute-Force
SSH
๐ง๐ท
dermatovirtual
2026-09-25 07:21:54
(15 hours ago)
Dermato Virtual CSIRT: Malicious web exploit/scanning probes against app.dermatovirtual.com.br (Web ...
show more
Dermato Virtual CSIRT: Malicious web exploit/scanning probes against app.dermatovirtual.com.br (Web Server Ports 80/443). 20 unauthorized requests recorded between 2026-09-24 07:15:43 UTC and 2026-09-24 07:15:47 UTC (rate: ~20 req/min). Edge perimeter firewall drop active.
Log sample:
[2026-09-24 07:15:45 UTC] IP: 34.21.109.29 - W3C IIS (Port 443): GET /web/.env -> HTTP 404 [CLIENT: 34.21.109.29]
[2026-09-24 07:15:45 UTC] IP: 34.21.109.29 - W3C IIS (Port 443): GET /server/.env -> HTTP 404 [CLIENT: 34.21.109.29]
[2026-09-24 07:15:45 UTC] IP: 34.21.109.29 - W3C IIS (Port 443): GET /.next/.env -> HTTP 404 [CLIENT: 34.21.109.29]
show less
Bad Web Bot
Web App Attack
๐ง๐ท
Peregrine
2026-09-25 03:10:09
(19 hours ago)
Fail2Ban Jail: tomcat-honeypot | Evidence: 34.21.109.29 104.23.209.69 - - [23/Sep/2026:10:56:34 -030 ...
show more
Fail2Ban Jail: tomcat-honeypot | Evidence: 34.21.109.29 104.23.209.69 - - [23/Sep/2026:10:56:34 -0300] "GET /document.php?modulepart=systemtools&file=../conf/conf.php&hashp=shared HTTP/1.1" 404 414
34.21.109.29 104.23.209.69 - - [23/Sep/2026:10:56:37 -0300] "GET /.env?raw HTTP/1.1" 404 414
34.21.109.29 104.23.209.68 - - [23/Sep/2026:10:56:37 -0300] "GET /.env?import&raw HTTP/1.1" 404 414
show less
Bad Web Bot
๐ฉ๐ช
niedson
2026-09-24 13:30:02
(1 day ago)
Automated scanning for exposed secrets: repeated requests for multiple distinct credential paths (.e ...
show more
Automated scanning for exposed secrets: repeated requests for multiple distinct credential paths (.env variants, .git metadata, .ssh private keys, .aws/credentials). Unsolicited. Reported automatically.
show less
Web App Attack
๐ช๐ธ
pipeline.es
2026-09-24 08:58:37
(1 day ago)
Web scanning / probing for vulnerable paths
Port Scan
Web App Attack
๐ง๐ท
dermatovirtual
2026-09-24 07:19:58
(1 day ago)
Dermato Virtual CSIRT: Malicious web exploit/scanning probes against app.dermatovirtual.com.br (Web ...
show more
Dermato Virtual CSIRT: Malicious web exploit/scanning probes against app.dermatovirtual.com.br (Web Server Ports 80/443). 20 unauthorized requests recorded between 2026-09-24 07:15:43 UTC and 2026-09-24 07:15:47 UTC (rate: ~20 req/min). Edge perimeter firewall drop active.
Log sample:
[2026-09-24 07:15:45 UTC] IP: 34.21.109.29 - W3C IIS (Port 443): GET /web/.env -> HTTP 404 [CLIENT: 34.21.109.29]
[2026-09-24 07:15:45 UTC] IP: 34.21.109.29 - W3C IIS (Port 443): GET /server/.env -> HTTP 404 [CLIENT: 34.21.109.29]
[2026-09-24 07:15:45 UTC] IP: 34.21.109.29 - W3C IIS (Port 443): GET /.next/.env -> HTTP 404 [CLIENT: 34.21.109.29]
show less
Bad Web Bot
Web App Attack
๐ง๐ท
dominioz
2026-09-24 06:29:17
(1 day ago)
2026-09-24 06:27:49 GET /.env - - 34.21.109.29 HTTP/1.1 Mozilla/5.0+(compatible;+cohere-ai;++https:/ ...
show more
2026-09-24 06:27:49 GET /.env - - 34.21.109.29 HTTP/1.1 Mozilla/5.0+(compatible;+cohere-ai;++https://cohere.com/crawler) - 301 467
...
show less
Brute-Force
Web App Attack
๐ง๐ท
SvrAdmin
2026-09-24 05:45:23
(1 day ago)
[204] (cpanel) Failed cPanel login from 34.21.109.29 (US/United States/29.109.21.34.bc.googleusercon ...
show more
[204] (cpanel) Failed cPanel login from 34.21.109.29 (US/United States/29.109.21.34.bc.googleusercontent.com): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CPANEL; Logs: [2026-09-24 02:45:15 -0300] info [cpaneld] 34.21.109.29 - - "GET /5eocdhnps2v7xxmvlhwk HTTP/1.1" FAILED LOGIN cpaneld: login attempt without username
[2026-09-24 02:45:15 -0300] info [cpaneld] 34.21.109.29 - - "GET /assets/manifest.json HTTP/1.1" FAILED LOGIN cpaneld: login attempt without username
[2026-09-24 02:45:15 -0300] info [cpaneld] 34.21.109.29 - - "GET /webpack-stats.json HTTP/1.1" FAILED LOGIN cpaneld: login attempt without username
[2026-09-24 02:45:15 -0300] info [cpaneld] 34.21.109.29 - - "GET /z9x8c7v6b5-debug-trigger-cpanel.portaldebeltrao.com.br HTTP/1.1" FAILED LOGIN cpaneld: login attempt without username
[2026-09-24 02:45:17 -0300] info [cpaneld] 34.21.109.29 - - "GET /@fs/src/.env?raw?? HTTP/1.1" FAILED LOGIN cpaneld: login attempt without username
show less
Port Scan
Hacking
Brute-Force
Exploited Host
๐ง๐ท
govfacil.app
2026-09-24 05:08:36
(1 day ago)
(cpanel) Failed cPanel login from 34.21.109.29 (US/United States/29.109.21.34.bc.googleusercontent.c ...
show more
(cpanel) Failed cPanel login from 34.21.109.29 (US/United States/29.109.21.34.bc.googleusercontent.com): 50 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CPANEL; Logs: [2026-09-24 02:08:23 -0300] info [cpaneld] 34.21.109.29 - - "GET /abcsfs09w2qxr6k24psg HTTP/1.1" FAILED LOGIN cpaneld: login attempt without username
[2026-09-24 02:08:24 -0300] info [cpaneld] 34.21.109.29 - - "GET /.env.local HTTP/1.1" FAILED LOGIN cpaneld: login attempt without username
[2026-09-24 02:08:24 -0300] info [cpaneld] 34.21.109.29 - - "GET /.env.backup HTTP/1.1" FAILED LOGIN cpaneld: login attempt without username
[2026-09-24 02:08:24 -0300] info [cpaneld] 34.21.109.29 - - "GET /.env.bak HTTP/1.1" FAILED LOGIN cpaneld: login attempt without username
[2026-09-24 02:08:24 -0300] info [cpaneld] 34.21.109.29 - - "GET /.env.production HTTP/1.1" FAILED LOGIN cpaneld: login attempt without username
[2026-09-24 02:08:24 -0300] info [cpaneld] 34.21.109.29 - - "POST /api/graphql HTTP/1.1" FAILED LOGIN [truncated]
show less
Brute-Force
Anonymous
2026-09-24 04:31:36
(1 day ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
Anonymous
2026-09-24 01:30:46
(1 day ago)
Spring Cloud Function Remote Code Execution (CVE-2022-22963).
Web App Attack
๐ฌ๐ง
consul.to
2026-09-23 17:03:06
(2 days ago)
Web attack/malicious scanning detected
Web App Attack