๐ง๐ท
Peregrine
2026-09-25 03:15:06
(1 hour ago)
Fail2Ban ct101 Jail: tomcat-honeypot | Evidence: 34.21.139.194 172.70.93.102 - - [23/Sep/2026:22:51: ...
show more
Fail2Ban ct101 Jail: tomcat-honeypot | Evidence: 34.21.139.194 172.70.93.102 - - [23/Sep/2026:22:51:05 -0300] "GET /config/.env HTTP/1.1" 404 18149
show less
Bad Web Bot
๐ง๐ท
dominioz
2026-09-24 16:38:17
(11 hours ago)
2026-09-24 16:38:08 GET /.env.save - - 34.21.139.194 HTTP/2 Mozilla/5.0+(compatible;+cohere-ai;++htt ...
show more
2026-09-24 16:38:08 GET /.env.save - - 34.21.139.194 HTTP/2 Mozilla/5.0+(compatible;+cohere-ai;++https://cohere.com/crawler) - 301 540
...
show less
Brute-Force
Web App Attack
๐ฉ๐ช
niedson
2026-09-24 14:00:04
(14 hours ago)
Automated scanning for exposed secrets: repeated requests for multiple distinct credential paths (.e ...
show more
Automated scanning for exposed secrets: repeated requests for multiple distinct credential paths (.env variants, .git metadata, .ssh private keys, .aws/credentials). Unsolicited. Reported automatically.
show less
Web App Attack
๐บ๐ธ
agenciahypelab.com.br
2026-09-24 13:25:21
(15 hours ago)
WordPress login brute-force detectado e bloqueado pelo CSF/LFD. Trigger: LF_TRIGGER
Brute-Force
SSH
๐ช๐ธ
pipeline.es
2026-09-24 08:41:03
(19 hours ago)
Web scanning / probing for vulnerable paths | URL: /auth | Evidence: geaweb.com.br 34.21.139.194 - - ...
show more
Web scanning / probing for vulnerable paths | URL: /auth | Evidence: geaweb.com.br 34.21.139.194 - - [24/Sep/2026:10:40:24 +0200] \"GET /auth HTTP/2.0\" 404 22210 \"-\" \"Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Mobile Safari/537.36\" GEOIP_COUNTRY_CODE=SG | ASN: GOOGLE-CLOUD-PLATFORM | Country: SG
show less
Port Scan
Web App Attack
Anonymous
2026-09-24 04:31:32
(1 day ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
๐ซ๐ท
mrcrassi
2026-09-24 02:19:00
(1 day ago)
Triggered Cloudflare WAF (firewallManaged) from SG.
Action taken: BLOCK
Protocol: HTTP/2 (POST metho ...
show more
Triggered Cloudflare WAF (firewallManaged) from SG.
Action taken: BLOCK
Protocol: HTTP/2 (POST method)
Endpoint: /api
UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Safari/605.1.15 (Applebot/0.1)
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ง๐ท
Peregrine
2026-09-24 01:51:07
(1 day ago)
Fail2Ban ct101 Jail: tomcat-404 | Evidence: 34.21.139.194 172.70.93.103 - - [23/Sep/2026:22:51:02 -0 ...
show more
Fail2Ban ct101 Jail: tomcat-404 | Evidence: 34.21.139.194 172.70.93.103 - - [23/Sep/2026:22:51:02 -0300] "GET /dist/.vite/manifest.json HTTP/1.1" 404 18149
34.21.139.194 172.70.93.103 - - [23/Sep/2026:22:51:02 -0300] "GET /zmtp7pbio7vt0p0queen HTTP/1.1" 404 18149
34.21.139.194 172.70.93.103 - - [23/Sep/2026:22:51:03 -0300] "GET /build/manifest.json HTTP/1.1" 404 18149
34.21.139.194 172.70.93.103 - - [23/Sep/2026:22:51:03 -0300] "GET /z9x8c7v6b5-debug-trigger-decise.com.br HTTP/1.1" 404 18149
34.21.139.194 172.70.93.103 - - [23/Sep/2026:22:51:04 -0300] "GET /rclone.conf HTTP/1.1" 404 18149
show less
Bad Web Bot
Web App Attack
๐ช๐ธ
pipeline.es
2026-09-24 00:03:28
(1 day ago)
Web scanning / probing for vulnerable paths | URL: /online/condicoes-gerais-da-venda.htm | Evidence: ...
show more
Web scanning / probing for vulnerable paths | URL: /online/condicoes-gerais-da-venda.htm | Evidence: escalaturismo.com.br 34.21.139.194 - - [24/Sep/2026:02:03:00 +0200] \"GET /online/condicoes-gerais-da-venda.htm HTTP/2.0\" 404 21712 \"-\" \"Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36\" GEOIP_COUNTRY_CODE=SG | ASN: GOOGLE-CLOUD-PLATFORM | Country: SG
show less
Port Scan
Web App Attack
๐ง๐ท
Halux
2026-09-23 23:53:22
(1 day ago)
34.21.139.194 Web Application Firewall multiple violations
Hacking
Web App Attack
๐ช๐ธ
pipeline.es
2026-09-23 23:43:05
(1 day ago)
Web scanning / probing for vulnerable paths | URL: /online/destinos-internacionais.htm | Evidence: e ...
show more
Web scanning / probing for vulnerable paths | URL: /online/destinos-internacionais.htm | Evidence: evoluirturismo.com.br 34.21.139.194 - - [24/Sep/2026:01:42:49 +0200] \"GET /online/destinos-internacionais.htm HTTP/2.0\" 404 19845 \"-\" \"Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Mobile Safari/537.36 EdgA/153.0.0.0\" GEOIP_COUNTRY_CODE=SG | ASN: GOOGLE-CLOUD-PLATFORM | Country: SG
show less
Port Scan
Web App Attack
๐ซ๐ท
mrcrassi
2026-09-23 22:29:14
(1 day ago)
Triggered Cloudflare WAF (firewallManaged) from SG.
Action taken: BLOCK
Protocol: HTTP/2 (GET method ...
show more
Triggered Cloudflare WAF (firewallManaged) from SG.
Action taken: BLOCK
Protocol: HTTP/2 (GET method)
Endpoint: /storage/.env
UA: Mozilla/5.0 (compatible; Bytespider; [email protected] ) AppleWebKit/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ช๐ธ
pipeline.es
2026-09-23 22:25:22
(1 day ago)
Web scanning / probing for vulnerable paths | URL: /.env.prod | Evidence: geaweb.com.br 34.21.139.19 ...
show more
Web scanning / probing for vulnerable paths | URL: /.env.prod | Evidence: geaweb.com.br 34.21.139.194 - - [24/Sep/2026:00:25:08 +0200] \"GET /.env.prod HTTP/2.0\" 404 22250 \"-\" \"Mozilla/5.0 (compatible; DeepSeekBot/1.0; +https://www.deepseek.com/)\" GEOIP_COUNTRY_CODE=SG | ASN: GOOGLE-CLOUD-PLATFORM | Country: SG
show less
Port Scan
Web App Attack
๐บ๐ธ
agaesteves
2026-09-23 17:47:27
(1 day ago)
[SISHIPISMO 360] TipoAtaque.PATH_PROBE | Acesso a path suspeito: /.env.save | Paths: /.env.save | UA ...
show more
[SISHIPISMO 360] TipoAtaque.PATH_PROBE | Acesso a path suspeito: /.env.save | Paths: /.env.save | UA: Mozilla/5.0 (compatible; MistralAI-User/1.0; +https://mistral.ai/)
show less
Web App Attack
๐ฌ๐ง
consul.to
2026-09-23 17:30:21
(1 day ago)
Web attack/malicious scanning detected
Web App Attack