๐บ๐ธ
agenciahypelab.com.br
2026-09-24 21:28:48
(5 hours ago)
WordPress login brute-force detectado e bloqueado pelo CSF/LFD. Trigger: LF_TRIGGER
Brute-Force
SSH
๐ซ๐ท
mrcrassi
2026-09-24 16:45:37
(10 hours ago)
Triggered Cloudflare WAF (firewallManaged) from SG.
Action taken: BLOCK
Protocol: HTTP/2 (POST metho ...
show more
Triggered Cloudflare WAF (firewallManaged) from SG.
Action taken: BLOCK
Protocol: HTTP/2 (POST method)
Endpoint: /api
UA: Mozilla/5.0 (compatible; DeepSeekBot/1.0; +https://www.deepseek.com/)
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ช๐ธ
pipeline.es
2026-09-24 08:58:42
(17 hours ago)
Web scanning / probing for vulnerable paths
Port Scan
Web App Attack
๐ง๐ท
SOC-BR
2026-09-24 07:24:33
(19 hours ago)
Attack detected by Fortinet - applications3: Vercel.Next.js.x-middleware-subrequest.Authentication.B ...
show more
Attack detected by Fortinet - applications3: Vercel.Next.js.x-middleware-subrequest.Authentication.Bypass - 2026-09-23 09:43:28 - Source Port 43384
show less
Port Scan
Hacking
Anonymous
2026-09-24 04:31:34
(22 hours ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
๐ซ๐ท
mrcrassi
2026-09-24 00:36:44
(1 day ago)
Triggered Cloudflare WAF (firewallManaged) from SG.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET meth ...
show more
Triggered Cloudflare WAF (firewallManaged) from SG.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /settings.json
UA: CCBot/2.0 (https://commoncrawl.org/faq/)
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ง๐ท
Halux
2026-09-24 00:17:12
(1 day ago)
34.21.149.196 Web Application Firewall multiple violations
Hacking
Web App Attack
๐ง๐ท
Halux
2026-09-23 20:28:32
(1 day ago)
34.21.149.196 Probing protected path or service
Web App Attack
๐บ๐ธ
abuse-opdc
2026-09-23 20:10:41
(1 day ago)
Malicious HTTP requests matching injection/exploit signatures.
Web App Attack
Brute-Force
๐ง๐ท
Peregrine
2026-09-23 19:14:32
(1 day ago)
Fail2Ban Jail: tomcat-404 | Evidence: 34.21.149.196 172.69.176.108 - - [23/Sep/2026:16:14:28 -0300] ...
show more
Fail2Ban Jail: tomcat-404 | Evidence: 34.21.149.196 172.69.176.108 - - [23/Sep/2026:16:14:28 -0300] "GET /build/manifest.json HTTP/1.1" 404 414
34.21.149.196 172.69.176.109 - - [23/Sep/2026:16:14:28 -0300] "GET /f5ht6mbn5puy155l4sgh HTTP/1.1" 404 414
34.21.149.196 172.69.176.109 - - [23/Sep/2026:16:14:28 -0300] "GET /dist/.vite/manifest.json HTTP/1.1" 404 414
34.21.149.196 172.69.176.109 - - [23/Sep/2026:16:14:28 -0300] "GET /z9x8c7v6b5-debug-trigger-peregrine.net.br HTTP/1.1" 404 414
34.21.149.196 172.69.176.109 - - [23/Sep/2026:16:14:28 -0300] "GET /dist/manifest.json HTTP/1.1" 404 414
34.21.149.196 172.69.176.108 - - [23/Sep/2026:16:14:28 -0300] "GET /.vite/manifest.json HTTP/1.1" 404 414
34.21.149.196 172.69.176.108 - - [23/Sep/2026:16:14:28 -0300] "GET /ka7a3qg2gy2j3hoevpoc HTTP/1.1" 404 414
34.21.149.196 172.69.176.109 - - [23/Sep/2026:16:14:29 -0300] "POST /graphql HTTP/1.1" 404 414
34.21.149.196 172.69.176.109 - - [23/Sep/2026:16:14:29 -0300] "GET /rclone.conf HTTP/1.1" 404 414
show less
Bad Web Bot
Web App Attack
๐ช๐ธ
pipeline.es
2026-09-23 17:54:10
(1 day ago)
Web scanning / probing for vulnerable paths | URL: /credentials.json | Evidence: ramatur.com.br 34.2 ...
show more
Web scanning / probing for vulnerable paths | URL: /credentials.json | Evidence: ramatur.com.br 34.21.149.196 - - [23/Sep/2026:19:52:27 +0200] \"GET /credentials.json HTTP/2.0\" 404 19320 \"-\" \"Mozilla/5.0 (compatible; Bytespider; [email]) AppleWebKit/537.36\" GEOIP_COUNTRY_CODE=SG | ASN: GOOGLE-CLOUD-PLATFORM | Country: SG
show less
Port Scan
Web App Attack
๐บ๐ธ
paulo.apoloni
2026-09-23 16:32:19
(1 day ago)
34.21.149.196 - - [23/Sep/2026:13:32:17 -0300] "GET /.dockerenv HTTP/2.0" 404 0 "-" "Mozilla/5.0 (co ...
show more
34.21.149.196 - - [23/Sep/2026:13:32:17 -0300] "GET /.dockerenv HTTP/2.0" 404 0 "-" "Mozilla/5.0 (compatible; Bytespider; [email protected] ) AppleWebKit/537.36"
34.21.149.196 - - [23/Sep/2026:13:32:18 -0300] "GET /.env.production?import&raw HTTP/2.0" 404 0 "-" "Mozilla/5.0 (compatible; Qwenbot/1.0; +https://qwen.alibaba.com/)"
34.21.149.196 - - [23/Sep/2026:13:32:18 -0300] "GET /.env.local?raw HTTP/2.0" 404 0 "-" "DuckAssistBot/1.1 (https://duckduckgo.com/duckassistbot)"
34.21.149.196 - - [23/Sep/2026:13:32:18 -0300] "GET /.env.development?raw HTTP/2.0" 404 0 "-" "Mozilla/5.0 (compatible; xAI-Grok/1.0; +https://x.ai/)"
34.21.149.196 - - [23/Sep/2026:13:32:18 -0300] "GET /.env.development?import&raw HTTP/2.0" 404 0 "-" "DuckAssistBot/1.1 (https://duckduckgo.com/duckassistbot)"
...
show less
Web App Attack
๐ง๐ท
maviei
2026-09-23 15:12:28
(1 day ago)
radiojfsliberdade.com.br 34.21.149.196 - - [23/Sep/2026:12:12:26 -0300] "GET /admin HTTP/2.0" 403 57 ...
show more
radiojfsliberdade.com.br 34.21.149.196 - - [23/Sep/2026:12:12:26 -0300] "GET /admin HTTP/2.0" 403 5754 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
...
show less
Web App Attack
๐ช๐ธ
pipeline.es
2026-09-23 15:08:50
(1 day ago)
Web scanning / probing for vulnerable paths | URL: /api/fs/exec | Evidence: ramatur.com.br 34.21.149 ...
show more
Web scanning / probing for vulnerable paths | URL: /api/fs/exec | Evidence: ramatur.com.br 34.21.149.196 - - [23/Sep/2026:17:07:57 +0200] \"POST /api/fs/exec HTTP/2.0\" 404 19280 \"-\" \"Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; +https://kimi.ai/)\" GEOIP_COUNTRY_CODE=SG | ASN: GOOGLE-CLOUD-PLATFORM | Country: SG
show less
Port Scan
Web App Attack
๐ณ๐ฑ
Savvii
2026-09-23 14:11:20
(1 day ago)
20 attempts against mh-misbehave-ban on redirect
Brute-Force
Bad Web Bot
Web App Attack