πΊπΈ
CBJ
2026-09-15 22:31:43
(3 days ago)
fail2ban: apache-filepath-recon
...
Web App Attack
π³π±
Site.eu
2026-09-15 07:39:19
(4 days ago)
Excessive multi-domain requests
Brute-Force
π«π·
guillaume illien
2026-09-14 16:25:44
(5 days ago)
34.21.57.100 - - [14/Sep/2026:16:25:42 +0000] "GET /%2e%2e/.env HTTP/1.1" 400 166 "-" "-"
34.21.57.1 ...
show more
34.21.57.100 - - [14/Sep/2026:16:25:42 +0000] "GET /%2e%2e/.env HTTP/1.1" 400 166 "-" "-"
34.21.57.100 - - [14/Sep/2026:16:25:42 +0000] "GET /..%2f..%2f.env HTTP/1.1" 400 166 "-" "-"
34.21.57.100 - - [14/Sep/2026:16:25:43 +0000] "GET /..%2f.env HTTP/1.1" 400 166 "-" "-"
34.21.57.100 - - [14/Sep/2026:16:25:43 +0000] "GET /public/plugins/alertlist/../../../../../../../../proc/self/cmdline HTTP/1.1" 400 166 "-" "-"
34.21.57.100 - - [14/Sep/2026:16:25:43 +0000] "GET /public/plugins/grafana-clock-panel/../../../../../../../../proc/self/environ HTTP/1.1" 400 166 "-" "-"
34.21.57.100 - - [14/Sep/2026:16:25:44 +0000] "GET /api/attachments/img/avatar/..%2F..%2F..%2F..%2F..%2Fproc%2Fself%2Fenviron HTTP/1.1" 400 166 "-" "-"
34.21.57.100 - - [14/Sep/2026:16:25:44 +0000] "GET /api/attachments/img/avatar/..%2F..%2F..%2F..%2F..%2F.env HTTP/1.1" 400 166 "-" "-"
...
show less
Hacking
Brute-Force
Web App Attack
SSH
π³π±
tmiland
2026-09-14 15:49:56
(5 days ago)
Detected 133 connections from 34.21.57.100 last 10 minutes.; lone high-rate source (combined 266 req ...
show more
Detected 133 connections from 34.21.57.100 last 10 minutes.; lone high-rate source (combined 266 requests in both windows); Logs: 34.21.57.100 - - [14/Sep/2026:17:49:30 +0200] "GET / HTTP/1.1" 200 50802 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36" 34.21.57.100 - - [14/Sep/2026:17:49:30 +0200] "GET /_nuxt/../.env HTTP/1.1" 404 2992 "-" "DuckAssistBot/1.1 (https://duckduckgo.com/duckassistbot)" 34.21.57.100 - - [14/Sep/2026:17:49:30 +0200] "GET /assets/manifest.json HTTP/1.1" 404 2992 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36" 34.21.57.100 - - [14/Sep/2026:17:49:30 +0200] "GET /@fs/..%252f..%252f..%252f..%252f..%252froot/.env?raw?? HTTP/1.1" 404 2992 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot)" 34.21.57.100 - - [14/Sep/2026:17:49:30 +0200] "GET /z9x8
show less
DDoS Attack
Bad Web Bot
Web App Attack
π³π±
tmiland
2026-09-14 15:49:34
(5 days ago)
(nginx_444) Nginx 444 34.21.57.100 (US/United States/100.57.21.34.bc.googleusercontent.com): 5 in th ...
show more
(nginx_444) Nginx 444 34.21.57.100 (US/United States/100.57.21.34.bc.googleusercontent.com): 5 in the last 3600 secs; IP: 34.21.57.100; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 34.21.57.100 - - [14/Sep/2026:17:49:31 +0200] "GET /media../.env HTTP/1.1" 444 0 "-" "Mozilla/5.0 (compatible; cohere-ai; +https://cohere.com/crawler)" 34.21.57.100 - - [14/Sep/2026:17:49:31 +0200] "GET /files../.env HTTP/1.1" 444 0 "-" "Mozilla/5.0 (compatible; cohere-ai; +https://cohere.com/crawler)" 34.21.57.100 - - [14/Sep/2026:17:49:31 +0200] "GET /.//.env HTTP/1.1" 404 2992 "-" "Mozilla/5.0 (compatible; DeepSeekBot/1.0; +https://www.deepseek.com/)" 34.21.57.100 - - [14/Sep/2026:17:49:31 +0200] "GET /media../.env HTTP/1.1" 444 0 "-" "Mozilla/5.0 (compatible; cohere-ai; +https://cohere.com/crawler)" 34.21.57.100 - - [14/Sep/2026:17:49:31 +0200] "GET /files../.env HTTP/1.1" 444 0 "-" "Mozilla/5.0 (compatible; cohere-ai; +https://cohere.com/crawler)"
show less
Brute-Force
Anonymous
2026-09-14 07:34:23
(5 days ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
π©πͺ
onlyops.app
2026-09-14 07:00:08
(5 days ago)
Web application firewall (ModSecurity) detected malicious traffic | detected by Fail2Ban (plesk-mods ...
show more
Web application firewall (ModSecurity) detected malicious traffic | detected by Fail2Ban (plesk-modsecurity jail) | onlyops.app
show less
Exploited Host
Anonymous
2026-09-14 06:49:44
(5 days ago)
[honeypot-scan] 2026-09-14 06:49:44, Client: 34.21.57.100, Protocol: 6 (TCP), Service: HTTP, Activit ...
show more
[honeypot-scan] 2026-09-14 06:49:44, Client: 34.21.57.100, Protocol: 6 (TCP), Service: HTTP, Activity: bait-path scan (.env/.git probing)
show less
Web App Attack
π©πͺ
FD-IX
2026-09-14 05:31:58
(5 days ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
π©πͺ
arnisolutions
2026-09-14 05:25:33
(5 days ago)
Vulnerability scanning (requests for admin panels, shells, backup files etc.) against a production s ...
show more
Vulnerability scanning (requests for admin panels, shells, backup files etc.) against a production server. Observed on 1 day(s) between 2026-09-14 and 2026-09-14 (UTC). Sample request: POST /mcp HTTP/2.0
show less
Web App Attack
Hacking
πΊπΈ
SketchyDude
2026-09-14 04:19:35
(5 days ago)
Banned by Fail2Ban jail: apache-fakegooglebot
Bad Web Bot
π§π·
Sergio de Souza Pascali
2026-09-14 04:18:30
(5 days ago)
Automated web probing/attacks (blocked requests and sensitive-path scans) against www.norluz.com.br
Web App Attack
Bad Web Bot
Brute-Force
π²π½
octageeks.com
2026-09-14 04:09:18
(5 days ago)
Wordpress malicious attack:[octamissingdomain]
Web App Attack
πΉπ
MWA SOC
2026-09-14 04:01:55
(5 days ago)
Hacking
π«π·
MatStef132
2026-09-14 03:40:56
(5 days ago)
MatShield L7: blocked on mathost.eu (suspicious behaviour)
DDoS Attack