🇮🇳
evicky2002
2026-08-31 00:01:03
(1 hour ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
🇧🇷
Peregrine
2026-08-30 03:11:56
(21 hours ago)
Fail2Ban Jail: tomcat-honeypot | Evidence: 34.21.61.44 162.158.79.69 - - [28/Aug/2026:19:03:24 -0300 ...
show more
Fail2Ban Jail: tomcat-honeypot | Evidence: 34.21.61.44 162.158.79.69 - - [28/Aug/2026:19:03:24 -0300] "GET /.env.local HTTP/1.1" 404 414
34.21.61.44 104.23.211.31 - - [28/Aug/2026:19:03:24 -0300] "GET /.env HTTP/1.1" 404 414
34.21.61.44 172.71.194.157 - - [28/Aug/2026:19:03:24 -0300] "GET /.env.bak HTTP/1.1" 404 414
34.21.61.44 104.22.102.8 - - [28/Aug/2026:19:03:24 -0300] "GET /.env.backup HTTP/1.1" 404 414
34.21.61.44 162.158.79.69 - - [28/Aug/2026:19:03:24 -0300] "GET /.env.prod HTTP/1.1" 404 414
34.21.61.44 104.22.102.8 - - [28/Aug/2026:19:03:24 -0300] "GET /.env.save HTTP/1.1" 404 414
34.21.61.44 104.22.104.93 - - [28/Aug/2026:19:03:24 -0300] "GET /.env.example HTTP/1.1" 404 414
34.21.61.44 104.22.100.181 - - [28/Aug/2026:19:03:24 -0300] "GET /.env.old HTTP/1.1" 404 414
34.21.61.44 172.70.174.202 - - [28/Aug/2026:19:03:24 -0300] "GET /.env.production HTTP/1.1" 404 414
34.21.61.44 172.70.34.122 - - [28/Aug/2026:19:03:24 -0300] "GET /.env.dev HTTP/1.1" 404 414
show less
Bad Web Bot
🇮🇹
CoreTech srl
2026-08-30 02:48:14
(22 hours ago)
[DC: IP:151.1.252.27] ntopng alert: blacklisted_client_contact
Hacking
🇯🇵
ki3
2026-08-30 02:30:14
(22 hours ago)
Fail2Ban: Web App Attacks and Forum Spam 34.21.61.44 1788057014.0(JST)
Web Spam
Bad Web Bot
Web App Attack
🇺🇸
etu brutus
2026-08-30 02:20:28
(22 hours ago)
34.21.61.44 Blocked by [Attack Vector List]
...
Hacking
Brute-Force
Exploited Host
Anonymous
2026-08-30 02:05:06
(22 hours ago)
WAF repeated trigger detected by Fail2Ban
Web App Attack
Anonymous
2026-08-30 00:49:13
(1 day ago)
[Sun Aug 30 02:49:12.484188 2026] [authz_core:error] [pid 19193] [client 34.21.61.44:56510] AH01630: ...
show more
[Sun Aug 30 02:49:12.484188 2026] [authz_core:error] [pid 19193] [client 34.21.61.44:56510] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Sun Aug 30 02:49:12.485104 2026] [authz_core:error] [pid 18454] [client 34.21.61.44:56530] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Sun Aug 30 02:49:12.485380 2026] [authz_core:error] [pid 19190] [client 34.21.61.44:56522] AH01630: client denied by server configuration: /etc/httpd/htdocs
...
show less
Web App Attack
🇩🇪
pscriptos
2026-08-30 00:25:22
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇿🇦
conure.sh
2026-08-29 12:01:52
(1 day ago)
csagent: score 20.8: 404 noise floor x3, wp-config backup grab x1, secrets grab x1; 1 domain(s) in 0 ...
show more
csagent: score 20.8: 404 noise floor x3, wp-config backup grab x1, secrets grab x1; 1 domain(s) in 0s
show less
Web App Attack
🇩🇪
Vegascosmetics
2026-08-29 04:54:40
(1 day ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after sensitive config/credentials exposure ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after sensitive config/credentials exposure probe. Evidence: AttackPattern: /\.env (Match: /.env)
show less
Hacking
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-08-29 03:42:14
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.21.61.44 (44.61.21.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.21.61.44 (44.61.21.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 23:42:08.519324 2026] [security2:error] [pid 6303:tid 6303] [client 34.21.61.44:45902] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.bookstands.fritsknuf.com"] [uri "/.env.dev"] [unique_id "apJVEFo5HcCJvO2CIa7khAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
WebNiraj
2026-08-29 01:54:34
(1 day ago)
(mod_security) mod_security (id:949110) triggered by 34.21.61.44 (US/United States/44.61.21.34.bc.go ...
show more
(mod_security) mod_security (id:949110) triggered by 34.21.61.44 (US/United States/44.61.21.34.bc.googleusercontent.com): 5 in the last 3600 secs [SIGMA]
show less
Brute-Force
🇺🇸
TPI-Abuse
2026-08-29 01:50:49
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.21.61.44 (44.61.21.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.21.61.44 (44.61.21.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 21:50:45.987968 2026] [security2:error] [pid 21263:tid 21263] [client 34.21.61.44:59612] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "destintoday.com"] [uri "/.env.dev"] [unique_id "apI69doOhhkWgNViYCVZhAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-08-29 01:46:47
(1 day ago)
Web attack/malicious scanning detected
Web App Attack
🇺🇸
TPI-Abuse
2026-08-29 01:35:31
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.21.61.44 (44.61.21.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.21.61.44 (44.61.21.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 21:35:24.637851 2026] [security2:error] [pid 12042:tid 12042] [client 34.21.61.44:56940] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gfsprod.com"] [uri "/.env"] [unique_id "apI3XEAAIT4QfLTW7hg-pQAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack