๐ฌ๐ง
Smish
2026-07-30 07:51:59
(23 hours ago)
HONEYPOT HIT --> Fail2ban time=1785397918 log=2026-07-30T08:51:58+01:00 ip=34.23.193.209 host=studio ...
show more
HONEYPOT HIT --> Fail2ban time=1785397918 log=2026-07-30T08:51:58+01:00 ip=34.23.193.209 host=studio.smishcraft.com method=GET uri="/.aws/credentials" status=404 ua="Mozilla/5.0 (compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot)" ref="-" rid=f2fae9a1624230b6e3e9b0bc9270a168
show less
Web App Attack
๐ซ๐ท
Octopuce
2026-07-30 03:42:05
(1 day ago)
Aggressive web search of vulnerable pages: / /.env /.env.local /admin/.env /api/.env ...
Web App Attack
๐ฆ๐บ
AWW-Admin
2026-07-30 03:41:14
(1 day ago)
(mod_security) mod_security triggered on hostname [redacted] 34.23.193.209 (US/United States/209.193 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.23.193.209 (US/United States/209.193.23.34.bc.googleusercontent.com)
show less
SQL Injection
๐ฌ๐ง
Smish
2026-07-30 03:03:07
(1 day ago)
HONEYPOT HIT --> Fail2ban time=1785380586 log=2026-07-30T04:03:06+01:00 ip=34.23.193.209 host=backof ...
show more
HONEYPOT HIT --> Fail2ban time=1785380586 log=2026-07-30T04:03:06+01:00 ip=34.23.193.209 host=backoffice.smishcraft.com method=GET uri="/.aws/config" status=404 ua="Mozilla/5.0 (compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot)" ref="-" rid=270690d08a55f7632543cdee1bd89998
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-30 02:18:34
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.23.193.209 (209.193.23.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.23.193.209 (209.193.23.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 29 22:18:31.313167 2026] [security2:error] [pid 78397:tid 78397] [client 34.23.193.209:49288] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "console.sinsky.net"] [uri "/.git/config"] [unique_id "amq0d9qIwt8A7ArmLI3ZlwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-30 01:38:45
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.23.193.209 (209.193.23.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.23.193.209 (209.193.23.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 29 21:38:37.617741 2026] [security2:error] [pid 27624:tid 27624] [client 34.23.193.209:46082] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||secure.robtown.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "secure.robtown.com"] [uri "/rclone.conf"] [unique_id "amqrHZVXbBlRo4XcM92D0wAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Marc
2026-07-30 01:33:59
(1 day ago)
34.23.193.209 - - [30/Jul/2026:03:33:58 +0200] "GET /.git/config HTTP/2.0" 404 269 "-" "Mozilla/5.0 ...
show more
34.23.193.209 - - [30/Jul/2026:03:33:58 +0200] "GET /.git/config HTTP/2.0" 404 269 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexity-user" 34.23.193.209 - - [30/Jul/2026:03:33:58 +0200] "GET /wp-json HTTP/2.0" 404 269 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexity-user" 34.23.193.209 - - [30/Jul/2026:03:33:58 +0200] "GET /.git/HEAD HTTP/2.0" 404 269 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexity-user"
show less
Brute-Force
Anonymous
2026-07-30 01:00:15
(1 day ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
๐ฉ๐ช
Philister11
2026-07-30 00:55:32
(1 day ago)
CrowdSec: crowdsecurity/http-sensitive-files (US/AS396982)
Web App Attack
Hacking
๐ฉ๐ช
Ba-Yu
2026-07-30 00:54:27
(1 day ago)
General hacking/exploits/scanning
Web Spam
Hacking
Brute-Force
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-30 00:54:13
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.23.193.209 (209.193.23.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.23.193.209 (209.193.23.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 29 20:54:09.190735 2026] [security2:error] [pid 676959:tid 676959] [client 34.23.193.209:52164] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||portal.semisysteme.com|F|2"] [data ".semisysteme.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "portal.semisysteme.com"] [uri "/z9x8c7v6b5-debug-trigger-portal.semisysteme.com"] [unique_id "amqgsVhmPtFLEyUznfBBrAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-07-30 00:24:33
(1 day ago)
Multiple WAF Violations
Web App Attack
๐ช๐ธ
alferez
2026-07-30 00:17:37
(1 day ago)
Searching .(env|sql|zip|tar|rar) files
Hacking
Exploited Host
Web App Attack
๐ฉ๐ช
Hazzard
2026-07-30 00:12:56
(1 day ago)
(PERMBLOCK) 34.23.193.209 (US/United States/South Carolina/North Charleston/209.193.23.34.bc.googleu ...
show more
(PERMBLOCK) 34.23.193.209 (US/United States/South Carolina/North Charleston/209.193.23.34.bc.googleusercontent.com/[redacted]) has had more than 4 temp blocks
show less
Hacking
๐ฎ๐น
VHosting
2026-07-30 00:10:04
(1 day ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack