๐ง๐ท
Peregrine
2026-10-06 03:16:15
(1 day ago)
Fail2Ban ct101 Jail: tomcat-honeypot | Evidence: 34.24.26.42 104.22.118.10 - - [04/Oct/2026:20:27:53 ...
show more
Fail2Ban ct101 Jail: tomcat-honeypot | Evidence: 34.24.26.42 104.22.118.10 - - [04/Oct/2026:20:27:53 -0300] "GET /.ssh/id_rsa HTTP/1.1" 404 18149
show less
Bad Web Bot
๐ง๐ท
SvrAdmin
2026-10-05 20:04:37
(2 days ago)
[204] (cpanel) Failed cPanel login from 34.24.26.42 (US/United States/42.26.24.34.bc.googleuserconte ...
show more
[204] (cpanel) Failed cPanel login from 34.24.26.42 (US/United States/42.26.24.34.bc.googleusercontent.com): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CPANEL; Logs: [2026-10-05 17:04:29 -0300] info [cpaneld] 34.24.26.42 - - "GET /webpack-stats.json HTTP/1.1" FAILED LOGIN cpaneld: login attempt without username
[2026-10-05 17:04:30 -0300] info [cpaneld] 34.24.26.42 - - "GET /var/run/secrets/kubernetes.io/serviceaccount/token HTTP/1.1" FAILED LOGIN cpaneld: login attempt without username
[2026-10-05 17:04:30 -0300] info [cpaneld] 34.24.26.42 - - "POST /graphql HTTP/1.1" FAILED LOGIN cpaneld: login attempt without username
[2026-10-05 17:04:30 -0300] info [cpaneld] 34.24.26.42 - - "GET /.env HTTP/1.1" FAILED LOGIN cpaneld: login attempt without username
[2026-10-05 17:04:30 -0300] info [cpaneld] 34.24.26.42 - - "GET /userfiles/x?path=../../.env HTTP/1.1" FAILED LOGIN cpaneld: login attempt without username
show less
Port Scan
Hacking
Brute-Force
Exploited Host
๐ง๐ท
govfacil.app
2026-10-05 19:15:34
(2 days ago)
(cpanel) Failed cPanel login from 34.24.26.42 (US/United States/42.26.24.34.bc.googleusercontent.com ...
show more
(cpanel) Failed cPanel login from 34.24.26.42 (US/United States/42.26.24.34.bc.googleusercontent.com): 50 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CPANEL; Logs: [2026-10-05 16:15:26 -0300] info [cpaneld] 34.24.26.42 - - "GET /poe1xh6f03xz2c4luiu7 HTTP/1.1" FAILED LOGIN cpaneld: login attempt without username
[2026-10-05 16:15:26 -0300] info [cpaneld] 34.24.26.42 - - "GET /static../.env HTTP/1.1" FAILED LOGIN cpaneld: login attempt without username
[2026-10-05 16:15:26 -0300] info [cpaneld] 34.24.26.42 - - "GET /wp-json HTTP/1.1" FAILED LOGIN cpaneld: login attempt without username
[2026-10-05 16:15:26 -0300] info [cpaneld] 34.24.26.42 - - "GET /media../.env HTTP/1.1" FAILED LOGIN cpaneld: login attempt without username
[2026-10-05 16:15:26 -0300] info [cpaneld] 34.24.26.42 - - "GET /.dockerenv HTTP/1.1" FAILED LOGIN cpaneld: login attempt without username
[2026-10-05 16:15:27 -0300] info [cpaneld] 34.24.26.42 - - "GET /assets../.env HTTP/1.1" FAILED LOGIN cpaneld: [truncated]
show less
Brute-Force
๐ง๐ท
dermatovirtual
2026-10-05 15:43:12
(2 days ago)
Dermato Virtual CSIRT: Malicious web exploit/scanning probes against app.dermatovirtual.com.br (Web ...
show more
Dermato Virtual CSIRT: Malicious web exploit/scanning probes against app.dermatovirtual.com.br (Web Server Ports 80/443). 65 unauthorized requests recorded between 2026-10-05 14:01:26 UTC and 2026-10-05 14:01:36 UTC (rate: ~65 req/min). Edge perimeter firewall drop active.
Log sample:
[2026-10-05 14:01:34 UTC] IP: 34.24.26.42 - W3C IIS (Port 443): GET /settings/.env -> HTTP 404 [CLIENT: 34.24.26.42]
[2026-10-05 14:01:34 UTC] IP: 34.24.26.42 - W3C IIS (Port 443): GET /api/.env -> HTTP 404 [CLIENT: 34.24.26.42]
[2026-10-05 14:01:34 UTC] IP: 34.24.26.42 - W3C IIS (Port 443): GET /.env -> HTTP 404 [CLIENT: 34.24.26.42]
show less
Bad Web Bot
Web App Attack
๐ง๐ท
Sysadmin-CLC
2026-10-05 15:27:30
(2 days ago)
Caught by f2b nginx-limit-req.
Web App Attack
DDoS Attack
๐ง๐ท
Host One
2026-10-05 13:20:20
(2 days ago)
[Honeypot] Malicious activity detected by honeypot on port 80. IP attempted unauthorized access to d ...
show more
[Honeypot] Malicious activity detected by honeypot on port 80. IP attempted unauthorized access to decoy service. Original message: Web honeypot: 293 malicious requests. Attack types: admin_scan, vulnerability_scan, generic_scan. Sample: GET / HTTP/2.0. Attempted credentials captured.
show less
Brute-Force
Web App Attack
๐จ๐ฆ
cubie
2026-10-05 12:57:36
(2 days ago)
Port Scan: Admin Enumeration - Reported by CubieCloud Firewall [CFW_H432-009]
Port Scan
๐บ๐ธ
paulo.apoloni
2026-10-05 12:56:25
(2 days ago)
34.24.26.42 - - [05/Oct/2026:09:56:24 -0300] "GET /.env HTTP/1.1" 444 0 "-" "Mozilla/5.0 (compatible ...
show more
34.24.26.42 - - [05/Oct/2026:09:56:24 -0300] "GET /.env HTTP/1.1" 444 0 "-" "Mozilla/5.0 (compatible; ChatGLM-Spider/1.0; +https://zhipuai.cn/)"
34.24.26.42 - - [05/Oct/2026:09:56:24 -0300] "GET /.env HTTP/1.1" 444 0 "-" "Mozilla/5.0 (compatible; ChatGLM-Spider/1.0; +https://zhipuai.cn/)"
34.24.26.42 - - [05/Oct/2026:09:56:24 -0300] "GET /.env.old HTTP/1.1" 444 0 "-" "Mozilla/5.0 (compatible; Google-Extended; +http://www.google.com/bot.html)"
34.24.26.42 - - [05/Oct/2026:09:56:24 -0300] "GET /.env.bak HTTP/1.1" 444 0 "-" "Mozilla/5.0 (compatible; PanguBot/1.0; +https://www.huaweicloud.com/)"
34.24.26.42 - - [05/Oct/2026:09:56:24 -0300] "GET /.env HTTP/1.1" 444 0 "-" "Mozilla/5.0 (compatible; ChatGLM-Spider/1.0; +https://zhipuai.cn/)"
...
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
niedson
2026-10-05 11:30:02
(2 days ago)
Automated scanning for exposed secrets: repeated requests for multiple distinct credential paths (.e ...
show more
Automated scanning for exposed secrets: repeated requests for multiple distinct credential paths (.env variants, .git metadata, .ssh private keys, .aws/credentials). Unsolicited. Reported automatically.
show less
Web App Attack
๐บ๐ธ
abuse-opdc
2026-10-05 09:05:51
(2 days ago)
Malicious HTTP requests matching injection/exploit signatures.
Web App Attack
Brute-Force
๐บ๐ธ
agaesteves
2026-10-05 01:47:11
(3 days ago)
[SISHIPISMO 360] TipoAtaque.PATH_PROBE | Acesso a path suspeito: /files../.env | Paths: /files../.en ...
show more
[SISHIPISMO 360] TipoAtaque.PATH_PROBE | Acesso a path suspeito: /files../.env | Paths: /files../.env | UA: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; [email protected]
show less
Web App Attack
Anonymous
2026-10-05 01:38:08
(3 days ago)
34.24.26.42 - - [04/Oct/2026:22:38:08 -0300] "GET /.htpasswd HTTP/2.0" 301 162 "-" "Mozilla/5.0 (com ...
show more
34.24.26.42 - - [04/Oct/2026:22:38:08 -0300] "GET /.htpasswd HTTP/2.0" 301 162 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
...
show less
Port Scan
Hacking
SQL Injection
Brute-Force
Bad Web Bot
Exploited Host
Anonymous
2026-10-05 01:06:27
(3 days ago)
Next.js Authentication Bypass (CVE-2025-29927).
Hacking
๐ง๐ท
Peregrine
2026-10-04 23:27:57
(3 days ago)
Fail2Ban ct101 Jail: tomcat-404 | Evidence: 34.24.26.42 104.22.118.10 - - [04/Oct/2026:20:27:52 -030 ...
show more
Fail2Ban ct101 Jail: tomcat-404 | Evidence: 34.24.26.42 104.22.118.10 - - [04/Oct/2026:20:27:52 -0300] "GET /y3a3hr19w1g5wwjlnj6y HTTP/1.1" 404 18149
34.24.26.42 104.22.118.10 - - [04/Oct/2026:20:27:52 -0300] "GET /z9x8c7v6b5-debug-trigger-decise.com.br HTTP/1.1" 404 18149
34.24.26.42 104.22.118.10 - - [04/Oct/2026:20:27:52 -0300] "GET /build/manifest.json HTTP/1.1" 404 18149
34.24.26.42 104.22.118.10 - - [04/Oct/2026:20:27:52 -0300] "GET /5x90qyupw8lkfjazc9q6 HTTP/1.1" 404 18149
34.24.26.42 104.22.118.10 - - [04/Oct/2026:20:27:52 -0300] "GET /.vite/manifest.json HTTP/1.1" 404 18149
show less
Bad Web Bot
Web App Attack
๐ซ๐ท
mrcrassi
2026-10-04 23:12:20
(3 days ago)
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: BLOCK
Protocol: HTTP/2 (POST metho ...
show more
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: BLOCK
Protocol: HTTP/2 (POST method)
Endpoint: /dashboard
UA: Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot