Anonymous
2026-09-15 22:25:57
(17 hours ago)
Fail2Ban: request for a known-malicious path (.env, .git, wp-login, actuator, ...) on a public web s ...
show more
Fail2Ban: request for a known-malicious path (.env, .git, wp-login, actuator, ...) on a public web server; honeypot hit, banned on first attempt.
show less
Web App Attack
Bad Web Bot
๐ง๐ท
dermatovirtual
2026-09-15 09:50:28
(1 day ago)
Dermato Virtual CSIRT: Malicious web exploit/scanning probes against app.dermatovirtual.com.br (Web ...
show more
Dermato Virtual CSIRT: Malicious web exploit/scanning probes against app.dermatovirtual.com.br (Web Server Ports 80/443). 31 unauthorized requests recorded between 2026-09-14 09:46:09 UTC and 2026-09-14 09:46:21 UTC (rate: ~31 req/min). Edge perimeter firewall drop active.
Log sample:
[2026-09-14 09:46:18 UTC] IP: 34.26.85.159 - W3C IIS (Port 443): GET /settings/.env -> HTTP 404 [CLIENT: 34.26.85.159]
[2026-09-14 09:46:18 UTC] IP: 34.26.85.159 - W3C IIS (Port 443): GET /@fs/.env -> HTTP 404 [CLIENT: 34.26.85.159]
[2026-09-14 09:46:18 UTC] IP: 34.26.85.159 - W3C IIS (Port 443): GET /@fs/.env -> HTTP 404 [CLIENT: 34.26.85.159]
show less
Bad Web Bot
Web App Attack
๐ง๐ท
Peregrine
2026-09-15 03:14:02
(1 day ago)
Fail2Ban ct101 Jail: tomcat-honeypot | Evidence: 34.26.85.159 172.71.30.35 - - [13/Sep/2026:05:23:21 ...
show more
Fail2Ban ct101 Jail: tomcat-honeypot | Evidence: 34.26.85.159 172.71.30.35 - - [13/Sep/2026:05:23:21 -0300] "GET /config/env/aws_credentials.env HTTP/1.1" 404 18149
show less
Bad Web Bot
Anonymous
2026-09-14 22:25:27
(1 day ago)
Fail2Ban: request for a known-malicious path (.env, .git, wp-login, actuator, ...) on a public web s ...
show more
Fail2Ban: request for a known-malicious path (.env, .git, wp-login, actuator, ...) on a public web server; honeypot hit, banned on first attempt.
show less
Web App Attack
Bad Web Bot
Anonymous
2026-09-14 16:33:18
(1 day ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
๐บ๐ธ
agenciahypelab.com.br
2026-09-14 12:23:33
(2 days ago)
WordPress login brute-force detectado e bloqueado pelo CSF/LFD. Trigger: LF_TRIGGER
Brute-Force
SSH
๐ง๐ท
dermatovirtual
2026-09-14 09:48:36
(2 days ago)
Dermato Virtual CSIRT: Malicious web exploit/scanning probes against app.dermatovirtual.com.br (Web ...
show more
Dermato Virtual CSIRT: Malicious web exploit/scanning probes against app.dermatovirtual.com.br (Web Server Ports 80/443). 31 unauthorized requests recorded between 2026-09-14 09:46:09 UTC and 2026-09-14 09:46:21 UTC (rate: ~31 req/min). Edge perimeter firewall drop active.
Log sample:
[2026-09-14 09:46:18 UTC] IP: 34.26.85.159 - W3C IIS (Port 443): GET /settings/.env -> HTTP 404 [CLIENT: 34.26.85.159]
[2026-09-14 09:46:18 UTC] IP: 34.26.85.159 - W3C IIS (Port 443): GET /@fs/.env -> HTTP 404 [CLIENT: 34.26.85.159]
[2026-09-14 09:46:18 UTC] IP: 34.26.85.159 - W3C IIS (Port 443): GET /@fs/.env -> HTTP 404 [CLIENT: 34.26.85.159]
show less
Bad Web Bot
Web App Attack
๐จ๐ฆ
cubie
2026-09-14 09:15:19
(2 days ago)
Port Scan: Admin Enumeration - Reported by CubieCloud Firewall [CFW_H344-004]
Port Scan
๐บ๐ธ
paulo.apoloni
2026-09-14 09:14:41
(2 days ago)
34.26.85.159 - - [14/Sep/2026:06:14:35 -0300] "GET /rclone.conf HTTP/2.0" 444 0 "-" "CCBot/2.0 (http ...
show more
34.26.85.159 - - [14/Sep/2026:06:14:35 -0300] "GET /rclone.conf HTTP/2.0" 444 0 "-" "CCBot/2.0 (https://commoncrawl.org/faq/)"
34.26.85.159 - - [14/Sep/2026:06:14:35 -0300] "GET /.docker/config.json HTTP/2.0" 444 0 "-" "Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; +https://kimi.ai/)"
34.26.85.159 - - [14/Sep/2026:06:14:35 -0300] "GET /.github/.env HTTP/2.0" 444 0 "-" "Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; +https://kimi.ai/)"
34.26.85.159 - - [14/Sep/2026:06:14:40 -0300] "GET /.htpasswd HTTP/2.0" 444 0 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; [email protected] )"
34.26.85.159 - - [14/Sep/2026:06:14:40 -0300] "GET /.svn/entries HTTP/2.0" 444 0 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexitybot)"
...
show less
Bad Web Bot
Web App Attack
๐ฎ๐ณ
evicky2002
2026-09-14 06:00:01
(2 days ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐ง๐ท
Peregrine
2026-09-14 03:11:55
(2 days ago)
Fail2Ban ct101 Jail: tomcat-404 | Evidence: 34.26.85.159 172.71.31.156 - - [13/Sep/2026:05:23:21 -03 ...
show more
Fail2Ban ct101 Jail: tomcat-404 | Evidence: 34.26.85.159 172.71.31.156 - - [13/Sep/2026:05:23:21 -0300] "GET /dist/.vite/manifest.json HTTP/1.1" 404 18149
34.26.85.159 172.71.31.156 - - [13/Sep/2026:05:23:21 -0300] "GET /build/manifest.json HTTP/1.1" 404 18149
34.26.85.159 172.71.31.156 - - [13/Sep/2026:05:23:22 -0300] "GET /rclone.conf HTTP/1.1" 404 18149
34.26.85.159 172.71.30.34 - - [13/Sep/2026:05:23:22 -0300] "GET /.idea/WebServers.xml HTTP/1.1" 404 18149
34.26.85.159 172.71.30.34 - - [13/Sep/2026:05:23:22 -0300] "GET /.vite/manifest.json HTTP/1.1" 404 18149
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
marcelhalls
2026-09-14 03:00:04
(2 days ago)
Repeated attacks detected by Fail2Ban in recidive jail
Hacking
Anonymous
2026-09-13 22:23:48
(2 days ago)
Fail2Ban: request for a known-malicious path (.env, .git, wp-login, actuator, ...) on a public web s ...
show more
Fail2Ban: request for a known-malicious path (.env, .git, wp-login, actuator, ...) on a public web server; honeypot hit, banned on first attempt.
show less
Web App Attack
Bad Web Bot
๐บ๐ธ
mibbsdevs
2026-09-13 16:23:27
(2 days ago)
(ric-sv) CoffeePot Web: Automated bad bot directory fuzzing and high-rate 404 probing.
Port Scan
Bad Web Bot
๐บ๐ธ
abuse-opdc
2026-09-13 14:05:49
(3 days ago)
Malicious HTTP requests matching injection/exploit signatures.
Web App Attack
Brute-Force