Anonymous
2026-09-16 13:45:13
(37 minutes ago)
Observed scanned 22 known-sensitive endpoint(s), e.g.: /.boto, /.dockerenv, /.env.php.bak, /.git-cre ...
show more
Observed scanned 22 known-sensitive endpoint(s), e.g.: /.boto, /.dockerenv, /.env.php.bak, /.git-credentials, /.ssh/id_rsa, /@fs/var/run/secrets/kubernetes.io/serviceaccount/ca.crt
show less
Bad Web Bot
Web App Attack
๐ง๐ช
taivas.nl
2026-09-16 04:34:23
(9 hours ago)
Many_bad_calls
Web App Attack
๐ฎ๐ณ
evicky2002
2026-09-16 00:02:04
(14 hours ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐ฉ๐ช
Hary74656
2026-09-15 23:15:49
(15 hours ago)
Fail2Ban on schani.hostmi.at: jail=apache-404, failures=30. No raw log data included.
Web App Attack
๐ง๐ฌ
HighWay
2026-09-15 22:16:22
(16 hours ago)
34.30.203.116 - - [15/Sep/2026:22:16:20 +0000] "GET /signin HTTP/1.1" 404 770 "-" "Mozilla/5.0 (Wind ...
show more
34.30.203.116 - - [15/Sep/2026:22:16:20 +0000] "GET /signin HTTP/1.1" 404 770 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
34.30.203.116 - - [15/Sep/2026:22:16:20 +0000] "GET /wp-json HTTP/1.1" 404 4758 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ChatGPT-User/1.0; +https://openai.com/bot)"
34.30.203.116 - - [15/Sep/2026:22:16:20 +0000] "POST /graphql HTTP/1.1" 404 4758 "https://vhelectronics.com" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
34.30.203.116 - - [15/Sep/2026:22:16:20 +0000] "GET /auth/login HTTP/1.1" 404 770 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
34.30.203.116 - - [15/Sep/2026:22:16:20 +0000] "GET /account/login HTTP/1.1" 404 770 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 S
...
show less
Bad Web Bot
Web App Attack
Anonymous
2026-09-15 21:57:45
(16 hours ago)
Banned by Fail2Ban on server
Web App Attack
๐ณ๐ฑ
r4fo.com
2026-09-15 21:43:54
(16 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/appsec-vpatch
Web App Attack
Anonymous
2026-09-15 21:03:26
(17 hours ago)
Observed scanned 1 known-sensitive endpoint(s), e.g.: /firebase-config.json
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 21:01:42
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.30.203.116 (116.203.30.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.30.203.116 (116.203.30.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 17:01:38.300534 2026] [security2:error] [pid 32316:tid 32316] [client 34.30.203.116:37602] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipostsocialmedia.com"] [uri "/%2e%2e/%2e%2e/%2e%2e/%2e%2e/.env"] [unique_id "aqmyMou0aZwLGTO8Jp-4QgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Aetherweb Ark
2026-09-15 20:55:18
(17 hours ago)
(mod_security) mod_security (id:949110) triggered by 34.30.203.116 (US/United States/116.203.30.34.b ...
show more
(mod_security) mod_security (id:949110) triggered by 34.30.203.116 (US/United States/116.203.30.34.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
๐ง๐ช
taivas.nl
2026-09-15 20:02:11
(18 hours ago)
Bad_requests
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-15 19:59:06
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.30.203.116 (116.203.30.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.30.203.116 (116.203.30.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 15:59:02.325155 2026] [security2:error] [pid 10004:tid 10030] [client 34.30.203.116:52126] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dwcmachining.com"] [uri "/.git/HEAD"] [unique_id "aqmjhjK_RXebi7Lrqk8pTAAAAEs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
maxpower
2026-09-15 19:41:04
(18 hours ago)
(junkbot) REGOLA 8 - Junk Bot Blocked 34.30.203.116 (US/United States/116.203.30.34.bc.googleusercon ...
show more
(junkbot) REGOLA 8 - Junk Bot Blocked 34.30.203.116 (US/United States/116.203.30.34.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 34.30.203.116 - - [15/Sep/2026:21:41:01 +0200] "GET /z9x8c7v6b5-debug-trigger-dvlimpianti.org HTTP/2.0" 200 12105 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot)" "-" host=dvlimpianti.org
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-09-15 19:31:48
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.30.203.116 (116.203.30.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.30.203.116 (116.203.30.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 15:31:43.046989 2026] [security2:error] [pid 23300:tid 23300] [client 34.30.203.116:54378] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dvdmasters.com"] [uri "/.git/HEAD"] [unique_id "aqmdHzIogAs_IPXYIwUBfwAAACc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-15 19:04:07
(19 hours ago)
[ti-01ov] Web exploit scanning: 1 suspicious requests detected by fail2ban jail <name>. Example: 34. ...
show more
[ti-01ov] Web exploit scanning: 1 suspicious requests detected by fail2ban jail <name>. Example: 34.30.203.116 - - [15/Sep/2026:21:04:06 +0200] "GET /@fs/.env?raw&url?? HTTP/1.1" 301 643 "-" "Mozilla/5.0 (compatible; MistralAI-User/1.0; +https://mistral.ai/)"
...
show less
Bad Web Bot
Web App Attack