๐ฉ๐ช
mondor.ro
2026-07-26 08:20:57
(43 minutes ago)
Cluster member 148.251.176.225 (DE/Germany/antares.webyouridea.ro) said, DENY 34.48.185.220, Reason: ...
show more
Cluster member 148.251.176.225 (DE/Germany/antares.webyouridea.ro) said, DENY 34.48.185.220, Reason:[(mod_security) mod_security (id:210832) triggered by 34.48.185.220 (US/United States/220.185.48.34.bc.googleusercontent.com): 3 in the last 3600 secs]; Ports: *; Direction: inout; Trigger: LF_CLUSTER; Logs:
show less
Port Scan
๐ฎ๐ณ
evicky2002
2026-07-26 06:00:00
(3 hours ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐ง๐ช
voormedia
2026-07-26 05:22:30
(3 hours ago)
Accessed trap at '/.aws/config'
Web App Attack
๐ซ๐ท
Dorian GRANDHAY
2026-07-26 03:04:59
(5 hours ago)
(PERMBLOCK) 34.48.185.220 (US/United States/220.185.48.34.bc.googleusercontent.com) has had more tha ...
show more
(PERMBLOCK) 34.48.185.220 (US/United States/220.185.48.34.bc.googleusercontent.com) has had more than 4 temp blocks in the last 604800 secs; Ports: *; Direction: inout; Trigger: LF_PERMBLOCK_COUNT; Logs:
show less
Port Scan
๐ฎ๐น
alessio loto
2026-07-26 02:32:35
(6 hours ago)
WAF Detection: Security_Scanner_Blocked (High Risk IP). AI Confirmed Attack Payload.
Bad Web Bot
Anonymous
2026-07-26 02:24:49
(6 hours ago)
[Sun Jul 26 04:24:47.760571 2026] [proxy_fcgi:error] [pid 41873:tid 42010] [client 34.48.185.220:575 ...
show more
[Sun Jul 26 04:24:47.760571 2026] [proxy_fcgi:error] [pid 41873:tid 42010] [client 34.48.185.220:57546] AH01071: Got error 'Primary script unknown'
[Sun Jul 26 04:24:47.838923 2026] [proxy_fcgi:error] [pid 42075:tid 42121] [client 34.48.185.220:47448] AH01071: Got error 'Primary script unknown'
[Sun Jul 26 04:24:47.886484 2026] [proxy_fcgi:error] [pid 42075:tid 42119] [client 34.48.185.220:57542] AH01071: Got error 'Primary script unknown'
[Sun Jul 26 04:24:48.131554 2026] [proxy_fcgi:error] [pid 41871:tid 42044] [client 34.48.185.220:57558] AH01071: Got error 'Primary script unknown'
[Sun Jul 26 04:24:48.235737 2026] [proxy_fcgi:error] [pid 42075:tid 42126] [client 34.48.185.220:57594] AH01071: Got error 'Primary script unknown'
...
show less
Brute-Force
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-07-26 01:21:06
(7 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐ฉ๐ช
LRob
2026-07-25 23:18:08
(9 hours ago)
CrowdSec: crowdsecurity/http-sensitive-files | req: /.aws/config | 5 distinct paths | UA: Mozilla/5. ...
show more
CrowdSec: crowdsecurity/http-sensitive-files | req: /.aws/config | 5 distinct paths | UA: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; Claude-SearchBot/1.0; +mailto:[email protected]
show less
Hacking
Anonymous
2026-07-25 22:30:53
(10 hours ago)
34.48.185.220 - - [26/Jul/2026:00:30:45 +0200] "GET /webpack-stats.json HTTP/1.1" 404 29859
34.48.18 ...
show more
34.48.185.220 - - [26/Jul/2026:00:30:45 +0200] "GET /webpack-stats.json HTTP/1.1" 404 29859
34.48.185.220 - - [26/Jul/2026:00:30:45 +0200] "GET /z9x8c7v6b5-debug-trigger-crypcool.com HTTP/1.1" 404 29859
34.48.185.220 - - [26/Jul/2026:00:30:46 +0200] "GET /secrets.json HTTP/1.1" 404 29859
34.48.185.220 - - [26/Jul/2026:00:30:47 +0200] "GET /secrets.yml HTTP/1.1" 404 29859
34.48.185.220 - - [26/Jul/2026:00:30:47 +0200] "GET /service-account.json HTTP/1.1" 404 29859
34.48.185.220 - - [26/Jul/2026:00:30:47 +0200] "GET /key.json HTTP/1.1" 404 29859
34.48.185.220 - - [26/Jul/2026:00:30:47 +0200] "GET /firebase-adminsdk.json HTTP/1.1" 404 29859
34.48.185.220 - - [26/Jul/2026:00:30:48 +0200] "GET /credentials.json HTTP/1.1" 404 28319
34.48.185.220 - - [26/Jul/2026:00:30:47 +0200] "GET /serviceAccountKey.json HTTP/1.1" 404 29859
34.48.185.220 - - [26/Jul/2026:00:30:48 +0200] "GET /terraform.tfstate HTTP/1.1" 404 28319
...
show less
Web Spam
Web App Attack
๐บ๐ธ
jsjdmediallc
2026-07-25 21:20:04
(11 hours ago)
Auto-blocked: score 126 (threshold 10). Tier: HIGH. Hits: 50. Flags: high-rate, 404-scanner, env-fil ...
show more
Auto-blocked: score 126 (threshold 10). Tier: HIGH. Hits: 50. Flags: high-rate, 404-scanner, env-file, backup-file, log-file, credentials, conf-file, ssh-key, ssh-dir, script-ua, secret-file, svn-exposure, aws-creds. Paths: /contact-associations-school-districts/, /contact-advertisers/, /case-studies/, /target-marketing/, /about-us/
show less
Bad Web Bot
Web App Attack
Anonymous
2026-07-25 21:07:02
(11 hours ago)
[Sat Jul 25 23:07:01.330004 2026] [authz_core:error] [pid 1332:tid 1515] [client 34.48.185.220:33746 ...
show more
[Sat Jul 25 23:07:01.330004 2026] [authz_core:error] [pid 1332:tid 1515] [client 34.48.185.220:33746] AH01630: client denied by server configuration: /var/www/wordp/.htpasswd
...
show less
Brute-Force
Web App Attack
๐ณ๐ฑ
Savvii
2026-07-25 20:46:56
(12 hours ago)
20 attempts against mh-misbehave-ban on burne
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-25 17:34:43
(15 hours ago)
[Sat Jul 25 19:34:42.230984 2026] [authz_core:error] [pid 1329:tid 1486] [client 34.48.185.220:58828 ...
show more
[Sat Jul 25 19:34:42.230984 2026] [authz_core:error] [pid 1329:tid 1486] [client 34.48.185.220:58828] AH01630: client denied by server configuration: /var/www/wordp/.htpasswd
...
show less
Brute-Force
Web App Attack
๐ซ๐ท
bazter.pro
2026-07-25 17:10:33
(15 hours ago)
Fail2Ban: plesk-bot-aggressive - 15 failures
Port Scan
Bad Web Bot
Web App Attack
๐จ๐ฟ
ptlab
2026-07-25 16:45:34
(16 hours ago)
Detected wp_config attack from WP-host.
Hacking
Web App Attack