๐ง๐ท
tiwanetbr
2026-09-18 09:21:14
(3 minutes ago)
Fail2Ban: Unauthorized connection / brute-force attempt detected (protocol: Web, failed attempts: 5) ...
show more
Fail2Ban: Unauthorized connection / brute-force attempt detected (protocol: Web, failed attempts: 5).
show less
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-09-18 08:35:54
(49 minutes ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-193)
Hacking
Web App Attack
Anonymous
2026-09-18 08:18:32
(1 hour ago)
34.50.66.91 - - [18/Sep/2026:03:18:30 -0500] "GET /.env HTTP/1.1" 403 199 "-" "Mozilla/5.0 (X11; Lin ...
show more
34.50.66.91 - - [18/Sep/2026:03:18:30 -0500] "GET /.env HTTP/1.1" 403 199 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" 34.50.66.91
34.50.66.91 - - [18/Sep/2026:03:18:30 -0500] "GET /.env.local HTTP/1.1" 403 199 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" 34.50.66.91
34.50.66.91 - - [18/Sep/2026:03:18:30 -0500] "GET /.env.production HTTP/1.1" 403 199 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" 34.50.66.91
34.50.66.91 - - [18/Sep/2026:03:18:30 -0500] "GET /.env.staging HTTP/1.1" 403 199 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" 34.50.66.91
34.50.66.91 - - [18/Sep/2026:03:18:31 -0500] "GET /.env.development HTTP/1.1" 403 199 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" 34.50
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ณ
evicky2002
2026-09-18 06:00:02
(3 hours ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐ต๐ฑ
lns.bz
2026-09-18 04:57:36
(4 hours ago)
Web app attack [PL.Lu]
Exploited Host
Web App Attack
๐จ๐ญ
4server
2026-09-18 03:52:49
(5 hours ago)
[FriSep1805:52:41.0808952026][security2:error][pid1178179:tid1178307][client34.50.66.91:0]ModSecurit ...
show more
[FriSep1805:52:41.0808952026][security2:error][pid1178179:tid1178307][client34.50.66.91:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"\(\?:\\\\\\\\\$\(\?:\\\\\\\\\(\(\?:\\\\\\\\\(.\*\\\\\\\\\)\|.\*\)\\\\\\\\\)\|\\\\\\\\{.\*\\\\\\\\}\)\|[\<\>]\\\\\\\\\(.\*\\\\\\\\\)\)\"atARGS:0.[file\"/etc/apache2/conf.d/modsec_rules/10_asl_rules.conf\"][line\"396\"][id\"393655\"][rev\"17\"][msg\"Atomicorp.comWAFRules:PossibleRemoteCommandExecution:UnixShellExpressionFound\"][data\"MatchedData:\$\(\(41\*271\)\)foundwithinARGS:0:{then:\$1:__proto__:thenstatus:resolved_modelreason:-1value:{then:\$b1337}_response:{_prefix:varres=process.mainmodule.require\(child_process\).execsync\(echo\$\(\(41\*271\)\)\|base64-w0\).tostring\(\).trim\(\)throwobject.assign\(newerror\(next_redirect\){digest:\`next_redirectpush/login\?a=\${res}307\`}\)_chunks:\$q2_formdata:{get:\$1:constructor:constructor}}}\"][tag\"attack-rce\"][hostname\"rssolution.ch\"][uri\"/\"][unique_id\"aqy1iTjS2IUKpsXulo9T_AAAARU\"]
show less
Hacking
Web App Attack
๐ฐ๐ท
doll.gl
2026-09-18 03:07:01
(6 hours ago)
CrowdSec: Ip 34.50.66.91 performed 'crowdsecurity/http-sensitive-files' (5 events over 1.049320933s) ...
show more
CrowdSec: Ip 34.50.66.91 performed 'crowdsecurity/http-sensitive-files' (5 events over 1.049320933s) at 2026-09-18 03:07:00.11204179 +0000 UTC (scenario: crowdsecurity/http-sensitive-files)
show less
Port Scan
Web App Attack
๐ซ๐ท
Nop Nop
2026-09-18 02:02:37
(7 hours ago)
CrowdSec ban: crowdsecurity/http-sensitive-files
Port Scan
๐บ๐ธ
Sonoflet
2026-09-18 01:48:52
(7 hours ago)
CrowdSec detection | scenario: http-probing
Port Scan
Web App Attack
๐ฐ๐ท
doll.gl
2026-09-18 01:03:04
(8 hours ago)
CrowdSec: Ip 34.50.66.91 performed 'crowdsecurity/http-sensitive-files' (5 events over 1.68407525s) ...
show more
CrowdSec: Ip 34.50.66.91 performed 'crowdsecurity/http-sensitive-files' (5 events over 1.68407525s) at 2026-09-18 01:03:02.961462628 +0000 UTC (scenario: crowdsecurity/http-sensitive-files)
show less
Port Scan
Web App Attack
๐ฌ๐ง
andypiper
2026-09-18 01:01:45
(8 hours ago)
CrowdSec ban for AbuseIPDB Top List
Brute-Force
Web App Attack
๐ณ๐ฑ
thedreamer.nl
2026-09-18 00:12:48
(9 hours ago)
34.50.66.91 - - [18/Sep/2026:02:10:50 +0200] "GET /.git/config HTTP/1.1" 499 0 "-" "Mozilla/5.0 (Mac ...
show more
34.50.66.91 - - [18/Sep/2026:02:10:50 +0200] "GET /.git/config HTTP/1.1" 499 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "ID" "Jakarta" "-6.21140" "106.84460"
34.50.66.91 - - [18/Sep/2026:02:10:51 +0200] "GET /.env HTTP/1.1" 499 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "ID" "Jakarta" "-6.21140" "106.84460"
34.50.66.91 - - [18/Sep/2026:02:10:52 +0200] "GET /.env.local HTTP/1.1" 499 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "ID" "Jakarta" "-6.21140" "106.84460"
34.50.66.91 - - [18/Sep/2026:02:10:53 +0200] "GET /.env.production HTTP/1.1" 499 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "ID" "Jakarta" "-6.21140" "106.84460"
...
show less
Hacking
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
mnazibo
2026-09-17 23:00:12
(10 hours ago)
Date: Sep 18 01:50:54 2026 EAT | Reported IP: 34.50.66.91 mod_security | id: 932130 932235 932260 93 ...
show more
Date: Sep 18 01:50:54 2026 EAT | Reported IP: 34.50.66.91 mod_security | id: 932130 932235 932260 933135 934100 934130 942151 942550 949110 930130 920440 920500 | ID/usernameab.my_domain/- | Connections: 1 | Blocked: Permanent Block: [LF_MODSEC] | Logs: ; Remote Command Execution: Unix Shell Expression Found; Remote Command Execution: Unix Command Injection (command without evasion); Remote Command Execution: Direct Unix Command Execution; PHP Injection Attack: Variable Access Found; Node.js Injection Attack 1/2; Node.js Injection Attack 1/2; Node.js Injection Attack 1/2; JavaScript Prototype Pollution; JavaScript Prototype Pollution; SQL Injection Attack: SQL function name detected; JSON-Based SQL Injection; Inbound Anomaly Score Exceeded (Total Score: 55); Restricted File Access Attempt; Remote Command Execution: Unix Shell Expression Found; Remote Command Execution: Unix Command Injection (command without evasion); Remote Command Exe
show less
SQL Injection
Brute-Force
Bad Web Bot
๐ฉ๐ช
snhosting
2026-09-17 22:56:50
(10 hours ago)
34.50.66.91 - - [18/Sep/2026:00:56:40 +0200] "GET /.git/config HTTP/1.1" 404 9 "-" "Mozilla/5.0 (Win ...
show more
34.50.66.91 - - [18/Sep/2026:00:56:40 +0200] "GET /.git/config HTTP/1.1" 404 9 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.50.66.91 - - [18/Sep/2026:00:56:40 +0200] "GET /.env HTTP/1.1" 404 9 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.50.66.91 - - [18/Sep/2026:00:56:40 +0200] "GET /.env.local HTTP/1.1" 404 9 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.50.66.91 - - [18/Sep/2026:00:56:41 +0200] "GET /.env.production HTTP/1.1" 404 9 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.50.66.91 - - [18/Sep/2026:00:56:41 +0200] "GET /.env.staging HTTP/1.1" 404 9 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
DNS Compromise
DNS Poisoning
Phishing
Email Spam
Brute-Force
Web App Attack
SSH
๐ฆ๐บ
electronico
2026-09-17 22:50:02
(10 hours ago)
34.50.66.91 - - [18/Sep/2026:09:50:00 +1100] "GET /.git/config HTTP/1.1" 404 241 "-" "Mozilla/5.0 (M ...
show more
34.50.66.91 - - [18/Sep/2026:09:50:00 +1100] "GET /.git/config HTTP/1.1" 404 241 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.50.66.91 - - [18/Sep/2026:09:50:00 +1100] "GET /.env HTTP/1.1" 404 241 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.50.66.91 - - [18/Sep/2026:09:50:01 +1100] "GET /.env.local HTTP/1.1" 404 241 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.50.66.91 - - [18/Sep/2026:09:50:01 +1100] "GET /.env.production HTTP/1.1" 404 241 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.50.66.91 - - [18/Sep/2026:09:50:01 +1100] "GET /.env.staging HTTP/1.1" 404 241 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131
...
show less
Brute-Force
Web App Attack