๐ง๐ท
dermatovirtual
2026-09-19 10:07:00
(6 days ago)
Dermato Virtual CSIRT: Malicious web exploit/scanning probes against app.dermatovirtual.com.br (Web ...
show more
Dermato Virtual CSIRT: Malicious web exploit/scanning probes against app.dermatovirtual.com.br (Web Server Ports 80/443). 51 unauthorized requests recorded between 2026-09-18 10:01:43 UTC and 2026-09-18 10:01:53 UTC (rate: ~51 req/min). Edge perimeter firewall drop active.
Log sample:
[2026-09-18 10:01:53 UTC] IP: 34.52.205.228 - W3C IIS (Port 443): GET /.env.local -> HTTP 404 [CLIENT: 34.52.205.228]
[2026-09-18 10:01:53 UTC] IP: 34.52.205.228 - W3C IIS (Port 443): GET /js../.env -> HTTP 404 [CLIENT: 34.52.205.228]
[2026-09-18 10:01:53 UTC] IP: 34.52.205.228 - W3C IIS (Port 443): GET /public../.env -> HTTP 404 [CLIENT: 34.52.205.228]
show less
Bad Web Bot
Web App Attack
๐ฌ๐ง
andypiper
2026-09-19 01:01:28
(6 days ago)
CrowdSec ban for AbuseIPDB Top List
Brute-Force
Web App Attack
๐ง๐ท
Sysadmin-CLC
2026-09-19 00:14:19
(6 days ago)
Probing and trying to access sensitive files caught in f2b nginx-forbidden filter
Web App Attack
Port Scan
๐ง๐ท
dominioz
2026-09-19 00:12:13
(6 days ago)
34.52.205.228 - - [18/Sep/2026:21:12:08 -0300] "GET /..%2f.env HTTP/1.1" 400 173 "-" "-" "-"
34.52.2 ...
show more
34.52.205.228 - - [18/Sep/2026:21:12:08 -0300] "GET /..%2f.env HTTP/1.1" 400 173 "-" "-" "-"
34.52.205.228 - - [18/Sep/2026:21:12:08 -0300] "GET /%2e%2e/.env HTTP/1.1" 400 173 "-" "-" "-"
34.52.205.228 - - [18/Sep/2026:21:12:08 -0300] "GET /..%2f..%2f.env HTTP/1.1" 400 173 "-" "-" "-"
34.52.205.228 - - [18/Sep/2026:21:12:09 -0300] "GET /public/plugins/alertlist/../../../../../../../../proc/self/environ HTTP/1.1" 400 173 "-" "-" "-"
34.52.205.228 - - [18/Sep/2026:21:12:09 -0300] "GET /api/uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2fproc/self/environ HTTP/1.1" 400 173 "-" "-" "-"
34.52.205.228 - - [18/Sep/2026:21:12:10 -0300] "GET /api/uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f.env HTTP/1.1" 400 173 "-" "-" "-"
34.52.205.228 - - [18/Sep/2026:21:12:10 -0300] "GET /icons/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/proc/self/environ HTTP/1.1" 400 173 "-" "-" "-"
34.52.205.228 - - [18/Sep/2026:21:12:10 -0300] "GET /uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f.env HTTP/1.1" 400 173 "-" "-" "-"
3
...
show less
Web App Attack
๐บ๐ธ
paulo.apoloni
2026-09-18 19:51:24
(1 week ago)
34.52.205.228 - - [18/Sep/2026:16:51:23 -0300] "GET /.ssh/id_ed25519 HTTP/2.0" 404 2352 "-" "Mozilla ...
show more
34.52.205.228 - - [18/Sep/2026:16:51:23 -0300] "GET /.ssh/id_ed25519 HTTP/2.0" 404 2352 "-" "Mozilla/5.0 (compatible; PanguBot/1.0; +https://www.huaweicloud.com/)"
34.52.205.228 - - [18/Sep/2026:16:51:23 -0300] "GET /.ssh/id_ecdsa HTTP/2.0" 404 2353 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot)"
34.52.205.228 - - [18/Sep/2026:16:51:23 -0300] "GET /.ssh/id_rsa HTTP/2.0" 404 2354 "-" "Mozilla/5.0 (compatible; MoonshotBot/1.0; +https://kimi.ai/)"
34.52.205.228 - - [18/Sep/2026:16:51:23 -0300] "GET /.ssh/id_dsa HTTP/2.0" 404 2354 "-" "Mozilla/5.0 (compatible; Bravebot/1.0; +https://brave.com/search/)"
34.52.205.228 - - [18/Sep/2026:16:51:23 -0300] "GET /.ssh/config HTTP/2.0" 404 2353 "-" "Mozilla/5.0 (compatible; YiBot/1.0; +https://01.ai/)"
...
show less
Web App Attack
๐ง๐ท
SvrAdmin
2026-09-18 17:27:30
(1 week ago)
[204] (cpanel) Failed cPanel login from 34.52.205.228 (BE/Belgium/228.205.52.34.bc.googleusercontent ...
show more
[204] (cpanel) Failed cPanel login from 34.52.205.228 (BE/Belgium/228.205.52.34.bc.googleusercontent.com): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CPANEL; Logs: [2026-09-18 14:27:23 -0300] info [cpaneld] 34.52.205.228 - - "GET /.git/HEAD HTTP/1.1" FAILED LOGIN cpaneld: login attempt without username
[2026-09-18 14:27:23 -0300] info [cpaneld] 34.52.205.228 - - "GET /.git/config HTTP/1.1" FAILED LOGIN cpaneld: login attempt without username
[2026-09-18 14:27:23 -0300] info [cpaneld] 34.52.205.228 - - "GET /.aws/credentials HTTP/1.1" FAILED LOGIN cpaneld: login attempt without username
[2026-09-18 14:27:23 -0300] info [cpaneld] 34.52.205.228 - - "GET /z9x8c7v6b5-debug-trigger-cpanel.portaldebeltrao.com.br HTTP/1.1" FAILED LOGIN cpaneld: login attempt without username
[2026-09-18 14:27:23 -0300] info [cpaneld] 34.52.205.228 - - "GET /dist/manifest.json HTTP/1.1" FAILED LOGIN cpaneld: login attempt without username
show less
Port Scan
Hacking
Brute-Force
Exploited Host
๐ง๐ท
govfacil.app
2026-09-18 16:47:01
(1 week ago)
(cpanel) Failed cPanel login from 34.52.205.228 (BE/Belgium/228.205.52.34.bc.googleusercontent.com): ...
show more
(cpanel) Failed cPanel login from 34.52.205.228 (BE/Belgium/228.205.52.34.bc.googleusercontent.com): 50 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CPANEL; Logs: [2026-09-18 13:46:47 -0300] info [cpaneld] 34.52.205.228 - - "GET /.vite/manifest.json HTTP/1.1" FAILED LOGIN cpaneld: login attempt without username
[2026-09-18 13:46:48 -0300] info [cpaneld] 34.52.205.228 - - "GET /__/firebase/init.json HTTP/1.1" FAILED LOGIN cpaneld: login attempt without username
[2026-09-18 13:46:48 -0300] info [cpaneld] 34.52.205.228 - - "POST /api/graphql HTTP/1.1" FAILED LOGIN cpaneld: login attempt without username
[2026-09-18 13:46:48 -0300] info [cpaneld] 34.52.205.228 - - "GET /app-config.json HTTP/1.1" FAILED LOGIN cpaneld: login attempt without username
[2026-09-18 13:46:49 -0300] info [cpaneld] 34.52.205.228 - - "GET /api/v1/env HTTP/1.1" FAILED LOGIN cpaneld: login attempt without username
[2026-09-18 13:46:49 -0300] info [cpaneld] 34.52.205.228 - - "GET /swagger.json HTTP/1. [truncated]
show less
Brute-Force
๐ง๐ท
Caue Henrique
2026-09-18 13:00:37
(1 week ago)
Multiple common web attacks from same source ip.
Web Spam
Hacking
Web App Attack
๐ง๐ท
dermatovirtual
2026-09-18 10:05:05
(1 week ago)
Dermato Virtual CSIRT: Malicious web exploit/scanning probes against app.dermatovirtual.com.br (Web ...
show more
Dermato Virtual CSIRT: Malicious web exploit/scanning probes against app.dermatovirtual.com.br (Web Server Ports 80/443). 51 unauthorized requests recorded between 2026-09-18 10:01:43 UTC and 2026-09-18 10:01:53 UTC (rate: ~51 req/min). Edge perimeter firewall drop active.
Log sample:
[2026-09-18 10:01:53 UTC] IP: 34.52.205.228 - W3C IIS (Port 443): GET /.env.local -> HTTP 404 [CLIENT: 34.52.205.228]
[2026-09-18 10:01:53 UTC] IP: 34.52.205.228 - W3C IIS (Port 443): GET /js../.env -> HTTP 404 [CLIENT: 34.52.205.228]
[2026-09-18 10:01:53 UTC] IP: 34.52.205.228 - W3C IIS (Port 443): GET /public../.env -> HTTP 404 [CLIENT: 34.52.205.228]
show less
Bad Web Bot
Web App Attack
Anonymous
2026-09-18 09:21:44
(1 week ago)
34.52.205.228 - - [18/Sep/2026:06:21:43 -0300] "GET /.git/config HTTP/2.0" 403 107 "-" "Mozilla/5.0 ...
show more
34.52.205.228 - - [18/Sep/2026:06:21:43 -0300] "GET /.git/config HTTP/2.0" 403 107 "-" "Mozilla/5.0 (compatible; Bravebot/1.0; +https://brave.com/search/)"
...
show less
Port Scan
Hacking
SQL Injection
Brute-Force
Bad Web Bot
Exploited Host
๐ซ๐ท
mrcrassi
2026-09-18 08:30:50
(1 week ago)
Triggered Cloudflare WAF (firewallManaged) from BE.
Action taken: BLOCK
Protocol: HTTP/1.1 (POST met ...
show more
Triggered Cloudflare WAF (firewallManaged) from BE.
Action taken: BLOCK
Protocol: HTTP/1.1 (POST method)
Endpoint: /api
UA: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexitybot)
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐จ๐ฆ
cubie
2026-09-18 08:02:00
(1 week ago)
Port Scan: Admin Enumeration - Reported by CubieCloud Firewall [CFW_H351-004]
Port Scan
๐บ๐ธ
paulo.apoloni
2026-09-18 07:58:23
(1 week ago)
34.52.205.228 - - [18/Sep/2026:04:58:23 -0300] "GET /model/.env HTTP/2.0" 444 0 "-" "Mozilla/5.0 (co ...
show more
34.52.205.228 - - [18/Sep/2026:04:58:23 -0300] "GET /model/.env HTTP/2.0" 444 0 "-" "Mozilla/5.0 (compatible; Hunyuan/1.0; +https://hunyuan.tencent.com/)"
34.52.205.228 - - [18/Sep/2026:04:58:23 -0300] "GET /.aws/credentials HTTP/2.0" 444 0 "-" "Mozilla/5.0 (compatible; cohere-ai; +https://cohere.com/crawler)"
34.52.205.228 - - [18/Sep/2026:04:58:23 -0300] "GET /.git/HEAD HTTP/2.0" 444 0 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; GPTBot/1.3; +https://openai.com/gptbot)"
34.52.205.228 - - [18/Sep/2026:04:58:23 -0300] "GET /.git/config HTTP/2.0" 444 0 "-" "Mozilla/5.0 (compatible; KimiBot/1.0; +https://kimi.ai/)"
34.52.205.228 - - [18/Sep/2026:04:58:23 -0300] "GET /.aws/config HTTP/2.0" 444 0 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot)"
...
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
bazter.pro
2026-09-18 03:52:10
(1 week ago)
Fail2Ban: plesk-bot-aggressive - 15 failures
Port Scan
Bad Web Bot
Web App Attack
๐ฉ๐ช
Skyrider
2026-09-18 03:50:28
(1 week ago)
Nginx: HTTP 4xx probe/scan attempts. Automated fail2ban report.
Bad Web Bot
Web App Attack