Anonymous
2026-09-29 00:10:37
(1 week ago)
abuse ssl access
Hacking
Brute-Force
Web App Attack
Anonymous
2026-09-28 15:53:21
(1 week ago)
Reported from Nginx log analysis 17. Log: 34.52.215.30 - - [28/Sep/2026:xx:xx:xx 0200] "GET / HTTP/ ...
show more
Reported from Nginx log analysis 17. Log: 34.52.215.30 - - [28/Sep/2026:xx:xx:xx 0200] "GET / HTTP/1.1" xxx xxx "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/127.0.0.0 Safari/537.36" "-" "BE Belgium Brussels" "AS396982" "Google LLC" | 34.52.215.30 - - [28/Sep/2026:xx:xx:xx 0200] "GET / HTTP/1.1" xxx xxx "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/127.0.0.0 Safari/537.36" "-" "BE Belgium Brussels" "AS396982" "Google LLC"
show less
Port Scan
Brute-Force
SSH
๐ฉ๐ช
ghostwarriors
2026-09-28 12:50:06
(1 week ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
Anonymous
2026-09-28 12:27:43
(1 week ago)
Fail2Ban triggered
Web App Attack
๐ฏ๐ต
www.winos.me
2026-09-28 12:26:15
(1 week ago)
Shield: Layer4 Port 9 Trap
Port Scan
Hacking
Anonymous
2026-09-28 12:09:01
(1 week ago)
34.52.215.30 - - [28/Sep/2026:21:08:58 +0900] "OPTIONS / HTTP/1.1" 403 4655 "-" "Mozilla/5.0 (compat ...
show more
34.52.215.30 - - [28/Sep/2026:21:08:58 +0900] "OPTIONS / HTTP/1.1" 403 4655 "-" "Mozilla/5.0 (compatible)"
34.52.215.30 - - [28/Sep/2026:21:08:59 +0900] "NAJV / HTTP/1.1" 403 4656 "-" "Mozilla/5.0 (compatible)"
34.52.215.30 - - [28/Sep/2026:21:08:59 +0900] "GET / HTTP/1.1" 403 4656 "-" "Mozilla/5.0 (compatible; nmap-http-info)"
34.52.215.30 - - [28/Sep/2026:21:09:00 +0900] "GET / HTTP/1.1" 403 4657 "-" "Mozilla/5.0 (compatible)"
34.52.215.30 - - [28/Sep/2026:21:09:00 +0900] "GET /favicon.ico HTTP/1.1" 403 4657 "-" "Mozilla/5.0 (compatible)"
...
show less
Brute-Force
Anonymous
2026-09-28 11:35:18
(1 week ago)
443/tcp (1 or more attempts)
Port Scan
๐ช๐ธ
robotstxt
2026-09-28 11:06:47
(1 week ago)
34.52.215.30 - - [28/Sep/2026:11:06:42 +0000] "GET / HTTP/1.1" 400 291 "-" "Mozilla/5.0 (compatible) ...
show more
34.52.215.30 - - [28/Sep/2026:11:06:42 +0000] "GET / HTTP/1.1" 400 291 "-" "Mozilla/5.0 (compatible)" "-" edge="34.52.215.30"
34.52.215.30 - - [28/Sep/2026:11:06:42 +0000] "HEAD / HTTP/1.1" 400 0 "-" "Mozilla/5.0 (compatible)" "-" edge="34.52.215.30"
34.52.215.30 - - [28/Sep/2026:11:06:43 +0000] "POST / HTTP/1.1" 400 291 "-" "Mozilla/5.0 (compatible)" "-" edge="34.52.215.30"
34.52.215.30 - - [28/Sep/2026:11:06:43 +0000] "OPTIONS / HTTP/1.1" 400 291 "-" "Mozilla/5.0 (compatible)" "-" edge="34.52.215.30"
34.52.215.30 - - [28/Sep/2026:11:06:44 +0000] ";\x00\x00\x00\x01\x00\x00\x00\x00\x00\x00\x00\xD4\x07\x00\x00\x00\x00\x00\x00admin.$cmd\x00\x00\x00\x00\x00\xFF\xFF\xFF\xFF\x14\x00\x00\x00\x01hello\x00\x00\x00\x00\x00\x00\x00\xF0?\x00" 400 193 "-" "-" "-" edge="34.52.215.30"
...
show less
Web Spam
Web App Attack
๐ต๐ฑ
ToJa
2026-09-28 10:36:45
(1 week ago)
Web App Attack - Scanning for vulnerable files:
34.52.215.30 - - [28/Sep/2026:12:36:38 +0200] "GET / ...
show more
Web App Attack - Scanning for vulnerable files:
34.52.215.30 - - [28/Sep/2026:12:36:38 +0200] "GET / HTTP/1.1" 403 168 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/127.0.0.0 Safari/537.36"
show less
Web App Attack
๐ซ๐ท
masterguru
2026-09-28 10:36:04
(1 week ago)
Host header is a numeric IP address. Pattern match "(?:^( (920350-196)
Hacking
Bad Web Bot
๐ฉ๐ฐ
RhQM
2026-09-28 09:22:01
(1 week ago)
Bad Web Bot
Exploited Host
Web App Attack
๐ซ๐ท
pm33
2026-09-28 06:30:44
(1 week ago)
Probing for resource vulnerabilities HTTP(S)
Web App Attack
๐ฉ๐ช
MaxMeier
2026-09-28 06:24:34
(1 week ago)
34.52.215.30 - - [28/Sep/2026:08:23:33 +0200] "GET / HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Windows NT 10 ...
show more
34.52.215.30 - - [28/Sep/2026:08:23:33 +0200] "GET / HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/127.0.0.0 Safari/537.36"
34.52.215.30 - - [28/Sep/2026:08:23:34 +0200] "GET / HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/127.0.0.0 Safari/537.36"
34.52.215.30 - - [28/Sep/2026:08:23:48 +0200] "07\xA0\x03\x02\x01`\xA100.0,\xA0*\x04(NTLMSSP\x00\x01\x00\x00\x00\xF7\xBA\xDB\xE2\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00" 400 150 "-" "-"
34.52.215.30 - - [28/Sep/2026:08:23:58 +0200] "0:\x02\x04Y\xD7\xF8k`2\x02\x01\x03\x04\x17cn=vxyewujemqvikozhehxl\x80\x14vxyewujemqvikozhehxl" 400 150 "-" "-"
34.52.215.30 - - [28/Sep/2026:08:24:08 +0200] "\x00\x00\x00C\x00\x12\x00\x00\x1E3\xF4\x81\x00\x1Fconsumer-Offset Explorer 2.2-18\x00\x12apache-kafka-java\x062.4.0\x00" 400 150 "-" "-"
34.52.215.30 - - [28/Sep/2026:08:24:08 +02
...
show less
Bad Web Bot
Web App Attack
๐น๐ญ
MWA SOC
2026-09-28 06:00:33
(1 week ago)
Hacking
๐ง๐ท
diego
2026-09-28 05:56:29
(1 week ago)
[probe-168-134] 2026-09-28 05:36:48, Client: 34.52.215.30, Protocol: 6, Unauthorized activity to HTT ...
show more
[probe-168-134] 2026-09-28 05:36:48, Client: 34.52.215.30, Protocol: 6, Unauthorized activity to HTTP: GET /
show less
Web App Attack