๐ฉ๐ช
Balthasar Morpheus Jรถrmundur (JKweb Service)
2026-07-23 07:15:47
(11 hours ago)
JKweb Security: Severe and dangerous web attack detected. Attacker permanently banned by Fail2Ban.
Port Scan
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-07-22 22:34:57
(19 hours ago)
Excessive multi-domain requests
Brute-Force
๐ซ๐ท
IRISIO
2026-07-22 16:32:56
(1 day ago)
scans/SQL injection/spam posts : 6114 queries
Web App Attack
SQL Injection
Anonymous
2026-07-22 11:26:21
(1 day ago)
Suspicious or malicious traffic has been detected
Web App Attack
Anonymous
2026-07-21 22:58:16
(1 day ago)
34.65.36.15 - - [21/Jul/2026:17:58:14 -0500] "GET /.env.example HTTP/1.1" 403 199 "-" "Mozilla/5.0 ( ...
show more
34.65.36.15 - - [21/Jul/2026:17:58:14 -0500] "GET /.env.example HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; GoogleOther; +http://www.google.com/bot.html)" 34.65.36.15
34.65.36.15 - - [21/Jul/2026:17:58:15 -0500] "GET /.env.production HTTP/1.1" 403 199 "-" "CCBot/2.0 (https://commoncrawl.org/faq/)" 34.65.36.15
34.65.36.15 - - [21/Jul/2026:17:58:15 -0500] "GET /.env HTTP/1.1" 403 199 "-" "CCBot/2.0 (https://commoncrawl.org/faq/)" 34.65.36.15
34.65.36.15 - - [21/Jul/2026:17:58:15 -0500] "GET /.env.staging HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot)" 34.65.36.15
34.65.36.15 - - [21/Jul/2026:17:58:15 -0500] "GET /.env.backup HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; GoogleOther; +http://www.google.com/bot.html)" 34.65.36.15
34.65.36.15 - - [21/Jul/2026:17:58:15 -0500] "GET /.env.bak HTTP/1.1" 403 199 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot" 34.
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ฌ
WMK965
2026-07-21 22:52:08
(1 day ago)
34.65.36.15 - - [22/Jul/2026:06:52:08 +0800] "GET /secrets.json HTTP/2.0" 404 1424 "-" "Mozilla/5.0 ...
show more
34.65.36.15 - - [22/Jul/2026:06:52:08 +0800] "GET /secrets.json HTTP/2.0" 404 1424 "-" "Mozilla/5.0 (compatible; Amzn-SearchBot/1.0; +https://developer.amazon.com/support/amazonbot)" "-"
34.65.36.15 - - [22/Jul/2026:06:52:08 +0800] "GET /wp-json HTTP/2.0" 404 1424 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; GPTBot/1.3; +https://openai.com/gptbot)" "-"
34.65.36.15 - - [22/Jul/2026:06:52:08 +0800] "GET /secrets.yml HTTP/2.0" 404 1424 "-" "Mozilla/5.0 (compatible; Applebot-Extended/0.1; +http://www.apple.com/go/applebot)" "-"
34.65.36.15 - - [22/Jul/2026:06:52:08 +0800] "GET /__/firebase/init.json HTTP/2.0" 404 1424 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" "-"
34.65.36.15 - - [22/Jul/2026:06:52:08 +0800] "GET /service-account.json HTTP/2.0" 404 1424 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ClaudeBot/1.0; +mailto:[email protected] " "-"
show less
Port Scan
Web App Attack
๐บ๐ธ
WizardsToolkit
2026-07-21 17:31:20
(2 days ago)
tried to access forbidden files; attempted to access /storage/logs/laravel.log
Web App Attack
๐ณ๐ฑ
Site.eu
2026-07-21 17:22:44
(2 days ago)
Excessive multi-domain requests
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-07-21 16:54:34
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.65.36.15 (15.36.65.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.36.15 (15.36.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 12:54:25.588877 2026] [security2:error] [pid 3095593:tid 3095593] [client 34.65.36.15:49696] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "panel.97201.com"] [uri "/.git/config"] [unique_id "al-kQZTHTnEQVH1C0dIeVQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ด
jad-abuse
2026-07-21 16:53:23
(2 days ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: aws_creds ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: aws_creds, actuator, git_exposure, server_status, env_probe, config_backup, source_backup, ssh_keys. Observed by 1 sensor(s); 161 hits.
show less
Hacking
Web App Attack
๐ซ๐ท
IRISIO
2026-07-21 16:10:04
(2 days ago)
scans/SQL injection/spam posts : 948 queries
Web App Attack
SQL Injection
๐ช๐ธ
pipeline.es
2026-07-21 16:03:04
(2 days ago)
Web scanning / probing for vulnerable paths | URL: /elmah.axd | Evidence: landingow.aavv.com 34.65.3 ...
show more
Web scanning / probing for vulnerable paths | URL: /elmah.axd | Evidence: landingow.aavv.com 34.65.36.15 - - [21/Jul/2026:17:58:34 +0200] \"GET /elmah.axd HTTP/1.1\" 404 207 \"-\" \"Mozilla/5.0 (compatible; Applebot/0.1; +http://www.apple.com/go/applebot)\" GEOIP_COUNTRY_CODE=CH | ASN: GOOGLE-CLOUD-PLATFORM | Country: CH
show less
Port Scan
Web App Attack
Anonymous
2026-07-21 14:51:04
(2 days ago)
Multiple web server 400 error codes from same source ip
Web App Attack
๐ฉ๐ช
grassau.com
2026-07-21 14:40:13
(2 days ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 34.65.36.15 (CH/Swit ...
show more
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 34.65.36.15 (CH/Switzerland/Zurich/Zurich/15.36.65.34.bc.googleusercontent.com)
show less
Bad Web Bot
๐ซ๐ท
dynamix
2026-07-21 08:58:40
(2 days ago)
Multiple WAF Violations
Web App Attack