๐บ๐ธ
wbsouza
2026-09-22 03:22:24
(23 hours ago)
CrowdSec: crowdsecurity/http-path-traversal-probing โ automated firewall drops on self-hosted IDS se ...
show more
CrowdSec: crowdsecurity/http-path-traversal-probing โ automated firewall drops on self-hosted IDS sensor
show less
Hacking
๐ช๐ธ
robotstxt
2026-09-21 22:12:40
(1 day ago)
34.66.63.12 - - [21/Sep/2026:22:12:26 +0000] "-" 400 0 "-" "-"
34.66.63.12 - - [21/Sep/2026:22:12:26 ...
show more
34.66.63.12 - - [21/Sep/2026:22:12:26 +0000] "-" 400 0 "-" "-"
34.66.63.12 - - [21/Sep/2026:22:12:26 +0000] "-" 400 0 "-" "-"
34.66.63.12 - - [21/Sep/2026:22:12:27 +0000] "-" 400 0 "-" "-"
34.66.63.12 - - [21/Sep/2026:22:12:29 +0000] "-" 400 0 "-" "-"
34.66.63.12 - - [21/Sep/2026:22:12:29 +0000] "-" 400 0 "-" "-"
...
show less
Web Spam
Web App Attack
๐ซ๐ท
IRISIO
2026-09-21 20:19:26
(1 day ago)
scans/SQL injection/spam posts : 3276 queries
Web App Attack
SQL Injection
๐ช๐ธ
robotstxt
2026-09-21 20:14:05
(1 day ago)
34.66.63.12 - - [21/Sep/2026:20:13:37 +0000] "GET /.aws/credentials HTTP/2.0" 403 16023 "https://hom ...
show more
34.66.63.12 - - [21/Sep/2026:20:13:37 +0000] "GET /.aws/credentials HTTP/2.0" 403 16023 "https://home.temporada-alta.com/.aws/credentials" "DuckAssistBot/1.1 (https://duckduckgo.com/duckassistbot)"
34.66.63.12 - - [21/Sep/2026:20:13:37 +0000] "GET /.aws/config HTTP/2.0" 403 16020 "https://home.temporada-alta.com/.aws/config" "Mozilla/5.0 (compatible; YouBot/1.0; +https://you.com/bot)"
34.66.63.12 - - [21/Sep/2026:20:13:37 +0000] "GET /.git/config HTTP/2.0" 403 16020 "https://home.temporada-alta.com/.git/config" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; GPTBot/1.4; +https://openai.com/gptbot"
34.66.63.12 - - [21/Sep/2026:20:13:37 +0000] "GET /.git/HEAD HTTP/2.0" 403 16022 "https://home.temporada-alta.com/.git/HEAD" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexitybot)"
34.66.63.12 - - [21/Sep/2026:20:13:37 +0000] "GET /.git-credentials HTTP/2.0" 403 16023 "https://home.temporada-alta.com/.git-cre
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 19:51:46
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.66.63.12 (12.63.66.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.66.63.12 (12.63.66.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 15:51:40.256372 2026] [security2:error] [pid 5279:tid 5279] [client 34.66.63.12:35672] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "brainwavecenters.com"] [uri "/.env.js"] [unique_id "arGKzBQnRZliEEat7COdiQAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฑ๐น
Evag Touf
2026-09-21 18:19:10
(1 day ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 34.66.63.12 (US/Unit ...
show more
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 34.66.63.12 (US/United States/12.63.66.34.bc.googleusercontent.com)
show less
Bad Web Bot
๐ซ๐ท
IRISIO
2026-09-21 15:45:35
(1 day ago)
scans/SQL injection/spam posts : 2203 queries
Web App Attack
SQL Injection
๐ณ๐ฑ
Savvii
2026-09-21 15:23:22
(1 day ago)
20 attempts against mh_ha-misbehave-ban on pf221108
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Vegascosmetics
2026-09-21 15:16:38
(1 day ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after first-seen suspicion / AbuseIPDB repu ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after first-seen suspicion / AbuseIPDB reputation policy (no URL signature). Evidence: Suspicion-Ban (Score 73>=65, Abuse 76, NonEU, first-seen)
show less
Hacking
Exploited Host
Web App Attack
Anonymous
2026-09-21 15:10:08
(1 day ago)
| Multiple common web attacks from same source ip. (multiple servers)
Web App Attack
Hacking
SQL Injection
Anonymous
2026-09-21 15:08:14
(1 day ago)
Date: 2026/09/22 00 08 14
URI: http://adelabelly.com/.env
Web App Attack
Anonymous
2026-09-21 14:45:12
(1 day ago)
34.66.63.12 - - [21/Sep/2026:22:45:11 +0800] "GET /deploy/.env HTTP/1.1" 404 297622 "-" "Mozilla/5.0 ...
show more
34.66.63.12 - - [21/Sep/2026:22:45:11 +0800] "GET /deploy/.env HTTP/1.1" 404 297622 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36; compatible; OAI-SearchBot/1.4; +https://openai.com/searchbot"
...
show less
Bad Web Bot
Web App Attack
๐ช๐ธ
robotstxt
2026-09-21 14:38:18
(1 day ago)
34.66.63.12 - - [21/Sep/2026:14:37:40 +0000] "GET /scripts/.env HTTP/2.0" 403 16021 "https://v1.temp ...
show more
34.66.63.12 - - [21/Sep/2026:14:37:40 +0000] "GET /scripts/.env HTTP/2.0" 403 16021 "https://v1.temporada-alta.com/scripts/.env" "DuckAssistBot/1.1 (https://duckduckgo.com/duckassistbot)"
34.66.63.12 - - [21/Sep/2026:14:37:40 +0000] "GET /infra/.env HTTP/2.0" 403 16020 "https://v1.temporada-alta.com/infra/.env" "Mozilla/5.0 (compatible; KimiBot/1.0; +https://kimi.ai/)"
34.66.63.12 - - [21/Sep/2026:14:37:40 +0000] "GET /.next/.env HTTP/2.0" 403 16021 "https://v1.temporada-alta.com/.next/.env" "Mozilla/5.0 (compatible; xAI-Grok/1.0; +https://x.ai/)"
34.66.63.12 - - [21/Sep/2026:14:37:40 +0000] "GET /build/.env HTTP/2.0" 403 16022 "https://v1.temporada-alta.com/build/.env" "CCBot/2.0 (https://commoncrawl.org/faq/)"
34.66.63.12 - - [21/Sep/2026:14:37:40 +0000] "GET /public/.env HTTP/2.0" 403 16018 "https://v1.temporada-alta.com/public/.env" "DuckAssistBot/1.1 (https://duckduckgo.com/duckassistbot)"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 14:33:38
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.66.63.12 (12.63.66.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.66.63.12 (12.63.66.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 10:33:31.642149 2026] [security2:error] [pid 14562:tid 14562] [client 34.66.63.12:39968] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.adirondackwaterfront.com"] [uri "/%2E%2E/%2E%2E/%2E%2E/%2E%2E/.env"] [unique_id "arFAO0zvn4JK2sIm3tzogwAAAE4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-21 14:04:55
(1 day ago)
[ti-05al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-05al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 34.66.63.12 - - [21/Sep/2026:16:04:53 +0200] "GET /__vite_rsc_findSourceMapURL?filename=file:///root/.ssh/id_rsa&environmentName=rsc HTTP/2.0" 404 1855 "-" "Mozilla/5.0 (compatible; YiBot/1.0; +https://01.ai/)"
...
show less
Bad Web Bot
Web App Attack