๐ฉ๐ช
crypto i trust, hold i must
2026-09-19 05:47:25
(48 minutes ago)
Web scanner path: /api/v2/config
Web App Attack
๐ณ๐ฑ
ismailk
2026-09-19 02:27:04
(4 hours ago)
WordPress attack on tuncayozkan.com (auto-detected): tur=imza ulke=? puan=100 nginx=162 wf=0 cf=0 hi ...
show more
WordPress attack on tuncayozkan.com (auto-detected): tur=imza ulke=? puan=100 nginx=162 wf=0 cf=0 hiz=151 404cesit=0. Blocked by adaptive firewall.
show less
Web App Attack
Bad Web Bot
Anonymous
2026-09-18 23:51:20
(6 hours ago)
(config_exploit_scan) Configuratie Scanner / Nep GPTBot 34.80.196.46 (TW/Taiwan/46.196.80.34.bc.goog ...
show more
(config_exploit_scan) Configuratie Scanner / Nep GPTBot 34.80.196.46 (TW/Taiwan/46.196.80.34.bc.googleusercontent.com): 3 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 34.80.196.46 - - [19/Sep/2026:01:51:18 +0200] "GET /.env_sample HTTP/2.0" 406 317 "-" "Mozilla/5.0 (compatible; Qwenbot/1.0; +https://qwen.alibaba.com/)"
34.80.196.46 - - [19/Sep/2026:01:51:19 +0200] "GET /.gitlab-ci.yml HTTP/2.0" 406 317 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-SearchBot/1.0; [email protected] )"
34.80.196.46 - - [19/Sep/2026:01:51:19 +0200] "GET /apps/.env HTTP/2.0" 406 317 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexitybot)"
show less
Port Scan
๐ฉ๐ช
XICTRON
2026-09-18 23:05:06
(7 hours ago)
ModSecurity rule violation detected by Fail2Ban
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-18 18:21:40
(12 hours ago)
[ti-12al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail <name>. Example: 34. ...
show more
[ti-12al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail <name>. Example: 34.80.196.46 - - \[18/Sep/2026:20:21:32 +0200\] "GET /build/.env HTTP/2.0" 404 1863 "-" "Mozilla/5.0 \(compatible\; Google-Extended\; +http://www.google.com/bot.html\)"
...
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-18 17:42:01
(12 hours ago)
[ti-03ov] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-03ov] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 34.80.196.46 - - [18/Sep/2026:19:41:40 +0200] "GET /portal/.env HTTP/2.0" 403 346 "-" "Mozilla/5.0 (compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot)"
...
show less
Bad Web Bot
Web App Attack
๐ง๐ท
dermatovirtual
2026-09-18 11:45:45
(18 hours ago)
Dermato Virtual CSIRT: Malicious web exploit/scanning probes against app.dermatovirtual.com.br (Web ...
show more
Dermato Virtual CSIRT: Malicious web exploit/scanning probes against app.dermatovirtual.com.br (Web Server Ports 80/443). 101 unauthorized requests recorded between 2026-09-17 11:42:08 UTC and 2026-09-17 11:42:20 UTC (rate: ~101 req/min). Edge perimeter firewall drop active.
Log sample:
[2026-09-17 11:42:20 UTC] IP: 34.80.196.46 - W3C IIS (Port 443): GET /scripts/.env -> HTTP 404 [CLIENT: 34.80.196.46]
[2026-09-17 11:42:20 UTC] IP: 34.80.196.46 - W3C IIS (Port 443): GET /.env.www -> HTTP 404 [CLIENT: 34.80.196.46]
[2026-09-17 11:42:20 UTC] IP: 34.80.196.46 - W3C IIS (Port 443): GET /.next/.env -> HTTP 404 [CLIENT: 34.80.196.46]
show less
Bad Web Bot
Web App Attack
๐ง๐ช
voormedia
2026-09-18 03:12:02
(1 day ago)
Accessed trap at '/.git/config'
Web App Attack
๐ซ๐ฎ
robotstxt
2026-09-17 23:49:21
(1 day ago)
34.80.196.46 - - [17/Sep/2026:23:49:12 +0000] "GET /conf/.env HTTP/2.0" 403 33010 "-" rt="11.609" "M ...
show more
34.80.196.46 - - [17/Sep/2026:23:49:12 +0000] "GET /conf/.env HTTP/2.0" 403 33010 "-" rt="11.609" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; [email protected] )" "-" edge="34.80.196.46" h="directorio.componentescalzado.com" sn="directorio.componentescalzado.com" ru="/conf/.env" u="/index.php" ucs="-" ua="unix:/var/run/php/ccalzadodir82.sock" us="404" uct="0.000" urt="11.610"
34.80.196.46 - - [17/Sep/2026:23:49:13 +0000] "GET /temp/.env HTTP/2.0" 403 0 "-" rt="12.390" "Mozilla/5.0 (compatible; xAI-Grok/1.0; +https://x.ai/)" "-" edge="34.80.196.46" h="directorio.componentescalzado.com" sn="directorio.componentescalzado.com" ru="/temp/.env" u="/index.php" ucs="-" ua="unix:/var/run/php/ccalzadodir82.sock" us="-" uct="0.000" urt="12.390"
34.80.196.46 - - [17/Sep/2026:23:49:13 +0000] "GET /etc/.env HTTP/2.0" 403 0 "-" rt="12.474" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; GPTBot/1.3; +https://openai.com/gptbot)" "-" edge="34.80
...
show less
Web App Attack
๐ฉ๐ช
bazter.pro
2026-09-17 23:00:46
(1 day ago)
Fail2Ban: plesk-bot-aggressive - 15 failures
Port Scan
Bad Web Bot
Web App Attack
๐ซ๐ท
SpaceHost-Server
2026-09-17 22:21:44
(1 day ago)
Brute-Force
Web App Attack
๐บ๐ธ
hostmach
2026-09-17 20:46:03
(1 day ago)
(cpanel) Failed cPanel login from 34.80.196.46 (TW/Taiwan/46.196.80.34.bc.googleusercontent.com): 5 ...
show more
(cpanel) Failed cPanel login from 34.80.196.46 (TW/Taiwan/46.196.80.34.bc.googleusercontent.com): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CPANEL; Logs: [2026-09-17 16:46:02 -0400] info [cpaneld] 34.80.196.46 - - "GET /id_ed25519 HTTP/1.1" FAILED LOGIN cpaneld: login attempt without username
[2026-09-17 16:46:02 -0400] info [cpaneld] 34.80.196.46 - - "GET /rclone.conf HTTP/1.1" FAILED LOGIN cpaneld: login attempt without username
[2026-09-17 16:46:02 -0400] info [cpaneld] 34.80.196.46 - - "GET /id_ecdsa HTTP/1.1" FAILED LOGIN cpaneld: login attempt without username
[2026-09-17 16:46:02 -0400] info [cpaneld] 34.80.196.46 - - "GET /server.key HTTP/1.1" FAILED LOGIN cpaneld: login attempt without username
[2026-09-17 16:46:02 -0400] info [cpaneld] 34.80.196.46 - - "GET /manifest.json HTTP/1.1" FAILED LOGIN cpaneld: login attempt without username
show less
Brute-Force
SSH
๐ฎ๐น
VHosting
2026-09-17 20:35:03
(1 day ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
Anonymous
2026-09-17 16:46:26
(1 day ago)
Portscan: TCP/8080 (3x), TCP/8443 (3x), TCP/443, TCP/80
Port Scan
Anonymous
2026-09-17 16:30:07
(1 day ago)
Wing FTP Server Remote Code Execution.
Web App Attack