🇩🇪
Jochen Pretli
2026-09-15 12:34:27
(49 minutes ago)
connection to honeypot
Email Spam
Port Scan
🇨🇦
SoteriaCovenant
2026-09-15 07:00:42
(6 hours ago)
Automated probe: /console on Soteria Global infrastructure. No vulnerable software present.
Hacking
🇺🇸
robotstxt
2026-09-14 12:29:02
(1 day ago)
34.80.42.195 - - [14/Sep/2026:12:28:57 +0000] "GET /..%2f..%2f.env HTTP/1.1" 400 193 "-" "-" "-" edg ...
show more
34.80.42.195 - - [14/Sep/2026:12:28:57 +0000] "GET /..%2f..%2f.env HTTP/1.1" 400 193 "-" "-" "-" edge="34.80.42.195"
34.80.42.195 - - [14/Sep/2026:12:28:58 +0000] "GET /public/plugins/alertlist/../../../../../../../../proc/self/environ HTTP/1.1" 400 193 "-" "-" "-" edge="34.80.42.195"
34.80.42.195 - - [14/Sep/2026:12:28:58 +0000] "GET /public/plugins/alertlist/../../../../../../../../proc/self/environ HTTP/1.1" 400 193 "-" "-" "-" edge="34.80.42.195"
34.80.42.195 - - [14/Sep/2026:12:28:58 +0000] "GET /api/uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2fproc/self/environ HTTP/1.1" 400 193 "-" "-" "-" edge="34.80.42.195"
34.80.42.195 - - [14/Sep/2026:12:28:58 +0000] "GET /static/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2fproc/self/environ HTTP/1.1" 400 193 "-" "-" "-" edge="34.80.42.195"
...
show less
Web Spam
Web App Attack
🇳🇱
Alt255
2026-09-14 05:22:18
(1 day ago)
[ti-17al] Web exploit scanning: 4 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-17al] Web exploit scanning: 4 suspicious requests detected by fail2ban jail apache-scanner. Example: 34.80.42.195 - - [14/Sep/2026:07:22:17 +0200] "GET /.env.production HTTP/2.0" 404 2004 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
34.80.42.195 - - [14/Sep/2026:07:22:17 +0200] "GET /.env.backup HTTP/2.0" 404 2004 "-" "Mozilla/5.0 (compatible; PanguBot/1.0; +https://www.huaweicloud.com/)"
34.80.42.195 - - [14/Sep/2026:07:22:17 +0200] "GET /.env HTTP/2.0" 404 2004 "-" "Mozilla/5.0 (compatible; MistralAI-User/1.0; +https://mistral.ai/)"
34.80.42.195 - - [14/Sep/2026:07:22:17 +0200] "GET /.env.example HTTP/2.0" 404 2004 "-" "Mozilla/5.0 (compatible; Qwenbot/1.0; +https://qwen.alibaba.com/)"
...
show less
Bad Web Bot
Web App Attack
Anonymous
2026-09-14 03:20:01
(1 day ago)
| Multiple common web attacks from same source ip. (multiple servers)
Web App Attack
Hacking
SQL Injection
🇺🇸
robotstxt
2026-09-14 01:09:00
(1 day ago)
34.80.42.195 - - [14/Sep/2026:01:08:53 +0000] "GET /api/uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f ...
show more
34.80.42.195 - - [14/Sep/2026:01:08:53 +0000] "GET /api/uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f.env HTTP/1.1" 400 193 "-" "-" "-" edge="34.80.42.195"
34.80.42.195 - - [14/Sep/2026:01:08:53 +0000] "GET /uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f.env HTTP/1.1" 400 193 "-" "-" "-" edge="34.80.42.195"
34.80.42.195 - - [14/Sep/2026:01:08:53 +0000] "GET /icons/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/proc/self/environ HTTP/1.1" 400 193 "-" "-" "-" edge="34.80.42.195"
34.80.42.195 - - [14/Sep/2026:01:08:55 +0000] "GET /public/plugins/text/../../../../../../../../proc/self/environ HTTP/1.1" 400 193 "-" "-" "-" edge="34.80.42.195"
34.80.42.195 - - [14/Sep/2026:01:08:55 +0000] "GET /public/plugins/grafana-clock-panel/../../../../../../../../proc/self/environ HTTP/1.1" 400 193 "-" "-" "-" edge="34.80.42.195"
...
show less
Web Spam
Web App Attack
🇹🇭
thaizone.com
2026-09-13 23:44:33
(1 day ago)
Hacking attempts against websites (D1) #2
Web App Attack
Hacking
🇹🇭
thaizone.com
2026-09-13 22:14:22
(1 day ago)
Hacking attempts against websites (D1) #1
Web App Attack
Hacking
🇨🇦
SoteriaCovenant
2026-09-13 18:12:10
(1 day ago)
Automated probe: /console on Soteria Global infrastructure. No vulnerable software present.
Hacking
🇺🇸
HamSammich
2026-09-13 16:33:14
(1 day ago)
Automated sensor: 5 HTTPS connection/probe attempts over the last 24h (latest 2026-09-13T16:33Z).
Brute-Force
Web App Attack
🇭🇺
kranem
2026-09-13 15:00:14
(1 day ago)
Triggered Cloudflare WAF from TW.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Protocol: HTTP/2 (POS ...
show more
Triggered Cloudflare WAF from TW.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Protocol: HTTP/2 (POST method)
Endpoint: /read-document
Timestamp: 2026-09-13T14:07:53Z
User-Agent: Mozilla/5.0 (compatible; Google-Extended; +http://www.google.com/bot.html)
show less
Bad Web Bot
🇧🇷
Halux
2026-09-13 12:06:49
(2 days ago)
34.80.42.195 Web Application Firewall multiple violations
Hacking
Web App Attack
🇵🇱
Budyn
2026-09-13 09:15:21
(2 days ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit Block. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: budyn.wtf | URI: /static../.env | UA: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexitybot) | BODY: [Empty / GET Request]
show less
Hacking
Web App Attack
🇳🇱
Site.eu
2026-09-13 08:08:28
(2 days ago)
Excessive multi-domain requests
Brute-Force
🇮🇳
evicky2002
2026-09-13 06:00:01
(2 days ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH