๐บ๐ธ
wteiken
2026-09-02 17:58:20
(8 hours ago)
2026-09-02T13:58:19.458942-04:00 rocinante.teiken.net kernel: [264545.562492] syn_limit:IN=ens5 OUT= ...
show more
2026-09-02T13:58:19.458942-04:00 rocinante.teiken.net kernel: [264545.562492] syn_limit:IN=ens5 OUT= MAC=0a:ff:cf:a1:a5:bb:0a:f3:ae:05:2f:b7:08:00 SRC=34.81.215.134 DST=192.168.16.119 LEN=60 TOS=0x00 PREC=0x60 TTL=58 ID=23050 DF PROTO=TCP SPT=11932 DPT=443 WINDOW=42600 RES=0x00 SYN URGP=0
2026-09-02T13:58:19.459116-04:00 rocinante.teiken.net kernel: [264545.562496] syn_limit:IN=ens5 OUT= MAC=0a:ff:cf:a1:a5:bb:0a:f3:ae:05:2f:b7:08:00 SRC=34.81.215.134 DST=192.168.16.119 LEN=60 TOS=0x00 PREC=0x60 TTL=58 ID=45518 DF PROTO=TCP SPT=11838 DPT=443 WINDOW=42600 RES=0x00 SYN URGP=0
2026-09-02T13:58:19.459142-04:00 rocinante.teiken.net kernel: [264545.565162] syn_limit:IN=ens5 OUT= MAC=0a:ff:cf:a1:a5:bb:0a:f3:ae:05:2f:b7:08:00 SRC=34.81.215.134 DST=192.168.16.119 LEN=60 TOS=0x00 PREC=0x00 TTL=57 ID=13759 DF PROTO=TCP SPT=12000 DPT=443 WINDOW=42600 RES=0x00 SYN URGP=0
2026-09-02T13:58:19.459166-04:00 rocinante.teiken.net kernel: [264545.567851] syn_limit:IN=ens5 OUT= MAC=0a:ff:cf:a1:a5:bb:0a:f
...
show less
Port Scan
๐ท๐บ
lns.bz
2026-09-02 17:56:43
(8 hours ago)
Too many 404 requests [RU.VDS]
Web App Attack
๐ฉ๐ช
cybertailor
2026-09-02 14:19:06
(12 hours ago)
34.81.215.134 - - [02/Sep/2026:19:19:00 +0500] "GET / HTTP/1.1" 404 146 "-" "Mozilla/5.0 (Macintosh; ...
show more
34.81.215.134 - - [02/Sep/2026:19:19:00 +0500] "GET / HTTP/1.1" 404 146 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 13_6_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.5 Safari/605.1.15; compatible; TelegramBot/1.0"
34.81.215.134 - - [02/Sep/2026:19:19:01 +0500] "GET /__aws_leak_probe_622bd2a7__ HTTP/1.1" 404 146 "-" "Mozilla/5.0 (compatible; Applebot/0.1; +http://www.apple.com/go/applebot)"
34.81.215.134 - - [02/Sep/2026:19:19:02 +0500] "GET /@fs/proc/self/environ HTTP/1.1" 404 146 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Discordbot/2.0; +https://discordapp.com)"
34.81.215.134 - - [02/Sep/2026:19:19:03 +0500] "GET /@fs/proc/self/environ?raw?? HTTP/1.1" 404 146 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexity-user)"
34.81.215.134 - - [02/Sep/2026:19:19:03 +0500] "GET /read?url=file:///proc/self/environ HTTP/1.1" 404 178 "-" "Mozilla/5.0 (Linux; Android 13; Pixel 7) AppleWebKit/5
...
show less
Port Scan
Anonymous
2026-09-02 07:50:01
(19 hours ago)
denied traffic to a honeypot network. destination port 8080.
Port Scan
Hacking
๐ฎ๐น
CoreTech srl
2026-09-02 06:38:49
(20 hours ago)
[DC: IP:151.1.252.27] ntopng alert: blacklisted_client_contact
Hacking
๐บ๐ธ
kosada.com
2026-09-02 06:16:58
(20 hours ago)
Repeated requests for suspicious nonexistent URLs, for example: /?file=../../../../etc/passwd (HTTP/ ...
show more
Repeated requests for suspicious nonexistent URLs, for example: /?file=../../../../etc/passwd (HTTP/1.1 port 80, bogus vhost, user agent: "Mozilla/5.0 (iPhone; CPU iPhone OS 18_4 like Mac OS X) AppleWebKit/537.36 (KHTML, like Gecko; compatible; TelegramBot/1.0) Chrome/134.0.2138.151 Mobile Safari/537.36")
show less
Web App Attack
๐ฎ๐ฉ
sockominfo
2026-09-01 13:00:52
(1 day ago)
Active Response: IP 34.81.215.134 Blocked via Firewall Drop, Critical LFI with PHP code injection de ...
show more
Active Response: IP 34.81.215.134 Blocked via Firewall Drop, Critical LFI with PHP code injection detected - Basic 2. Threat Score: 9/10 (CRITICAL). Confidence: 70%. CVSS v3.1: 10/10 (Critical). CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H. Bayesian Probability: 90%. MITRE ATT&CK: T1190 (Exploit Public-Facing Application). Tactic: TA0001. Freshness: Fresh. Source Reputation: KNOWN_MALICIOUS. Methodology: CVSS 3.1 + Bayesian + Temporal + Environmental + MITRE ATT&CK + OWASP. Standards: ISO/IEC 27065:2022, NIST SP 800-30, IEEE S&P 2020. Reported by TangerangKota-CSIRT. Status: MALICIOUS
show less
Hacking
Brute-Force
๐ฎ๐ฉ
sockominfo
2026-09-01 12:00:09
(1 day ago)
Critical LFI with PHP code injection detected - Basic 2. Threat Score: 7.7/10 (HIGH). Reported by Ta ...
show more
Critical LFI with PHP code injection detected - Basic 2. Threat Score: 7.7/10 (HIGH). Reported by TangerangKota-CSIRT. Status: MALICIOUS
show less
Hacking
Brute-Force
๐ฏ๐ต
VXG-NET
2026-09-01 11:55:31
(1 day ago)
port=80, indicator_type=info-leak
Hacking
๐ฟ๐ฆ
conure.sh
2026-09-01 06:51:36
(1 day ago)
csagent: score 21.4: 404 noise floor x6, secrets grab x2; 1 domain(s) in 1s
Web App Attack
๐บ๐ธ
alecj.com
2026-08-31 22:48:13
(2 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/appsec-vpatch
Web App Attack
๐จ๐ฆ
Mediashaker
2026-08-31 19:18:53
(2 days ago)
(CT) IP 34.81.215.134 (TW/Taiwan/134.215.81.34.bc.googleusercontent.com) found to have 607 connectio ...
show more
(CT) IP 34.81.215.134 (TW/Taiwan/134.215.81.34.bc.googleusercontent.com) found to have 607 connections
show less
DDoS Attack
๐บ๐ธ
kadour
2026-08-31 14:16:24
(2 days ago)
[Mon Aug 31 09:16:20.794269 2026] [proxy_fcgi:error] [pid 3348089:tid 3348123] [client 34.81.215.134 ...
show more
[Mon Aug 31 09:16:20.794269 2026] [proxy_fcgi:error] [pid 3348089:tid 3348123] [client 34.81.215.134:13012] AH01071: Got error 'Primary script unknown', referer: https://172.233.212.194:443/.env.php
[Mon Aug 31 09:16:21.365632 2026] [proxy_fcgi:error] [pid 3244878:tid 3244918] [client 34.81.215.134:12578] AH01071: Got error 'Primary script unknown', referer: https://172.233.212.194:443/phpinfo.php
[Mon Aug 31 09:16:21.999432 2026] [proxy_fcgi:error] [pid 3348089:tid 3348128] [client 34.81.215.134:13332] AH01071: Got error 'Primary script unknown', referer: https://172.233.212.194:443/app_dev.php/_profiler/.env
[Mon Aug 31 09:16:22.377756 2026] [proxy_fcgi:error] [pid 3348089:tid 3348136] [client 34.81.215.134:12810] AH01071: Got error 'Primary script unknown', referer: https://172.233.212.194:443/app_dev.php/_profiler/phpinfo
[Mon Aug 31 09:16:23.193787 2026] [proxy_fcgi:error] [pid 3244878:tid 3244928] [client 34.81.215.134:64294] AH01071: Got error 'Primary script unknown', referer:
...
show less
Web App Attack
๐ซ๐ท
guillaume illien
2026-08-31 13:53:37
(2 days ago)
34.81.215.134 - - [31/Aug/2026:13:53:30 +0000] "GET / HTTP/1.1" 301 178 "-" "Mozilla/5.0 (compatible ...
show more
34.81.215.134 - - [31/Aug/2026:13:53:30 +0000] "GET / HTTP/1.1" 301 178 "-" "Mozilla/5.0 (compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexity-user)"
34.81.215.134 - - [31/Aug/2026:13:53:33 +0000] "GET /__aws_leak_probe_affbdc91__ HTTP/1.1" 301 178 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; Bytespider; +https://zhanzhang.toutiao.com/"
34.81.215.134 - - [31/Aug/2026:13:53:37 +0000] "GET /config.js HTTP/1.1" 301 178 "-" "Mozilla/5.0 (compatible; TelegramBot/1.0)"
34.81.215.134 - - [31/Aug/2026:13:53:37 +0000] "GET /.git/HEAD HTTP/1.1" 301 178 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; GrokBot/1.0; +https://x.ai/grokbot)"
34.81.215.134 - - [31/Aug/2026:13:53:37 +0000] "GET /.env.local HTTP/1.1" 301 178 "-" "Mozilla/5.0 (compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexity-user)"
34.81.215.134 - - [31/Aug/2026:13:53:37 +0000] "GET /api/config HTTP/1.1" 301 178 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gec
...
show less
Hacking
Brute-Force
Web App Attack
SSH
๐ณ๐ฑ
Mangelot Hosting
2026-08-31 13:11:20
(2 days ago)
(modsecurity) srv102 ModSecurity 34.81.215.134 (TW/Taiwan/134.215.81.34.bc.googleusercontent.com): 3 ...
show more
(modsecurity) srv102 ModSecurity 34.81.215.134 (TW/Taiwan/134.215.81.34.bc.googleusercontent.com): 30 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack