๐ณ๐ฑ
oisecnet
2026-10-05 21:02:45
(5 days ago)
Automated report: Unauthorized vulnerability scanning detected on 2026-10-05. 1822 requests from thi ...
show more
Automated report: Unauthorized vulnerability scanning detected on 2026-10-05. 1822 requests from this IP.
show less
Port Scan
Hacking
Web App Attack
๐ฉ๐ช
Marco711
2026-10-05 19:12:40
(5 days ago)
port/URL scanning
Port Scan
Web App Attack
๐ฉ๐ช
curiosity
2026-10-05 18:55:27
(5 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-bad-user-agent
Web App Attack
Bad Web Bot
๐บ๐ธ
Charlesiv
2026-10-05 18:01:04
(5 days ago)
Triggered Cloudflare WAF (firewallCustom) from TW.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Prot ...
show more
Triggered Cloudflare WAF (firewallCustom) from TW.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Protocol: HTTP/2 (GET method)
Endpoint: /.gitlab-ci.yml
Timestamp: 2026-10-05T17:22:07Z
Ray ID: a45e1b4f0a2402c2
UA: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; [email protected] )
show less
Bad Web Bot
๐ฉ๐ช
firestorm
2026-10-05 16:12:16
(5 days ago)
34.81.64.235 - - [05/Oct/2026:18:12:15 +0200] "GET /..%2f.env HTTP/1.1" 400 150 "-" "-"
34.81.64.235 ...
show more
34.81.64.235 - - [05/Oct/2026:18:12:15 +0200] "GET /..%2f.env HTTP/1.1" 400 150 "-" "-"
34.81.64.235 - - [05/Oct/2026:18:12:15 +0200] "GET /%2e%2e/.env HTTP/1.1" 400 150 "-" "-"
34.81.64.235 - - [05/Oct/2026:18:12:15 +0200] "GET /..%2f..%2f.env HTTP/1.1" 400 150 "-" "-"
...
show less
Brute-Force
Web App Attack
๐ซ๐ท
guillaume illien
2026-10-05 15:23:20
(5 days ago)
34.81.64.235 - - [05/Oct/2026:15:23:14 +0000] "POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e ...
show more
34.81.64.235 - - [05/Oct/2026:15:23:14 +0000] "POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh HTTP/1.1" 400 166 "-" "-"
34.81.64.235 - - [05/Oct/2026:15:23:15 +0000] "GET /..%2f.env HTTP/1.1" 400 166 "-" "-"
34.81.64.235 - - [05/Oct/2026:15:23:16 +0000] "GET /%2e%2e/.env HTTP/1.1" 400 166 "-" "-"
34.81.64.235 - - [05/Oct/2026:15:23:16 +0000] "GET /..%2f..%2f.env HTTP/1.1" 400 166 "-" "-"
34.81.64.235 - - [05/Oct/2026:15:23:16 +0000] "GET /icons/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/proc/self/environ HTTP/1.1" 400 166 "-" "-"
34.81.64.235 - - [05/Oct/2026:15:23:19 +0000] "GET /api/uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2fproc/self/environ HTTP/1.1" 400 166 "-" "-"
34.81.64.235 - - [05/Oct/2026:15:23:19 +0000] "GET /static/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2fproc/self/environ HTTP/1.1" 400 166 "-" "-"
...
show less
Hacking
Brute-Force
Web App Attack
SSH
๐ซ๐ท
guillaume illien
2026-10-05 12:28:32
(5 days ago)
34.81.64.235 - - [05/Oct/2026:12:28:23 +0000] "POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e ...
show more
34.81.64.235 - - [05/Oct/2026:12:28:23 +0000] "POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh HTTP/1.1" 400 166 "-" "-"
34.81.64.235 - - [05/Oct/2026:12:28:30 +0000] "GET /public/plugins/text/../../../../../../../../proc/self/environ HTTP/1.1" 400 166 "-" "-"
34.81.64.235 - - [05/Oct/2026:12:28:30 +0000] "GET /api/uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2fproc/self/environ HTTP/1.1" 400 166 "-" "-"
34.81.64.235 - - [05/Oct/2026:12:28:30 +0000] "GET /api/uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f.env HTTP/1.1" 400 166 "-" "-"
34.81.64.235 - - [05/Oct/2026:12:28:30 +0000] "GET /uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f.env HTTP/1.1" 400 166 "-" "-"
34.81.64.235 - - [05/Oct/2026:12:28:31 +0000] "GET /api/uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2f.env HTTP/1.1" 400 166 "-" "-"
34.81.64.235 - - [05/Oct/2026:12:28:31 +0000] "GET /..%2f.env HTTP/1.1" 400 166 "-" "-"
...
show less
Hacking
Brute-Force
Web App Attack
SSH
๐ณ๐ด
Abuse Buster
2026-10-05 12:27:56
(5 days ago)
34.81.64.235 - - [05/Oct/2026:14:27:54 +0200] "GET /z9x8c7v6b5-debug-trigger-api.wingthor.net HTTP/2 ...
show more
34.81.64.235 - - [05/Oct/2026:14:27:54 +0200] "GET /z9x8c7v6b5-debug-trigger-api.wingthor.net HTTP/2.0" 404 22 "-" "Mozilla/5.0 (compatible; YouBot/1.0; +https://you.com/bot)"
34.81.64.235 - - [05/Oct/2026:14:27:54 +0200] "GET /xzkz2nh884yltkvtbbpq HTTP/2.0" 404 22 "-" "Mozilla/5.0 (compatible; xAI-Grok/1.0; +https://x.ai/)"
34.81.64.235 - - [05/Oct/2026:14:27:54 +0200] "GET /x8jjr6djqyajd5r7a4k8 HTTP/2.0" 404 22 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36; compatible; OAI-SearchBot/1.4; +https://openai.com/searchbot"
...
show less
Web App Attack
๐บ๐ธ
Charlesiv
2026-10-05 10:00:07
(5 days ago)
Triggered Cloudflare WAF (firewallCustom) from TW.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Prot ...
show more
Triggered Cloudflare WAF (firewallCustom) from TW.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Protocol: HTTP/2 (GET method)
Endpoint: /debug/vars
Timestamp: 2026-10-05T09:59:29Z
Ray ID: a45b92e968322566
UA: Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; +https://kimi.ai/)
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-05 05:20:55
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 34.81.64.235 (235.64.81.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.81.64.235 (235.64.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 01:20:48.651043 2026] [security2:error] [pid 12303:tid 12303] [client 34.81.64.235:47058] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "whaleyhouse.net"] [uri "/.htpasswd"] [unique_id "asMzsJY_tBhn6wExa3F7cQAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
[email protected]
2026-10-05 05:07:08
(5 days ago)
CrowdSec ban: crowdsecurity/http-admin-interface-probing (duration: 71h59m59s)
Web App Attack
๐ฉ๐ช
BlueWire Hosting
2026-10-05 05:06:21
(5 days ago)
Aggressive scanning resulting into 404
Bad Web Bot
๐ฉ๐ช
pscriptos
2026-10-05 04:37:55
(5 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐ซ๐ท
masterguru
2026-10-05 04:32:58
(5 days ago)
BAD BOT - Detected and Blocked.. Matched phrase "ccbot" at REQUEST_HEADERS:User-Agent. (1100000-195)
Bad Web Bot
๐บ๐ธ
Starburst SysOp Team
2026-10-05 04:26:06
(5 days ago)
HTTP header is restricted by policy (/x-middleware-subrequest/). String match within "/content-encod ...
show more
HTTP header is restricted by policy (/x-middleware-subrequest/). String match within "/content-encoding/ /proxy/ /lock-token/ /content-range/ /if/ /x-http-method-override/ /x-http-method/ /x-method-override/ /x-middleware-subrequest/ /expect/" at TX:header_name_920450_x-middleware-subrequest. (920450-mnz6-1)
show less
Bad Web Bot