๐ฎ๐ฉ
hiiruki
2026-10-05 19:51:09
(5 days ago)
Cloudflare WAF: Block by managed rules. Automated web scanner probing for sensitive files (.env/.git ...
show more
Cloudflare WAF: Block by managed rules. Automated web scanner probing for sensitive files (.env/.git); admin panels/known CVE endpoints; path traversal: 82 requests, 21 distinct probe paths (2026-10-04 19:52:07 to 2026-10-05 19:51:09 UTC), e.g. /.env.production, /document.php, /app_dev.php, /.ssh/id_ed25519, /.git/config, /actuator/loggers. 12 POST requests to login/signup/admin endpoints (e.g. /dashboard, /api, /login). Request details: DELETE/GET/POST HTTP/1.1/HTTP/2; User agent: 15 rotating user agents (crawler-style e.g. CCBot/2.0; Amazonbot/0.1; Baiduspider/2.0; Bytespider, plus generic browser strings); Verified bot category: None; ASN: 396982 - Google LLC; Country: SG.
show less
Hacking
Brute-Force
Web App Attack
๐ฉ๐ช
updown.io
2026-10-05 18:03:03
(5 days ago)
{"level":"info","ts":1791223377.670793,"logger":"http.log.access.log1","msg":"handled request","requ ...
show more
{"level":"info","ts":1791223377.670793,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"34.87.132.39","remote_port":"50054","client_ip":"34.87.132.39","proto":"HTTP/2.0","method":"GET","host":"status.archive.li","uri":"/.ssh/id_rsa","headers":{"Cookie":["REDACTED"],"X-Middleware-Subrequest":["src/middleware:nowaf:src/middleware:src/middleware:src/middleware:src/middleware:middleware:middleware:nowaf:middleware:middleware:middleware:pages/_middleware"],"X-Nextjs-Data":["1"],"User-Agent":["Mozilla/5.0 (compatible; Bytespider; [email protected] ) AppleWebKit/537.36"],"Accept":["*/*"],"Accept-Encoding":["gzip"]},"tls":{"resumed":false,"version":772,"cipher_suite":4865,"proto":"h2","server_name":"status.archive.li","ech":false}},"bytes_read":0,"user_id":"","duration":0.00110658,"size":0,"status":429,"resp_headers":{"Server":["Caddy"],"Alt-Svc":["h3=\":443\"; ma=2592000"],"Retry-After":["1"]}}
{"level":"info","ts":1791223377.7659388,"logger":"http.lo
...
show less
DDoS Attack
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-10-05 14:20:34
(5 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/grafana-cve-2021-43798
Web App Attack
Hacking
๐ณ๐ฑ
ConsulHosting
2026-10-05 11:14:35
(5 days ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack
๐จ๐ญ
ca
2026-10-05 01:23:10
(6 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐ฉ๐ช
Laplus
2026-10-04 22:01:41
(6 days ago)
34.87.132.39 - - [05/Oct/2026:00:01:36 +0200] "GET /api/uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2fproc/self ...
show more
34.87.132.39 - - [05/Oct/2026:00:01:36 +0200] "GET /api/uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2fproc/self/environ HTTP/1.1" 400 157 "-" "-" "-"
34.87.132.39 - - [05/Oct/2026:00:01:36 +0200] "GET /%2E%2E/%2E%2E/%2E%2E/%2E%2E/proc/self/environ HTTP/1.1" 400 157 "-" "-" "-"
34.87.132.39 - - [05/Oct/2026:00:01:36 +0200] "GET /icons/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/proc/self/environ HTTP/1.1" 400 157 "-" "-" "-"
34.87.132.39 - - [05/Oct/2026:00:01:36 +0200] "GET /api/uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2f.env HTTP/1.1" 400 157 "-" "-" "-"
34.87.132.39 - - [05/Oct/2026:00:01:36 +0200] "GET /appearance/../../.env HTTP/1.1" 400 157 "-" "-" "-"
34.87.132.39 - - [05/Oct/2026:00:01:36 +0200] "GET /api/uploads/%2e%2e%2f%2e%2e%2f.env HTTP/1.1" 302 145 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot)" "-"
34.87.132.39 - - [05/Oct/2026:00:01:36 +0200] "GET /uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f.env HTTP/1.1" 400 157 "-" "-" "-"
3
...
show less
Hacking
Web App Attack
๐ธ๐ช
nekopavel
2026-10-04 21:40:04
(6 days ago)
34.87.132.39 - - [04/Oct/2026:23:40:02 +0200]"GET /images../.env HTTP/2.0" 444 0"-" thighs.moe "CCBo ...
show more
34.87.132.39 - - [04/Oct/2026:23:40:02 +0200]"GET /images../.env HTTP/2.0" 444 0"-" thighs.moe "CCBot/2.0 (https://commoncrawl.org/faq/)""0.000" "-""Singapore" "SG"
34.87.132.39 - - [04/Oct/2026:23:40:02 +0200]"GET /build../.env HTTP/2.0" 444 0"-" thighs.moe "CCBot/2.0 (https://commoncrawl.org/faq/)""0.000" "-""Singapore" "SG"
34.87.132.39 - - [04/Oct/2026:23:40:02 +0200]"GET /static//app/.env HTTP/2.0" 404 142"-" thighs.moe "DuckAssistBot/1.1 (https://duckduckgo.com/duckassistbot)""0.003" "0.001""Singapore" "SG"
...
show less
Hacking
Bad Web Bot
Web App Attack
๐ฆ๐น
penguin-solutions.at
2026-10-04 21:16:38
(6 days ago)
Excessive 403/404 errors
...
Brute-Force
Web App Attack
๐จ๐ญ
backslash
2026-10-04 21:06:00
(6 days ago)
block ruleset bad bot: misc bad content F608233CC4C86EE814CE8DDDA9C4A0D3C79882F6
Bad Web Bot
๐จ๐ญ
Origon
2026-10-04 20:43:00
(6 days ago)
http-path-traversal-probing - IP: 34.87.132.39 - time="2026-10-04T22:43:00+02:00" level=info msg="( ...
show more
http-path-traversal-probing - IP: 34.87.132.39 - time="2026-10-04T22:43:00+02:00" level=info msg="(555f66b4f6a74558bc11e3f93469658es8App0Mcc0TKEeje/crowdsec) crowdsecurity/http-path-traversal-probing by ip 34.87.132.39 (SG/396982) : 4h ban on Ip 34.87.132.39" module=db
show less
Web App Attack
๐จ๐ญ
ca
2026-10-04 20:36:14
(6 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-path-traversal-probing
Web App Attack
Hacking
๐ซ๐ฎ
KTSTechnology
2026-10-04 20:00:39
(6 days ago)
Web vulnerability scanning detected by our ISP firewall
Web App Attack
Anonymous
2026-10-04 19:55:41
(6 days ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
๐จ๐ฆ
Read.Team
2026-10-04 19:55:01
(6 days ago)
Automated report: repeat offender across honeypot, portscan, and brute force systems. Score: 9
Port Scan
Hacking
Web App Attack
๐ฎ๐น
VHosting
2026-10-04 19:50:04
(6 days ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack