🇮🇳
evicky2002
2026-09-08 00:01:54
(21 hours ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
🇺🇸
wbsouza
2026-09-07 03:29:50
(1 day ago)
CrowdSec: crowdsecurity/http-path-traversal-probing — automated firewall drops on self-hosted IDS se ...
show more
CrowdSec: crowdsecurity/http-path-traversal-probing — automated firewall drops on self-hosted IDS sensor
show less
Hacking
🇨🇦
Mediashaker
2026-09-07 01:57:38
(1 day ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 34.9.71.127 (US/Unit ...
show more
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 34.9.71.127 (US/United States/127.71.9.34.bc.googleusercontent.com)
show less
Bad Web Bot
🇧🇪
cmbplf
2026-09-07 01:06:36
(1 day ago)
2.103 requests from abuseipdb.com blacklisted IP (2mos5d17h)
Brute-Force
Bad Web Bot
🇺🇸
thieuleu
2026-09-07 00:57:43
(1 day ago)
Unauthorized connection attempt blocked by firewall policy. Web application hardening active.
Brute-Force
Exploited Host
🇺🇸
Charlesiv
2026-09-07 00:31:57
(1 day ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Prot ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Protocol: HTTP/2 (GET method)
Endpoint: /.env.js
Timestamp: 2026-09-07T00:04:46Z
Ray ID: a371753e9a2a000c
UA: Mozilla/5.0 (compatible; GrokBot/1.0; +https://x.ai/)
show less
Bad Web Bot
🇩🇪
Skyrider
2026-09-06 23:51:17
(1 day ago)
Nginx: HTTP 4xx probe/scan attempts. Automated fail2ban report.
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 22:50:16
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.9.71.127 (127.71.9.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.9.71.127 (127.71.9.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 18:50:08.796208 2026] [security2:error] [pid 26715:tid 26715] [client 34.9.71.127:52282] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||gisur.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "gisur.com"] [uri "/z9x8c7v6b5-debug-trigger-gisur.com"] [unique_id "ap3uIKDq4iZuXYSTg5smGwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇵🇱
sefinek.net
2026-09-06 22:41:32
(1 day ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action: BLOCK | Protocol: HTTP/2 (GET) | Endpoint ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action: BLOCK | Protocol: HTTP/2 (GET) | Endpoint: /.env | UA: Mozilla/5.0 (compatible; Bytespider; [email protected] ) AppleWebKit/537.36 • Generated by: github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
🇺🇸
lavnet.net
2026-09-06 22:08:34
(1 day ago)
34.9.71.127 - - [06/Sep/2026:22:08:34 +0000] "GET /..%2f.env HTTP/2.0" 404 1878 "-" "Mozilla/5.0 App ...
show more
34.9.71.127 - - [06/Sep/2026:22:08:34 +0000] "GET /..%2f.env HTTP/2.0" 404 1878 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; [email protected] )"
34.9.71.127 - - [06/Sep/2026:22:08:34 +0000] "GET /admin/login HTTP/2.0" 404 1855 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36 Edg/151.0.0.0"
34.9.71.127 - - [06/Sep/2026:22:08:34 +0000] "GET /z9x8c7v6b5-debug-trigger-www.jackaltx.com HTTP/2.0" 404 1855 "-" "CCBot/2.0 (https://commoncrawl.org/faq/)"
34.9.71.127 - - [06/Sep/2026:22:08:34 +0000] "GET /%2e%2e/.env HTTP/2.0" 400 1841 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; GPTBot/1.3; +https://openai.com/gptbot)"
34.9.71.127 - - [06/Sep/2026:22:08:34 +0000] "GET /signin HTTP/2.0" 404 1855 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36 Edg/151.0.0.0"
34.9.71.127 - - [06/Sep/2026:22:08:
...
show less
Brute-Force
🇺🇸
jormaster3k
2026-09-06 21:44:29
(2 days ago)
Attack against Apache (too many 404s)
Web App Attack
🇩🇪
Nightreaver
2026-09-06 21:26:41
(2 days ago)
34.9.71.127 - - [06/Sep/2026:23:26:41 0200] "GET /files../.env HTTP/1.1" 404 5718 "-" "Mozilla/5.0 ...
show more
34.9.71.127 - - [06/Sep/2026:23:26:41 0200] "GET /files../.env HTTP/1.1" 404 5718 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ChatGPT-User/1.0; https://openai.com/bot)"
34.9.71.127 - - [06/Sep/2026:23:26:41 0200] "GET /dist/manifest.json HTTP/1.1" 404 5718 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36 Edg/152.0.0.0"
34.9.71.127 - - [06/Sep/2026:23:26:41 0200] "GET /wp-json HTTP/1.1" 404 5718 "-" "Mozilla/5.0 (compatible; Google-Extended; http://www.google.com/bot.html)"
34.9.71.127 - - [06/Sep/2026:23:26:41 0200] "GET /webpack-stats.json HTTP/1.1" 404 5718 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36 Edg/152.0.0.0"
34.9.71.127 - - [06/Sep/2026:23:26:41 0200] "GET /static/manifest.json HTTP/1.1" 404 5718 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36 Edg/152.0.0.0[...]
show less
Bad Web Bot
Web App Attack
🇺🇸
CBJ
2026-09-06 19:57:35
(2 days ago)
fail2ban: apache-filepath-recon
...
Web App Attack
🇩🇪
Gwyneth Llewelyn
2026-09-06 19:06:00
(2 days ago)
2026/09/06 20:05:57 [error] 380594#380594: *3291509 access forbidden by rule, client: 34.9.71.127, s ...
show more
2026/09/06 20:05:57 [error] 380594#380594: *3291509 access forbidden by rule, client: 34.9.71.127, server: gwynethllewelyn.net, request: "GET /assets../.env HTTP/2.0", host: "gwynethllewelyn.net"
2026/09/06 20:05:58 [error] 380594#380594: *3291523 access forbidden by rule, client: 34.9.71.127, server: gwynethllewelyn.net, request: "GET /images../.env HTTP/2.0", host: "gwynethllewelyn.net"
2026/09/06 20:05:58 [error] 380594#380594: *3291526 access forbidden by rule, client: 34.9.71.127, server: gwynethllewelyn.net, request: "GET /uploads../.env HTTP/2.0", host: "gwynethllewelyn.net"
show less
Brute-Force
Web App Attack
🇳🇱
Josh S.
2026-09-06 18:42:57
(2 days ago)
{"level":"info","ts":1788720176.5514784,"logger":"http.log.access.log0","msg":"handled request","req ...
show more
{"level":"info","ts":1788720176.5514784,"logger":"http.log.access.log0","msg":"handled request","request":{"remote_ip":"34.9.71.127","remote_port":"41400","client_ip":"34.9.71.127","proto":"HTTP/2.0","method":"GET","host":"git.joshseveros.cloud","uri":"/.env?raw","headers":{"Cookie":["REDACTED"],"X-Middleware-Subrequest":["src/middleware:nowaf:src/middleware:src/middleware:src/middleware:src/middleware:middleware:middleware:nowaf:middleware:middleware:middleware:pages/_middleware"],"X-Nextjs-Data":["1"],"User-Agent":["Mozilla/5.0 (compatible; Hunyuan/1.0; +https://hunyuan.tencent.com/)"],"Accept-Encoding":["gzip"],"Accept":["*/*"]},"tls":{"resumed":false,"version":772,"cipher_suite":4865,"proto":"h2","server_name":"git.joshseveros.cloud"}},"bytes_read":0,"user_id":"","duration":0.001368281,"size":11,"status":404,"resp_headers":{"Content-Length":["11"],"Server":["Caddy"],"Alt-Svc":["h3=\":443\"; ma=2592000"],"Cache-Control":["max-age=0, private, must-revalidate, no-transform"],"Content-
...
show less
Web App Attack