๐ง๐ท
dermatovirtual
2026-10-06 11:30:34
(1 day ago)
Dermato Virtual CSIRT: Malicious web exploit/scanning probes against app.dermatovirtual.com.br (Web ...
show more
Dermato Virtual CSIRT: Malicious web exploit/scanning probes against app.dermatovirtual.com.br (Web Server Ports 80/443). 36 unauthorized requests recorded between 2026-10-05 11:26:27 UTC and 2026-10-05 11:26:37 UTC (rate: ~36 req/min). Edge perimeter firewall drop active.
Log sample:
[2026-10-05 11:26:31 UTC] IP: 34.95.33.221 - W3C IIS (Port 443): GET /.env -> HTTP 404 [CLIENT: 34.95.33.221]
[2026-10-05 11:26:31 UTC] IP: 34.95.33.221 - W3C IIS (Port 443): GET /.env -> HTTP 404 [CLIENT: 34.95.33.221]
[2026-10-05 11:26:31 UTC] IP: 34.95.33.221 - W3C IIS (Port 443): GET /.env -> HTTP 404 [CLIENT: 34.95.33.221]
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
niedson
2026-10-06 07:30:01
(1 day ago)
Automated scanning for exposed secrets: repeated requests for multiple distinct credential paths (.e ...
show more
Automated scanning for exposed secrets: repeated requests for multiple distinct credential paths (.env variants, .git metadata, .ssh private keys, .aws/credentials). Unsolicited. Reported automatically.
show less
Web App Attack
๐ง๐ท
SOC-BR
2026-10-06 07:26:03
(1 day ago)
Attack detected by Fortinet - applications3: Vercel.Next.js.x-middleware-subrequest.Authentication.B ...
show more
Attack detected by Fortinet - applications3: Vercel.Next.js.x-middleware-subrequest.Authentication.Bypass - 2026-10-05 11:21:36 - Source Port 56504
show less
Port Scan
Hacking
๐ง๐ท
Host One
2026-10-06 04:00:29
(2 days ago)
Web vulnerability scanning: requests to known exploit/probe paths; requests blocked by WAF (ModSecur ...
show more
Web vulnerability scanning: requests to known exploit/probe paths; requests blocked by WAF (ModSecurity) rules. Blocked by firewall on 5 different hosting servers. Protocol TCP, port 80, 443 (HTTP/HTTPS). Requested paths: /config.json, /graphql, /info.php, /phpinfo.php, /firebase-config.json. Automated report.
show less
Hacking
Bad Web Bot
Web App Attack
๐ง๐ท
Sysadmin-CLC
2026-10-06 00:46:57
(2 days ago)
Probing and trying to access sensitive files caught in f2b nginx-forbidden filter
Web App Attack
Port Scan
๐บ๐ธ
paulo.apoloni
2026-10-06 00:42:04
(2 days ago)
34.95.33.221 - - [05/Oct/2026:21:42:03 -0300] "GET /.htpasswd HTTP/1.1" 444 0 "-" "Mozilla/5.0 (comp ...
show more
34.95.33.221 - - [05/Oct/2026:21:42:03 -0300] "GET /.htpasswd HTTP/1.1" 444 0 "-" "Mozilla/5.0 (compatible; cohere-ai; +https://cohere.com/crawler)"
34.95.33.221 - - [05/Oct/2026:21:42:03 -0300] "GET /.ssh/id_rsa HTTP/1.1" 444 0 "-" "Mozilla/5.0 (compatible; KimiBot/1.0; +https://kimi.ai/)"
34.95.33.221 - - [05/Oct/2026:21:42:03 -0300] "GET /.ssh/id_rsa HTTP/1.1" 444 0 "-" "Mozilla/5.0 (compatible; KimiBot/1.0; +https://kimi.ai/)"
...
show less
Bad Web Bot
Web App Attack
๐ซ๐ท
georgton.tech
2026-10-05 23:59:08
(2 days ago)
34.95.33.221 - - [05/Oct/2026:20:59:06 -0300] "GET /public/plugins/text/../../../../../../../../proc ...
show more
34.95.33.221 - - [05/Oct/2026:20:59:06 -0300] "GET /public/plugins/text/../../../../../../../../proc/self/environ HTTP/1.1" 400 166 "-" "-"
34.95.33.221 - - [05/Oct/2026:20:59:08 -0300] "GET /..%2f.env HTTP/1.1" 400 166 "-" "-"
34.95.33.221 - - [05/Oct/2026:20:59:08 -0300] "GET /%2e%2e/.env HTTP/1.1" 400 166 "-" "-"
...
show less
Bad Web Bot
Web App Attack
๐ง๐ท
SvrAdmin
2026-10-05 22:56:58
(2 days ago)
[204] (cpanel) Failed cPanel login from 34.95.33.221 (CA/Canada/221.33.95.34.bc.googleusercontent.co ...
show more
[204] (cpanel) Failed cPanel login from 34.95.33.221 (CA/Canada/221.33.95.34.bc.googleusercontent.com): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CPANEL; Logs: [2026-10-05 19:56:52 -0300] info [cpaneld] 34.95.33.221 - - "GET /static/manifest.json HTTP/1.1" FAILED LOGIN cpaneld: login attempt without username
[2026-10-05 19:56:52 -0300] info [cpaneld] 34.95.33.221 - - "GET /manifest.json HTTP/1.1" FAILED LOGIN cpaneld: login attempt without username
[2026-10-05 19:56:52 -0300] info [cpaneld] 34.95.33.221 - - "GET /z9x8c7v6b5-debug-trigger-cpanel.portaldebeltrao.com.br HTTP/1.1" FAILED LOGIN cpaneld: login attempt without username
[2026-10-05 19:56:52 -0300] info [cpaneld] 34.95.33.221 - - "GET /7mjynkoo45ek84o1c4cp HTTP/1.1" FAILED LOGIN cpaneld: login attempt without username
[2026-10-05 19:56:53 -0300] info [cpaneld] 34.95.33.221 - - "GET /wp-json HTTP/1.1" FAILED LOGIN cpaneld: login attempt without username
show less
Port Scan
Hacking
Brute-Force
Exploited Host
๐ง๐ท
govfacil.app
2026-10-05 22:30:15
(2 days ago)
(cpanel) Failed cPanel login from 34.95.33.221 (CA/Canada/221.33.95.34.bc.googleusercontent.com): 50 ...
show more
(cpanel) Failed cPanel login from 34.95.33.221 (CA/Canada/221.33.95.34.bc.googleusercontent.com): 50 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CPANEL; Logs: [2026-10-05 19:30:06 -0300] info [cpaneld] 34.95.33.221 - - "GET /z9x8c7v6b5-debug-trigger-cpanel.hostmine.com.br HTTP/1.1" FAILED LOGIN cpaneld: login attempt without username
[2026-10-05 19:30:06 -0300] info [cpaneld] 34.95.33.221 - - "GET /qdgm4wdyxf87slhk2q66 HTTP/1.1" FAILED LOGIN cpaneld: login attempt without username
[2026-10-05 19:30:06 -0300] info [cpaneld] 34.95.33.221 - - "GET /build/manifest.json HTTP/1.1" FAILED LOGIN cpaneld: login attempt without username
[2026-10-05 19:30:06 -0300] info [cpaneld] 34.95.33.221 - - "GET /static../.env HTTP/1.1" FAILED LOGIN cpaneld: login attempt without username
[2026-10-05 19:30:06 -0300] info [cpaneld] 34.95.33.221 - - "GET /.ssh/id_rsa HTTP/1.1" FAILED LOGIN cpaneld: login attempt without username
[2026-10-05 19:30:06 -0300] info [cpaneld] 34.95.33.221 - - "P [truncated]
show less
Brute-Force
๐ง๐ท
vfAcceloReporter
2026-10-05 20:34:06
(2 days ago)
34.95.33.221 - - [05/Oct/2026:17:34:06 -0300] "GET /@fs/app/.env?raw?? HTTP/2.0" 404 114 "-" "Mozill ...
show more
34.95.33.221 - - [05/Oct/2026:17:34:06 -0300] "GET /@fs/app/.env?raw?? HTTP/2.0" 404 114 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexitybot)"
...
show less
Brute-Force
Web App Attack
Exploited Host
Anonymous
2026-10-05 17:02:17
(2 days ago)
Kubernetes Authentication Bypass (CVE-2019-11248); Linux System Files Information Disclosure; Vite I ...
show more
Kubernetes Authentication Bypass (CVE-2019-11248); Linux System Files Information Disclosure; Vite Information Disclosure; Apache HTTP Server Directory Traversal; Sensitive Configuration File Disclosure; Web Servers Directory Traversal.
show less
Hacking
Web App Attack
๐จ๐ฆ
Blinker73
2026-10-05 12:01:51
(2 days ago)
34.95.33.221 - - [05/Oct/2026:08:01:50 -0400] "GET /api/uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f ...
show more
34.95.33.221 - - [05/Oct/2026:08:01:50 -0400] "GET /api/uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2fproc/self/environ HTTP/1.1" 400 150 "-" "-"
34.95.33.221 - - [05/Oct/2026:08:01:50 -0400] "GET /api/uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f.env HTTP/1.1" 400 150 "-" "-"
34.95.33.221 - - [05/Oct/2026:08:01:50 -0400] "GET /public/plugins/text/../../../../../../../../proc/self/environ HTTP/1.1" 400 150 "-" "-"
34.95.33.221 - - [05/Oct/2026:08:01:51 -0400] "GET /api/uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2f.env HTTP/1.1" 400 150 "-" "-"
show less
Bad Web Bot
Web App Attack
๐ง๐ท
dermatovirtual
2026-10-05 11:29:57
(2 days ago)
Dermato Virtual CSIRT: Malicious web exploit/scanning probes against app.dermatovirtual.com.br (Web ...
show more
Dermato Virtual CSIRT: Malicious web exploit/scanning probes against app.dermatovirtual.com.br (Web Server Ports 80/443). 36 unauthorized requests recorded between 2026-10-05 11:26:27 UTC and 2026-10-05 11:26:37 UTC (rate: ~36 req/min). Edge perimeter firewall drop active.
Log sample:
[2026-10-05 11:26:31 UTC] IP: 34.95.33.221 - W3C IIS (Port 443): GET /.env -> HTTP 404 [CLIENT: 34.95.33.221]
[2026-10-05 11:26:31 UTC] IP: 34.95.33.221 - W3C IIS (Port 443): GET /.env -> HTTP 404 [CLIENT: 34.95.33.221]
[2026-10-05 11:26:31 UTC] IP: 34.95.33.221 - W3C IIS (Port 443): GET /.env -> HTTP 404 [CLIENT: 34.95.33.221]
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
InfraGuardAPI
2026-10-05 11:05:28
(2 days ago)
InfraGuard API: sonda honeypot em /api/.env
Hacking
Bad Web Bot
๐บ๐ธ
paulo.apoloni
2026-10-05 09:58:07
(2 days ago)
34.95.33.221 - - [05/Oct/2026:06:58:06 -0300] "GET /files../.env HTTP/1.1" 444 0 "-" "Mozilla/5.0 Ap ...
show more
34.95.33.221 - - [05/Oct/2026:06:58:06 -0300] "GET /files../.env HTTP/1.1" 444 0 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexitybot)"
34.95.33.221 - - [05/Oct/2026:06:58:06 -0300] "GET /static../.env HTTP/1.1" 444 0 "-" "CCBot/2.0 (https://commoncrawl.org/faq/)"
34.95.33.221 - - [05/Oct/2026:06:58:06 -0300] "GET /files../.env HTTP/1.1" 444 0 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexitybot)"
34.95.33.221 - - [05/Oct/2026:06:58:06 -0300] "GET /static../.env HTTP/1.1" 444 0 "-" "CCBot/2.0 (https://commoncrawl.org/faq/)"
...
show less
Bad Web Bot
Web App Attack