๐ง๐ท
dermatovirtual
2026-10-05 15:43:12
(2 hours ago)
Dermato Virtual CSIRT: Malicious web exploit/scanning probes against app.dermatovirtual.com.br (Web ...
show more
Dermato Virtual CSIRT: Malicious web exploit/scanning probes against app.dermatovirtual.com.br (Web Server Ports 80/443). 89 unauthorized requests recorded between 2026-10-05 11:56:08 UTC and 2026-10-05 11:56:18 UTC (rate: ~89 req/min). Edge perimeter firewall drop active.
Log sample:
[2026-10-05 11:56:17 UTC] IP: 35.230.8.252 - W3C IIS (Port 443): GET /.env -> HTTP 404 [CLIENT: 35.230.8.252]
[2026-10-05 11:56:17 UTC] IP: 35.230.8.252 - W3C IIS (Port 443): GET /.env -> HTTP 404 [CLIENT: 35.230.8.252]
[2026-10-05 11:56:18 UTC] IP: 35.230.8.252 - W3C IIS (Port 443): GET /actuator/configprops -> HTTP 404 [CLIENT: 35.230.8.252]
show less
Bad Web Bot
Web App Attack
Anonymous
2026-10-05 15:26:33
(2 hours ago)
2026/10/05 12:26:32 [error] 1378263#1378263: *154269 openat() "/var/www/chat.sorotop.com.br/web/admi ...
show more
2026/10/05 12:26:32 [error] 1378263#1378263: *154269 openat() "/var/www/chat.sorotop.com.br/web/admin/login" failed (2: No such file or directory), client: 35.230.8.252, server: chat.sorotop.com.br, request: "GET /admin/login HTTP/2.0", host: "chat.sorotop.com.br"
2026/10/05 12:26:32 [error] 1378263#1378263: *154269 openat() "/var/www/chat.sorotop.com.br/web/admin" failed (2: No such file or directory), client: 35.230.8.252, server: chat.sorotop.com.br, request: "GET /admin HTTP/2.0", host: "chat.sorotop.com.br"
2026/10/05 12:26:32 [error] 1378263#1378263: *154269 access forbidden by rule, client: 35.230.8.252, server: chat.sorotop.com.br, request: "GET /@fs/app/.env?raw?? HTTP/2.0", host: "chat.sorotop.com.br"
...
show less
Port Scan
๐ง๐ท
Sysadmin-CLC
2026-10-05 13:15:17
(4 hours ago)
Caught by f2b nginx-limit-req.
Web App Attack
DDoS Attack
๐จ๐ฆ
cubie
2026-10-05 10:10:58
(7 hours ago)
Port Scan: Admin Enumeration - Reported by CubieCloud Firewall [CFW_H430-004]
Port Scan
๐บ๐ธ
paulo.apoloni
2026-10-05 08:58:38
(9 hours ago)
35.230.8.252 - - [05/Oct/2026:05:58:33 -0300] "GET /.ssh/id_rsa HTTP/1.1" 404 146 "-" "Mozilla/5.0 ( ...
show more
35.230.8.252 - - [05/Oct/2026:05:58:33 -0300] "GET /.ssh/id_rsa HTTP/1.1" 404 146 "-" "Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; +https://kimi.ai/)"
35.230.8.252 - - [05/Oct/2026:05:58:33 -0300] "GET /.htpasswd HTTP/1.1" 404 146 "-" "Mozilla/5.0 (compatible; Bravebot/1.0; +https://brave.com/search/)"
35.230.8.252 - - [05/Oct/2026:05:58:34 -0300] "GET /.ssh/id_ed25519 HTTP/1.1" 404 146 "-" "Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; +https://kimi.ai/)"
35.230.8.252 - - [05/Oct/2026:05:58:34 -0300] "GET /.ssh/config HTTP/1.1" 404 146 "-" "Mozilla/5.0 (compatible; Qwenbot/1.0; +https://qwen.alibaba.com/)"
35.230.8.252 - - [05/Oct/2026:05:58:36 -0300] "GET /.env?raw HTTP/1.1" 404 146 "-" "Mozilla/5.0 (compatible; Meta-ExternalAgent/1.0; +https://developers.facebook.com/docs/sharing/webmasters/crawler)"
...
show less
Web App Attack
๐ฉ๐ช
niedson
2026-10-05 08:30:02
(9 hours ago)
Automated scanning for exposed secrets: repeated requests for multiple distinct credential paths (.e ...
show more
Automated scanning for exposed secrets: repeated requests for multiple distinct credential paths (.env variants, .git metadata, .ssh private keys, .aws/credentials). Unsolicited. Reported automatically.
show less
Web App Attack
๐บ๐ธ
abuse-opdc
2026-10-05 06:36:08
(11 hours ago)
Malicious HTTP requests matching injection/exploit signatures.
Web App Attack
Brute-Force
๐ง๐ท
Host One
2026-10-05 05:15:37
(12 hours ago)
Web vulnerability scanning: requests to known exploit/probe paths. Blocked by firewall on 5 differen ...
show more
Web vulnerability scanning: requests to known exploit/probe paths. Blocked by firewall on 5 different hosting servers. Protocol TCP, port 80, 443 (HTTP/HTTPS). Requested paths: /google-credentials.json, /graphql, /_profiler/latest, /_profiler/open, /firebase-credentials.json. Automated report.
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
agaesteves
2026-10-05 03:39:58
(14 hours ago)
[SISHIPISMO 360] TipoAtaque.PATH_PROBE | Acesso a path suspeito: /static../.env | Paths: /static../. ...
show more
[SISHIPISMO 360] TipoAtaque.PATH_PROBE | Acesso a path suspeito: /static../.env | Paths: /static../.env | UA: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perplexity-User/1.0; +https://perplex
show less
Web App Attack
๐ซ๐ท
mrcrassi
2026-10-05 02:23:18
(15 hours ago)
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: BLOCK
Protocol: HTTP/2 (POST metho ...
show more
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: BLOCK
Protocol: HTTP/2 (POST method)
Endpoint: /php-cgi/php-cgi.exe
UA: Mozilla/5.0 (compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot)
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ช๐ธ
pipeline.es
2026-10-05 00:35:59
(17 hours ago)
Web scanning / probing for vulnerable paths | URL: /api/system/fileView?file=/app/.env | Evidence: e ...
show more
Web scanning / probing for vulnerable paths | URL: /api/system/fileView?file=/app/.env | Evidence: evoluirturismo.com.br 35.230.8.252 - - [05/Oct/2026:02:35:31 +0200] \"GET /api/system/fileView?file=/app/.env HTTP/2.0\" 404 19051 \"-\" \"Mozilla/5.0 (compatible; Bytespider; [email]) AppleWebKit/537.36\" GEOIP_COUNTRY_CODE=US 22977 | ASN: GOOGLE-CLOUD-PLATFORM | Country: US
show less
Port Scan
Web App Attack
๐ง๐ท
Halux
2026-10-05 00:22:29
(17 hours ago)
35.230.8.252 Web Application Firewall multiple violations
Hacking
Web App Attack
๐ง๐ท
Peregrine
2026-10-04 22:02:18
(19 hours ago)
Fail2Ban ct101 Jail: tomcat-404 | Evidence: 35.230.8.252 162.158.42.135 - - [04/Oct/2026:19:02:16 -0 ...
show more
Fail2Ban ct101 Jail: tomcat-404 | Evidence: 35.230.8.252 162.158.42.135 - - [04/Oct/2026:19:02:16 -0300] "GET /dist/.vite/manifest.json HTTP/1.1" 404 18149
35.230.8.252 162.158.42.135 - - [04/Oct/2026:19:02:16 -0300] "GET /1wgsl35o44am6tfn8oxo HTTP/1.1" 404 18149
35.230.8.252 162.158.42.135 - - [04/Oct/2026:19:02:16 -0300] "GET /dist/manifest.json HTTP/1.1" 404 18149
35.230.8.252 162.158.42.136 - - [04/Oct/2026:19:02:16 -0300] "POST /lib/terminal-xhr.php HTTP/1.1" 404 18149
35.230.8.252 162.158.42.136 - - [04/Oct/2026:19:02:16 -0300] "GET /z9x8c7v6b5-debug-trigger-decise.com.br HTTP/1.1" 404 18149
show less
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-10-04 21:46:40
(20 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐ง๐ท
dominioz
2026-10-04 21:29:43
(20 hours ago)
2026-10-04 21:29:38 GET /@fs/..%2f..%2f..%2f..%2f..%2fproc/self/environ raw?? - 35.230.8.252 HTTP/2 ...
show more
2026-10-04 21:29:38 GET /@fs/..%2f..%2f..%2f..%2f..%2fproc/self/environ raw?? - 35.230.8.252 HTTP/2 Mozilla/5.0+AppleWebKit/537.36+(KHTML,+like+Gecko;+compatible;+PerplexityBot/1.0;++https://perplexity.ai/perplexitybot) - 301 654
...
show less
Bad Web Bot
Web App Attack