|
๐ณ๐ฑ
93.123.109.152
|
|
93.123.109.152 - - [12/Aug/2026:09:49:19 +0000] "GET /wp-content/.git/config HTTP/1.1" 404 22 "-" "M ...
show more
93.123.109.152 - - [12/Aug/2026:09:49:19 +0000] "GET /wp-content/.git/config HTTP/1.1" 404 22 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/123.0.0.0 Safari/537.36" 505 0.012 [messenger-bridge-service-80] [] 10.244.27.141:8000 22 0.012 404 71f3dc34acdfd5dd65c1dd76feb39000
...
show less
|
Web App Attack
|
|
๐ณ๐ฑ
195.178.110.199
|
|
195.178.110.199 - - [12/Aug/2026:09:27:46 +0000] "GET /.boto HTTP/1.1" 401 574 "-" "Mozilla/5.0 (Mac ...
show more
195.178.110.199 - - [12/Aug/2026:09:27:46 +0000] "GET /.boto HTTP/1.1" 401 574 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36" 510 0.000 [default-comfy-mars-service-80] [] - - - - 387340b9ae3af609ef4978f64b9cc6b4
195.178.110.199 - - [12/Aug/2026:09:27:46 +0000] "GET /%2egit/%63onfig HTTP/1.1" 401 172 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14_5) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.5 Safari/605.1.15" 517 0.000 [default-comfy-mars-service-80] [] - - - - c175d52af28419bf89e6f595e061a59f
195.178.110.199 - - [12/Aug/2026:09:27:46 +0000] "GET /*/[slug] HTTP/1.1" 401 574 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36" 497 0.000 [default-comfy-mars-service-80] [] - - - - a1e2c8e16a246f3e2f77bcb6d254116b
...
show less
|
Brute-Force
|
|
๐บ๐ธ
2a06:98c0:3600::103
|
|
2a06:98c0:3600::103 - - [12/Aug/2026:08:40:29 +0000] "GET /.git/config HTTP/1.1" 404 12182 "-" "Mozi ...
show more
2a06:98c0:3600::103 - - [12/Aug/2026:08:40:29 +0000] "GET /.git/config HTTP/1.1" 404 12182 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36" 850 0.001 [default-cv-service-80] [] 10.244.27.146:3000 12182 0.001 404 7c949510cbba3f42df7d4d5770243fc6
2a06:98c0:3600::103 - - [12/Aug/2026:08:40:29 +0000] "GET /.git/HEAD HTTP/1.1" 404 12182 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36" 848 0.001 [default-cv-service-80] [] 10.244.27.161:3000 12182 0.001 404 df399ea5cce5b52c13501dc4853958a5
...
show less
|
Web App Attack
|
|
๐ง๐ช
34.62.13.13
|
|
2026-08-11 21:39:14,857 fail2ban.actions [964]: NOTICE [k8s-nginx-403] Ban 34.62.13.13
2026- ...
show more
2026-08-11 21:39:14,857 fail2ban.actions [964]: NOTICE [k8s-nginx-403] Ban 34.62.13.13
2026-08-11 21:39:15,973 fail2ban.actions [964]: NOTICE [k8s-nginx-404] Ban 34.62.13.13
2026-08-11 21:39:19,874 fail2ban.actions [964]: NOTICE [k8s-nginx-bruteforce] Ban 34.62.13.13
...
show less
|
Exploited Host
|
|
๐ง๐ช
34.62.13.13
|
|
34.62.13.13 - - [12/Aug/2026:07:39:16 +0000] "GET /.env.production HTTP/1.1" 403 0 "-" "anthropic-ai ...
show more
34.62.13.13 - - [12/Aug/2026:07:39:16 +0000] "GET /.env.production HTTP/1.1" 403 0 "-" "anthropic-ai" 401 0.000 [default-cv-service-80] [] 10.244.27.161:3000 0 0.000 403 f74f58cc0c1596c0cb3d52bf0bf68bfa
34.62.13.13 - - [12/Aug/2026:07:39:18 +0000] "GET /.ssh/id_ed25519 HTTP/1.1" 403 0 "-" "anthropic-ai" 401 0.000 [default-cv-service-80] [] 10.244.27.161:3000 0 0.001 403 ca84120c570878041f714c9a8d50699b
34.62.13.13 - - [12/Aug/2026:07:39:19 +0000] "GET /.aider.conf.yml HTTP/1.1" 403 0 "-" "anthropic-ai" 401 0.001 [default-cv-service-80] [] 10.244.27.146:3000 0 0.000 403 63ce3b76a8c16aa81efc3568da3abe13
...
show less
|
Brute-Force
|
|
๐ง๐ช
34.62.13.13
|
|
34.62.13.13 - - [12/Aug/2026:07:39:14 +0000] "GET /wp-json HTTP/1.1" 403 0 "-" "anthropic-ai" 393 0. ...
show more
34.62.13.13 - - [12/Aug/2026:07:39:14 +0000] "GET /wp-json HTTP/1.1" 403 0 "-" "anthropic-ai" 393 0.000 [default-cv-service-80] [] 10.244.27.161:3000 0 0.001 403 76df50d711dff19271cd7fbb3bbe0135
34.62.13.13 - - [12/Aug/2026:07:39:14 +0000] "GET /.git/config HTTP/1.1" 403 0 "-" "anthropic-ai" 397 0.002 [default-cv-service-80] [] 10.244.27.146:3000 0 0.002 403 dea7294c631ea36c1b2fecd31845d1be
34.62.13.13 - - [12/Aug/2026:07:39:14 +0000] "GET /.aws/credentials HTTP/1.1" 403 0 "-" "anthropic-ai" 402 0.000 [default-cv-service-80] [] 10.244.27.161:3000 0 0.000 403 785c58ec5aafa41d3761b28d16695235
34.62.13.13 - - [12/Aug/2026:07:39:14 +0000] "GET /.aws/config HTTP/1.1" 403 0 "-" "anthropic-ai" 397 0.002 [default-cv-service-80] [] 10.244.27.146:3000 0 0.001 403 dae0c30e63066b2c2dc425cd28f528d3
34.62.13.13 - - [12/Aug/2026:07:39:15 +0000] "GET /.gitlab-ci.yml HTTP/1.1" 403 0 "-" "anthropic-ai" 400 0.002 [default-cv-service-80] [] 10.244.27.161:3000 0 0.003 403 1c3d09f32c42fc3cbc19419dbce7fbbf
...
show less
|
Web App Attack
|
|
๐บ๐ธ
2001:19f0:6401:24f:5400:5ff:fef1:c38a
|
|
2001:19f0:6401:24f:5400:5ff:fef1:c38a - - [12/Aug/2026:07:49:35 +0000] "GET /config/.env.txt HTTP/1. ...
show more
2001:19f0:6401:24f:5400:5ff:fef1:c38a - - [12/Aug/2026:07:49:35 +0000] "GET /config/.env.txt HTTP/1.1" 404 4036 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:125.0) Gecko/20100101 Firefox/125.0" 657 0.003 [default-techdata-service-80] [] 10.244.27.142:3000 4036 0.003 404 cb782180d4cfa2746ae7516859b8b6cb
2001:19f0:6401:24f:5400:5ff:fef1:c38a - - [12/Aug/2026:07:49:36 +0000] "GET /.env HTTP/1.1" 404 4036 "https://techdata.solutions/.env/" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14_4) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.4 Safari/605.1.15" 723 0.004 [default-techdata-service-80] [] 10.244.27.142:3000 4036 0.004 404 59c75d1e68a68c0892c5df05b8d4b4f7
2001:19f0:6401:24f:5400:5ff:fef1:c38a - - [12/Aug/2026:07:49:37 +0000] "GET /config%5c.env HTTP/1.1" 404 4036 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:125.0) Gecko/20100101 Firefox/125.0" 655 0.003 [default-techdata-service-80] [] 10.244.27.142:3000 4036 0.003 404 cd1eed23d84e52b89d46f2e47f04dc3b
2001:19f0:6401:24f:54
...
show less
|
Web App Attack
|
|
๐ง๐ช
34.62.13.13
|
|
34.62.13.13 - - [12/Aug/2026:07:39:14 +0000] "GET /wp-json HTTP/1.1" 403 0 "-" "anthropic-ai" 393 0. ...
show more
34.62.13.13 - - [12/Aug/2026:07:39:14 +0000] "GET /wp-json HTTP/1.1" 403 0 "-" "anthropic-ai" 393 0.000 [default-cv-service-80] [] 10.244.27.161:3000 0 0.001 403 76df50d711dff19271cd7fbb3bbe0135
34.62.13.13 - - [12/Aug/2026:07:39:14 +0000] "GET /rclone.conf HTTP/1.1" 403 0 "-" "anthropic-ai" 397 0.001 [default-cv-service-80] [] 10.244.27.161:3000 0 0.001 403 9711cde82de2237e3b4cbd5ddd3132d0
34.62.13.13 - - [12/Aug/2026:07:39:14 +0000] "GET /.git/config HTTP/1.1" 403 0 "-" "anthropic-ai" 397 0.002 [default-cv-service-80] [] 10.244.27.146:3000 0 0.002 403 dea7294c631ea36c1b2fecd31845d1be
34.62.13.13 - - [12/Aug/2026:07:39:14 +0000] "GET /z9x8c7v6b5-debug-trigger-gregorymariani.com HTTP/1.1" 403 0 "-" "anthropic-ai" 429 0.001 [default-cv-service-80] [] 10.244.27.146:3000 0 0.000 403 9fe2b775731c672fbda29cdbe2eb825d
34.62.13.13 - - [12/Aug/2026:07:39:14 +0000] "GET /.aws/credentials HTTP/1.1" 403 0 "-" "anthropic-ai" 402 0.000 [default-cv-service-80] [] 10.244.27.161:3000 0 0.000 403 785c5
...
show less
|
Web App Attack
|
|
๐บ๐ธ
2600:3000:1305:4212::83
|
|
2600:3000:1305:4212::83 - - [12/Aug/2026:06:17:37 +0000] "GET /.well-known/acme-challenge/NjO4ZeyLKw ...
show more
2600:3000:1305:4212::83 - - [12/Aug/2026:06:17:37 +0000] "GET /.well-known/acme-challenge/NjO4ZeyLKw2VVYuwcjKFeszxBiOo_OiOsy7hzOUq32o HTTP/1.1" 404 12182 "http://www.gregorymariani.com/.well-known/acme-challenge/NjO4ZeyLKw2VVYuwcjKFeszxBiOo_OiOsy7hzOUq32o" "Mozilla/5.0 (compatible; Let's Encrypt validation server; +https://www.letsencrypt.org)" 670 0.001 [default-cv-service-80] [] 10.244.27.146:3000 12182 0.001 404 c9fd10b6d74d746b13d493b661d18528
...
show less
|
Web App Attack
|
|
๐ณ๐ฑ
45.148.10.120
|
|
45.148.10.120 - - [12/Aug/2026:05:08:00 +0000] "GET / HTTP/1.1" 401 574 "-" "Mozilla/5.0 (Fedora; Li ...
show more
45.148.10.120 - - [12/Aug/2026:05:08:00 +0000] "GET / HTTP/1.1" 401 574 "-" "Mozilla/5.0 (Fedora; Linux i686) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/129.0.0.0 Safari/537.36" 496 0.000 [default-comfy-mars-service-80] [] - - - - 1afe3c38371b69b6e06e5b6794d7c44a
...
show less
|
Brute-Force
|
|
๐ณ๐ฑ
93.123.109.152
|
|
93.123.109.152 - - [11/Aug/2026:23:25:59 +0000] "GET /wp-admin/.git/config HTTP/1.1" 404 196 "-" "Mo ...
show more
93.123.109.152 - - [11/Aug/2026:23:25:59 +0000] "GET /wp-admin/.git/config HTTP/1.1" 404 196 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/123.0.0.0 Safari/537.36" 502 0.002 [erp-dolibarr-svc-80] [] 10.244.10.198:80 196 0.001 404 8fa82e39ee5ba80f4ea7bf524f88f8dc
93.123.109.152 - - [11/Aug/2026:23:25:59 +0000] "GET /backup/.git/config HTTP/1.1" 404 196 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/123.0.0.0 Safari/537.36" 500 0.002 [erp-dolibarr-svc-80] [] 10.244.10.198:80 196 0.003 404 37a05b2150a3b7d65e631bf246c48432
93.123.109.152 - - [11/Aug/2026:23:25:59 +0000] "GET /wp-content/.git/config HTTP/1.1" 404 196 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/123.0.0.0 Safari/537.36" 504 0.002 [erp-dolibarr-svc-80] [] 10.244.10.198:80 196 0.001 404 6a117e487efb5d40e98cfad21fecf767
...
show less
|
Web App Attack
|
|
๐บ๐ธ
8.228.106.194
|
|
2026-08-11 12:31:59,863 fail2ban.actions [982]: NOTICE [k8s-nginx-403] Ban 8.228.106.194
202 ...
show more
2026-08-11 12:31:59,863 fail2ban.actions [982]: NOTICE [k8s-nginx-403] Ban 8.228.106.194
2026-08-11 12:31:59,939 fail2ban.actions [982]: NOTICE [k8s-nginx-bruteforce] Ban 8.228.106.194
2026-08-11 12:32:00,406 fail2ban.actions [982]: NOTICE [k8s-nginx-404] Ban 8.228.106.194
...
show less
|
Exploited Host
|
|
๐บ๐ธ
8.228.106.194
|
|
8.228.106.194 - - [11/Aug/2026:22:31:59 +0000] "GET /.git/config HTTP/1.1" 403 0 "-" "anthropic-ai" ...
show more
8.228.106.194 - - [11/Aug/2026:22:31:59 +0000] "GET /.git/config HTTP/1.1" 403 0 "-" "anthropic-ai" 401 0.001 [default-cv-service-80] [] 10.244.14.156:3000 0 0.000 403 95ed101e06f60ddd869efa7283295083
8.228.106.194 - - [11/Aug/2026:22:31:59 +0000] "GET /z9x8c7v6b5-debug-trigger-gregorymariani.com HTTP/1.1" 403 0 "-" "anthropic-ai" 433 0.001 [default-cv-service-80] [] 10.244.14.157:3000 0 0.002 403 971ad013aa2da966326f67990299ee65
8.228.106.194 - - [11/Aug/2026:22:31:59 +0000] "GET /wp-json HTTP/1.1" 403 0 "-" "anthropic-ai" 397 0.000 [default-cv-service-80] [] 10.244.14.157:3000 0 0.001 403 e1fb3e6346fb020fcf39b2de4e40d615
8.228.106.194 - - [11/Aug/2026:22:31:59 +0000] "GET /rclone.conf HTTP/1.1" 403 0 "-" "anthropic-ai" 401 0.002 [default-cv-service-80] [] 10.244.14.157:3000 0 0.002 403 8434dc03285217e3c5831bfc05dc5a2e
8.228.106.194 - - [11/Aug/2026:22:31:59 +0000] "GET /.aws/credentials HTTP/1.1" 403 0 "-" "anthropic-ai" 406 0.003 [default-cv-service-80] [] 10.244.14.156:3000 0 0.003
...
show less
|
Web App Attack
|
|
๐บ๐ธ
34.26.196.83
|
|
34.26.196.83 - - [11/Aug/2026:21:16:08 +0000] "GET /.env.example HTTP/1.1" 200 2109 "-" "anthropic-a ...
show more
34.26.196.83 - - [11/Aug/2026:21:16:08 +0000] "GET /.env.example HTTP/1.1" 200 2109 "-" "anthropic-ai" 403 0.022 [default-open-webui-8080] [] 10.244.10.183:8080 2109 0.022 200 d79771336be14ae12343cf07961a3ada
34.26.196.83 - - [11/Aug/2026:21:16:09 +0000] "GET /backend/.env HTTP/1.1" 200 2109 "-" "anthropic-ai" 403 0.009 [default-open-webui-8080] [] 10.244.10.183:8080 2109 0.009 200 101a4c1891e94f0fde966c7278e15d6e
34.26.196.83 - - [11/Aug/2026:21:16:09 +0000] "GET /secrets.json HTTP/1.1" 200 2109 "-" "anthropic-ai" 403 0.009 [default-open-webui-8080] [] 10.244.10.183:8080 2109 0.009 200 ae2313dc65f07349336f41f12460d4b7
34.26.196.83 - - [11/Aug/2026:21:16:09 +0000] "GET /.github/.env HTTP/1.1" 200 2109 "-" "anthropic-ai" 403 0.005 [default-open-webui-8080] [] 10.244.10.183:8080 2109 0.005 200 38bb77c798427f7139cc936f21bf67f5
34.26.196.83 - - [11/Aug/2026:21:16:09 +0000] "GET /.svn/entries HTTP/1.1" 200 2109 "-" "anthropic-ai" 403 0.005 [default-open-webui-8080] [] 10.244.10.183:8080 210
...
show less
|
Web App Attack
|
|
๐บ๐ธ
34.26.196.83
|
|
34.26.196.83 - - [11/Aug/2026:21:16:06 +0000] "GET /.gitconfig HTTP/1.1" 200 2109 "-" "anthropic-ai" ...
show more
34.26.196.83 - - [11/Aug/2026:21:16:06 +0000] "GET /.gitconfig HTTP/1.1" 200 2109 "-" "anthropic-ai" 401 0.010 [default-open-webui-8080] [] 10.244.10.183:8080 2109 0.009 200 e84d1f07fb0a606c18dca754a965001d
34.26.196.83 - - [11/Aug/2026:21:16:08 +0000] "GET /.env.local HTTP/1.1" 200 2109 "-" "anthropic-ai" 401 0.011 [default-open-webui-8080] [] 10.244.10.183:8080 2109 0.012 200 ddaae746da52d42834404962b75a4e37
34.26.196.83 - - [11/Aug/2026:21:16:08 +0000] "GET /admin/.env HTTP/1.1" 200 2109 "-" "anthropic-ai" 401 0.005 [default-open-webui-8080] [] 10.244.10.183:8080 2109 0.005 200 0f470e4ce34465e2680c847b29ee2120
...
show less
|
Brute-Force
|
|
๐บ๐ธ
74.7.243.194
|
|
74.7.243.194 - - [11/Aug/2026:19:12:03 +0000] "GET /privacy HTTP/1.1" 403 0 "https://www.gregorymari ...
show more
74.7.243.194 - - [11/Aug/2026:19:12:03 +0000] "GET /privacy HTTP/1.1" 403 0 "https://www.gregorymariani.com/" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; GPTBot/1.4; +https://openai.com/gptbot)" 590 0.000 [default-cv-service-80] [] 10.244.14.157:3000 0 0.001 403 46be373bd28e4eb41be87e84792b2d2d
74.7.243.194 - - [11/Aug/2026:19:12:06 +0000] "GET /_astro/ai-probe.BmB9qCIB.css HTTP/1.1" 403 0 "https://www.gregorymariani.com/" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; GPTBot/1.4; +https://openai.com/gptbot)" 611 0.001 [default-cv-service-80] [] 10.244.14.156:3000 0 0.000 403 867b7f18f5024e75ba4d9e492e4c80ff
74.7.243.194 - - [11/Aug/2026:19:12:09 +0000] "GET /CV-dev.pdf HTTP/1.1" 403 0 "https://www.gregorymariani.com/" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; GPTBot/1.4; +https://openai.com/gptbot)" 593 0.000 [default-cv-service-80] [] 10.244.14.157:3000 0 0.001 403 e91306d1686bab5c11ed8054564d0cf6
74.7.243.194 - - [11/Aug/202
...
show less
|
Web App Attack
|
|
๐ธ๐ฌ
34.126.80.180
|
|
34.126.80.180 - - [11/Aug/2026:17:26:59 +0000] "GET /.env HTTP/1.1" 403 0 "-" "Mozilla/5.0 (compatib ...
show more
34.126.80.180 - - [11/Aug/2026:17:26:59 +0000] "GET /.env HTTP/1.1" 403 0 "-" "Mozilla/5.0 (compatible; OAI-SearchBot/1.3; +https://openai.com/searchbot)" 549 0.001 [default-cv-service-80] [] 10.244.14.156:3000 0 0.000 403 66227226f8c6faec79a77bbd082b6866
34.126.80.180 - - [11/Aug/2026:17:26:59 +0000] "GET /.env.staging HTTP/1.1" 403 0 "-" "Mozilla/5.0 (compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot)" 571 0.001 [default-cv-service-80] [] 10.244.14.157:3000 0 0.001 403 def5de5025cabe59a91b5d0856549b95
34.126.80.180 - - [11/Aug/2026:17:26:59 +0000] "GET /.env.local HTTP/1.1" 403 0 "-" "Mozilla/5.0 (compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot)" 562 0.003 [default-cv-service-80] [] 10.244.14.157:3000 0 0.002 403 f95ba7c040ccc98585851b8071b6c558
34.126.80.180 - - [11/Aug/2026:17:26:59 +0000] "GET /.env.development HTTP/1.1" 403 0 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot"
...
show less
|
Web App Attack
|
|
๐ธ๐ฌ
34.126.80.180
|
|
34.126.80.180 - - [11/Aug/2026:17:26:52 +0000] "GET /@fs/.env.staging?raw?? HTTP/1.1" 403 0 "-" "Moz ...
show more
34.126.80.180 - - [11/Aug/2026:17:26:52 +0000] "GET /@fs/.env.staging?raw?? HTTP/1.1" 403 0 "-" "Mozilla/5.0 (compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot)" 581 0.001 [default-cv-service-80] [] 10.244.14.157:3000 0 0.001 403 05127a25f9739bbccd283b42cd629eae
34.126.80.180 - - [11/Aug/2026:17:26:52 +0000] "GET /@fs/root/.env?raw?? HTTP/1.1" 403 0 "-" "Mozilla/5.0 (compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot)" 571 0.001 [default-cv-service-80] [] 10.244.14.156:3000 0 0.001 403 cb0d23fd5bba958993d89875e78d3f46
34.126.80.180 - - [11/Aug/2026:17:26:52 +0000] "GET /@fs/../.env?raw?? HTTP/1.1" 403 0 "-" "Mozilla/5.0 (compatible; Amzn-SearchBot/1.0; +https://developer.amazon.com/support/amazonbot)" 581 0.001 [default-cv-service-80] [] 10.244.14.157:3000 0 0.001 403 284667504fa936669ab6c4a8d5c6650f
34.126.80.180 - - [11/Aug/2026:17:26:52 +0000] "GET /@fs/root/.aws/credentials.bak?raw?? HTTP/1.1" 403 0 "-" "Mozilla/5.0 (compatible; Amzn-Search
...
show less
|
Web App Attack
|
|
๐ธ๐ช
20.91.239.158
|
|
2026-08-10 03:25:58,002 fail2ban.actions [982]: NOTICE [k8s-nginx-404] Ban 20.91.239.158
202 ...
show more
2026-08-10 03:25:58,002 fail2ban.actions [982]: NOTICE [k8s-nginx-404] Ban 20.91.239.158
2026-08-10 19:53:27,783 fail2ban.actions [982]: NOTICE [k8s-nginx-404] Ban 20.91.239.158
2026-08-11 04:15:43,997 fail2ban.actions [982]: NOTICE [k8s-nginx-404] Ban 20.91.239.158
...
show less
|
Exploited Host
|
|
๐ธ๐ช
20.91.239.158
|
|
20.91.239.158 - - [11/Aug/2026:14:15:40 +0000] "GET /wp-content/plugins/hellopress/wp_filemanager.ph ...
show more
20.91.239.158 - - [11/Aug/2026:14:15:40 +0000] "GET /wp-content/plugins/hellopress/wp_filemanager.php HTTP/1.1" 404 179 "-" "-" 393 0.007 [default-shop-oscar-amartyne-8080] [] 10.244.10.190:8080 179 0.008 404 d4d6732a2a5d3ed1377c062153e4d0ea
20.91.239.158 - - [11/Aug/2026:14:15:43 +0000] "GET /admin.php HTTP/1.1" 404 179 "-" "-" 354 0.008 [default-shop-oscar-amartyne-8080] [] 10.244.10.190:8080 179 0.009 404 ea5372fa29faaf7aeaa8e2b91282ff90
20.91.239.158 - - [11/Aug/2026:14:15:43 +0000] "GET /admin.php HTTP/1.1" 404 179 "-" "-" 354 0.008 [default-shop-oscar-amartyne-8080] [] 10.244.10.190:8080 179 0.009 404 ea5372fa29faaf7aeaa8e2b91282ff90
...
show less
|
Web App Attack
|
|
๐ณ๐ฑ
45.148.10.194
|
|
45.148.10.194 - - [11/Aug/2026:12:37:14 +0000] "GET /wp-json/ HTTP/1.1" 404 12182 "-" "Mozilla/5.0 ( ...
show more
45.148.10.194 - - [11/Aug/2026:12:37:14 +0000] "GET /wp-json/ HTTP/1.1" 404 12182 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.2 Safari/605.1.15" 532 0.002 [default-cv-service-80] [] 10.244.14.157:3000 12182 0.001 404 927e266631f0822d86c2a7878a47ad38
45.148.10.194 - - [11/Aug/2026:12:37:15 +0000] "GET /wp-json/ HTTP/1.1" 404 179 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" 526 0.013 [default-shop-oscar-amartyne-8080] [] 10.244.10.190:8080 179 0.013 404 4cae5ded1dcda67b939fde5abdd8a960
45.148.10.194 - - [11/Aug/2026:12:37:15 +0000] "GET /wp-login.php HTTP/1.1" 404 12182 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.2 Safari/605.1.15" 536 0.001 [default-cv-service-80] [] 10.244.14.156:3000 12182 0.001 404 0974b2692a1ec3ca5218a287cb025b22
45.148.10.194 - - [11/Aug/2026:12:37:18 +0000] "GET /wp-
...
show less
|
Web App Attack
|
|
๐ณ๐ฑ
195.178.110.211
|
|
195.178.110.211 - - [11/Aug/2026:13:36:49 +0000] "GET /wp-json/gravitysmtp/v1/tests/mock-data?page=g ...
show more
195.178.110.211 - - [11/Aug/2026:13:36:49 +0000] "GET /wp-json/gravitysmtp/v1/tests/mock-data?page=gravitysmtp-settings HTTP/1.1" 404 4036 "http://www.techdata.solutions/wp-json/gravitysmtp/v1/tests/mock-data?page=gravitysmtp-settings" "Mozilla/5.0 (compatible; SecurityResearch/1.0; )" 590 0.004 [default-techdata-service-80] [] 10.244.10.184:3000 4036 0.004 404 ef6ba2f0f4759a89105070b09cff9d34
...
show less
|
Web App Attack
|
|
๐ณ๐ด
20.100.191.218
|
|
20.100.191.218 - - [11/Aug/2026:00:12:55 +0000] "GET /wp-content/plugins/hellopress/wp_filemanager.p ...
show more
20.100.191.218 - - [11/Aug/2026:00:12:55 +0000] "GET /wp-content/plugins/hellopress/wp_filemanager.php HTTP/1.1" 404 179 "-" "-" 395 0.010 [default-shop-oscar-amartyne-8080] [] 10.244.10.190:8080 179 0.010 404 0df01635651e45611400ce5370f38ee3
20.100.191.218 - - [11/Aug/2026:00:12:58 +0000] "GET /admin.php HTTP/1.1" 404 179 "-" "-" 356 0.018 [default-shop-oscar-amartyne-8080] [] 10.244.10.190:8080 179 0.019 404 7021449d2eabf7cc7d9e1586be8434a0
20.100.191.218 - - [11/Aug/2026:00:13:26 +0000] "GET //wp-includes/js/jquery/ HTTP/1.1" 404 179 "-" "-" 370 0.011 [default-shop-oscar-amartyne-8080] [] 10.244.10.190:8080 179 0.011 404 bc769c5a8bf550729a9fb6cd2739a345
20.100.191.218 - - [11/Aug/2026:13:28:45 +0000] "GET /wp-content/plugins/hellopress/wp_filemanager.php HTTP/1.1" 404 4036 "-" "-" 405 0.003 [default-techdata-service-80] [] 10.244.10.184:3000 4036 0.004 404 5fe6850fd01ae0460bf522ffbdd7d4b8
20.100.191.218 - - [11/Aug/2026:13:28:49 +0000] "GET /admin.php HTTP/1.1" 404 4036 "-" "-" 366
...
show less
|
Web App Attack
|
|
๐ฎ๐น
4.232.185.206
|
|
4.232.185.206 - - [11/Aug/2026:05:59:48 +0000] "GET /wp-content/plugins/hellopress/wp_filemanager.ph ...
show more
4.232.185.206 - - [11/Aug/2026:05:59:48 +0000] "GET /wp-content/plugins/hellopress/wp_filemanager.php HTTP/1.1" 404 12182 "-" "-" 399 0.001 [default-cv-service-80] [] 10.244.14.157:3000 12182 0.001 404 672ebcf3a9c208f55c16888784418995
4.232.185.206 - - [11/Aug/2026:05:59:49 +0000] "GET /admin.php HTTP/1.1" 404 12182 "-" "-" 360 0.001 [default-cv-service-80] [] 10.244.14.157:3000 12182 0.001 404 bc1551c29acf3c9dba542dbc5f44399a
4.232.185.206 - - [11/Aug/2026:05:59:49 +0000] "GET /admin.php HTTP/1.1" 404 12182 "-" "-" 360 0.001 [default-cv-service-80] [] 10.244.14.157:3000 12182 0.001 404 bc1551c29acf3c9dba542dbc5f44399a
4.232.185.206 - - [11/Aug/2026:05:59:50 +0000] "GET /wp-includes/block-supports/ HTTP/1.1" 404 12182 "-" "-" 378 0.001 [default-cv-service-80] [] 10.244.14.156:3000 12182 0.001 404 4bfe9173527b348dedcce4825d04da66
...
show less
|
Web App Attack
|
|
๐ธ๐ช
20.91.239.158
|
|
20.91.239.158 - - [11/Aug/2026:05:52:56 +0000] "GET /wp-content/plugins/hellopress/wp_filemanager.ph ...
show more
20.91.239.158 - - [11/Aug/2026:05:52:56 +0000] "GET /wp-content/plugins/hellopress/wp_filemanager.php HTTP/1.1" 404 4036 "-" "-" 399 0.003 [default-techdata-service-80] [] 10.244.10.184:3000 4036 0.003 404 c8d64f348ca901e90846824d4d85dcdc
20.91.239.158 - - [11/Aug/2026:05:53:00 +0000] "GET /admin.php HTTP/1.1" 404 4036 "-" "-" 360 0.005 [default-techdata-service-80] [] 10.244.10.184:3000 4036 0.004 404 f957864bac9c751199b1c4d75ff651e0
20.91.239.158 - - [11/Aug/2026:05:53:00 +0000] "GET /admin.php HTTP/1.1" 404 4036 "-" "-" 360 0.005 [default-techdata-service-80] [] 10.244.10.184:3000 4036 0.004 404 f957864bac9c751199b1c4d75ff651e0
20.91.239.158 - - [11/Aug/2026:05:53:27 +0000] "GET /wp-includes/js/jquery HTTP/1.1" 404 4036 "-" "-" 372 0.002 [default-techdata-service-80] [] 10.244.10.184:3000 4036 0.003 404 686aa9bb0b5e9f9e220e63a322a0e3ca
...
show less
|
Web App Attack
|