π©πͺ
185.84.159.31
15 Aug 2026
Fail2Ban automatic report:
SSH brute-force:
Aug 15 10:22:37 serw sshd[483486]: Invalid user promethe ...
show more
Fail2Ban automatic report:
SSH brute-force:
Aug 15 10:22:37 serw sshd[483486]: Invalid user prometheus from 185.84.159.31 port 35854
Aug 15 10:22:37 serw sshd[483486]: Disconnected from invalid user prometheus 185.84.159.31 port 35854 [preauth]
Aug 15 10:25:12 serw sshd[483556]: Invalid user system from 185.84.159.31 port 60312
show less
Brute-Force
SSH
π¨π³
106.13.107.71
15 Aug 2026
Fail2Ban automatic report:
SSH multiple root login attempts:
Aug 15 10:10:50 serw sshd[483367]: Conn ...
show more
Fail2Ban automatic report:
SSH multiple root login attempts:
Aug 15 10:10:50 serw sshd[483367]: Connection closed by authenticating user root 106.13.107.71 port 40488 [preauth]
show less
Brute-Force
SSH
π§πͺ
34.156.98.72
15 Aug 2026
Fail2Ban automatic report:
Multiple forbidden requests in short amount of time:
34.156.98.72 - - [15 ...
show more
Fail2Ban automatic report:
Multiple forbidden requests in short amount of time:
34.156.98.72 - - [15/Aug/2026:09:52:07 +0200] "GET / HTTP/2.0" 403 555 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Safari/537.36" "-"
34.156.98.72 - - [15/Aug/2026:09:52:07 +0200] "GET /user/login HTTP/2.0" 403 555 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Safari/537.36" "-"
34.156.98.72 - - [15/Aug/2026:09:52:07 +0200] "GET /portal HTTP/2.0" 403 555 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Safari/537.36" "-"
34.156.98.72 - - [15/Aug/2026:09:52:07 +0200] "GET /manage HTTP/2.0" 403 555 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150
show less
Hacking
Web App Attack
πΊπΈ
34.74.118.2
15 Aug 2026
Fail2Ban automatic report:
Multiple forbidden requests in short amount of time:
34.74.118.2 - - [15/ ...
show more
Fail2Ban automatic report:
Multiple forbidden requests in short amount of time:
34.74.118.2 - - [15/Aug/2026:08:34:23 +0200] "GET / HTTP/2.0" 403 555 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Safari/537.36" "-"
34.74.118.2 - - [15/Aug/2026:08:34:24 +0200] "GET /settings.json HTTP/2.0" 403 153 "-" "Mozilla/5.0 (compatible; Amzn-SearchBot/1.0; +https://developer.amazon.com/support/amazonbot)" "-"
34.74.118.2 - - [15/Aug/2026:08:34:24 +0200] "GET /dashboard HTTP/2.0" 403 555 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Safari/537.36" "-"
34.74.118.2 - - [15/Aug/2026:08:34:24 +0200] "GET /env.js HTTP/2.0" 403 153 "-" "Mozilla/5.0 (compatible; Amzn-SearchBot/1.0; +https://developer.amazon.com/support/amazonbot)" "-"
34.74.11
show less
Hacking
Web App Attack
π§πͺ
34.38.185.57
15 Aug 2026
Fail2Ban automatic report:
SSH suspicious user names:
Aug 15 08:07:19 serw sshd[481636]: Connection ...
show more
Fail2Ban automatic report:
SSH suspicious user names:
Aug 15 08:07:19 serw sshd[481636]: Connection closed by invalid user admin 34.38.185.57 port 15436 [preauth]
show less
Brute-Force
SSH
π³π±
93.123.109.234
15 Aug 2026
Fail2Ban automatic report:
Multiple forbidden requests in short amount of time:
93.123.109.234 - - [ ...
show more
Fail2Ban automatic report:
Multiple forbidden requests in short amount of time:
93.123.109.234 - - [15/Aug/2026:07:53:52 +0200] "GET / HTTP/1.1" 403 153 "-" "l9tcpid/v1.1.0" "-"
93.123.109.234 - - [15/Aug/2026:07:53:52 +0200] "GET /.env.backup HTTP/1.1" 403 153 "-" "l9explore/1.2.2" "-"
93.123.109.234 - - [15/Aug/2026:07:53:52 +0200] "GET /.git/config HTTP/1.1" 403 153 "-" "l9explore/1.2.2" "-"
93.123.109.234 - - [15/Aug/2026:07:53:52 +0200] "GET /.git-credentials HTTP/1.1" 403 153 "-" "l9explore/1.2.2" "-"
93.123.109.234 - - [15/Aug/2026:07:53:52 +0200] "GET /.git/HEAD HTTP/1.1" 403 153 "-" "l9explore/1.2.2" "-"
93.123.109.234 - - [15/Aug/2026:07:53:52 +0200] "GET /.npmrc HTTP/1.1" 403 153 "-" "l9explore/1.2.2" "-"
93.123.109.234 - - [15/Aug/2026:07:53:52 +0200] "GET /.env.local HTTP/1.1" 403 153 "-" "l9explore/1.2.2" "-"
93.123.109.23
show less
Hacking
Web App Attack
πΊπΈ
104.28.153.120
15 Aug 2026
Fail2Ban automatic report:
SSH brute-force:
Aug 15 07:29:27 serw sshd[481174]: Invalid user super fr ...
show more
Fail2Ban automatic report:
SSH brute-force:
Aug 15 07:29:27 serw sshd[481174]: Invalid user super from 104.28.153.120 port 63196
Aug 15 07:29:27 serw sshd[481174]: Disconnected from invalid user super 104.28.153.120 port 63196 [preauth]
Aug 15 07:34:36 serw sshd[481208]: Disconnected from authenticating user root 104.28.153.120 port 63229 [preauth]
show less
Brute-Force
SSH
πΊπΈ
104.28.214.112
15 Aug 2026
Fail2Ban automatic report:
SSH brute-force:
Aug 15 07:15:12 serw sshd[480978]: Disconnected from aut ...
show more
Fail2Ban automatic report:
SSH brute-force:
Aug 15 07:15:12 serw sshd[480978]: Disconnected from authenticating user root 104.28.214.112 port 26057 [preauth]
Aug 15 07:21:37 serw sshd[481065]: Disconnected from authenticating user root 104.28.214.112 port 26018 [preauth]
Aug 15 07:24:14 serw sshd[481100]: Disconnected from authenticating user root 104.28.214.112 port 25866 [preauth]
show less
Brute-Force
SSH
π²π½
68.155.155.23
15 Aug 2026
Fail2Ban automatic report:
Multiple forbidden requests in short amount of time:
68.155.155.23 - - [1 ...
show more
Fail2Ban automatic report:
Multiple forbidden requests in short amount of time:
68.155.155.23 - - [15/Aug/2026:04:36:59 +0200] "GET /wp-content/plugins/hellopress/wp_filemanager.php HTTP/1.1" 403 153 "-" "-" "-"
68.155.155.23 - - [15/Aug/2026:04:37:00 +0200] "GET /this_is_a_new_hello_world.php HTTP/1.1" 403 153 "-" "-" "-"
68.155.155.23 - - [15/Aug/2026:04:37:00 +0200] "GET /admin.php HTTP/1.1" 403 153 "-" "-" "-"
68.155.155.23 - - [15/Aug/2026:04:37:00 +0200] "GET /public/css.php HTTP/1.1" 403 153 "-" "-" "-"
68.155.155.23 - - [15/Aug/2026:04:37:00 +0200] "GET /classwithtostring.php HTTP/1.1" 403 153 "-" "-" "-"
68.155.155.23 - - [15/Aug/2026:04:37:00 +0200] "GET /wp-includes/block-supports/ HTTP/1.1" 403 153 "-" "-" "-"
68.155.155.23 - - [15/Aug/2026:04:37:00 +0200] "GET /wp-content/admin.php HTTP/1.1" 403 153 "-" "-" "-"
68.155.155.2
show less
Hacking
Web App Attack
πΈπ¬
103.224.165.190
15 Aug 2026
Fail2Ban automatic report:
SSH suspicious user names:
Aug 15 02:48:30 serw sshd[477898]: Connection ...
show more
Fail2Ban automatic report:
SSH suspicious user names:
Aug 15 02:48:30 serw sshd[477898]: Connection closed by invalid user admin 103.224.165.190 port 7052 [preauth]
show less
Brute-Force
SSH
π»π³
116.110.220.29
15 Aug 2026
Fail2Ban automatic report:
SSH multiple root login attempts:
Aug 15 02:32:59 serw sshd[477676]: Conn ...
show more
Fail2Ban automatic report:
SSH multiple root login attempts:
Aug 15 02:32:59 serw sshd[477676]: Connection closed by authenticating user root 116.110.220.29 port 45826 [preauth]
show less
Brute-Force
SSH
π»π³
116.99.174.196
15 Aug 2026
Fail2Ban automatic report:
SSH brute-force:
Aug 15 02:26:45 serw sshd[477595]: Invalid user config f ...
show more
Fail2Ban automatic report:
SSH brute-force:
Aug 15 02:26:45 serw sshd[477595]: Invalid user config from 116.99.174.196 port 36312
Aug 15 02:26:46 serw sshd[477595]: Connection closed by invalid user config 116.99.174.196 port 36312 [preauth]
Aug 15 02:26:56 serw sshd[477603]: Invalid user installer from 116.99.174.196 port 38756
show less
Brute-Force
SSH
π»π³
116.110.216.80
15 Aug 2026
Fail2Ban automatic report:
SSH suspicious user names:
Aug 15 02:26:33 serw sshd[477552]: Connection ...
show more
Fail2Ban automatic report:
SSH suspicious user names:
Aug 15 02:26:33 serw sshd[477552]: Connection closed by invalid user admin 116.110.216.80 port 34518 [preauth]
show less
Brute-Force
SSH
π»π³
103.179.174.112
15 Aug 2026
Fail2Ban automatic report:
SSH brute-force:
Aug 15 02:02:49 serw sshd[477148]: Invalid user erpnext ...
show more
Fail2Ban automatic report:
SSH brute-force:
Aug 15 02:02:49 serw sshd[477148]: Invalid user erpnext from 103.179.174.112 port 50288
Aug 15 02:02:49 serw sshd[477148]: Disconnected from invalid user erpnext 103.179.174.112 port 50288 [preauth]
Aug 15 02:05:41 serw sshd[477216]: Invalid user vicente from 103.179.174.112 port 46360
show less
Brute-Force
SSH
π§πͺ
34.156.42.206
14 Aug 2026
Fail2Ban automatic report:
Multiple forbidden requests in short amount of time:
34.156.42.206 - - [1 ...
show more
Fail2Ban automatic report:
Multiple forbidden requests in short amount of time:
34.156.42.206 - - [15/Aug/2026:01:31:18 +0200] "GET / HTTP/2.0" 403 555 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Safari/537.36" "-"
34.156.42.206 - - [15/Aug/2026:01:31:18 +0200] "GET /z9x8c7v6b5-debug-trigger-www.swisz.cz HTTP/2.0" 403 153 "-" "Mozilla/5.0 (compatible; Amzn-SearchBot/1.0; +https://developer.amazon.com/support/amazonbot)" "-"
34.156.42.206 - - [15/Aug/2026:01:31:18 +0200] "GET /.github/.env HTTP/2.0" 403 153 "-" "Mozilla/5.0 (compatible; Amzn-SearchBot/1.0; +https://developer.amazon.com/support/amazonbot)" "-"
34.156.42.206 - - [15/Aug/2026:01:31:18 +0200] "GET /firebase-service-account.json HTTP/2.0" 403 153 "-" "Mozilla/5.0 (compatible; Amzn-SearchBot/1.0; +https://developer.ama
show less
Hacking
Web App Attack
π»π³
160.30.157.214
14 Aug 2026
Fail2Ban automatic report:
Multiple forbidden requests in short amount of time:
160.30.157.214 - - [ ...
show more
Fail2Ban automatic report:
Multiple forbidden requests in short amount of time:
160.30.157.214 - - [15/Aug/2026:00:42:26 +0200] "POST /hello.world?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input HTTP/1.1" 403 153 "-" "libredtail-http" "-"
160.30.157.214 - - [15/Aug/2026:00:42:26 +0200] "POST /?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input HTTP/1.1" 403 153 "-" "libredtail-http" "-"
160.30.157.214 - - [15/Aug/2026:00:42:27 +0200] "POST /index.php?%25ADd+allow_url_include%3D1+%25ADd+auto_prepend_file%3Dphp://input HTTP/1.1" 403 153 "-" "libredtail-http" "-"
160.30.157.214 - - [15/Aug/2026:00:42:27 +0200] "POST /test.hello?%25ADd+allow_url_include%3D1+%25ADd+auto_prepend_file%3Dphp://input HTTP/1.1" 403 153 "-" "libredtail-http" "-"
160.30.157.214 - - [15/Aug/2026:00:42:28 +0200] "POST /index.php?-d+allow_
show less
Hacking
Web App Attack
π¨π¦
4.204.200.143
14 Aug 2026
Fail2Ban automatic report:
Multiple forbidden requests in short amount of time:
4.204.200.143 - - [1 ...
show more
Fail2Ban automatic report:
Multiple forbidden requests in short amount of time:
4.204.200.143 - - [14/Aug/2026:23:48:18 +0200] "GET /wp-content/plugins/hellopress/wp_filemanager.php HTTP/1.1" 403 153 "-" "-" "-"
4.204.200.143 - - [14/Aug/2026:23:48:18 +0200] "GET /this_is_a_new_hello_world.php HTTP/1.1" 403 153 "-" "-" "-"
4.204.200.143 - - [14/Aug/2026:23:48:18 +0200] "GET /class.php HTTP/1.1" 403 153 "-" "-" "-"
4.204.200.143 - - [14/Aug/2026:23:48:18 +0200] "GET /lm13.php HTTP/1.1" 403 153 "-" "-" "-"
4.204.200.143 - - [14/Aug/2026:23:48:18 +0200] "GET /1aa.php HTTP/1.1" 403 153 "-" "-" "-"
4.204.200.143 - - [14/Aug/2026:23:48:18 +0200] "GET /menu.php HTTP/1.1" 403 153 "-" "-" "-"
4.204.200.143 - - [14/Aug/2026:23:48:19 +0200] "GET /mail.php HTTP/1.1" 403 153 "-" "-" "-"
4.204.200.143 - - [14/Aug/2026:23:48:19 +0200] "GET /v3.php HTT
show less
Hacking
Web App Attack
πΊπΈ
136.67.142.230
14 Aug 2026
Fail2Ban automatic report:
Multiple forbidden requests in short amount of time:
136.67.142.230 - - [ ...
show more
Fail2Ban automatic report:
Multiple forbidden requests in short amount of time:
136.67.142.230 - - [14/Aug/2026:23:27:14 +0200] "GET / HTTP/2.0" 403 555 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Safari/537.36" "-"
136.67.142.230 - - [14/Aug/2026:23:27:15 +0200] "GET /z9x8c7v6b5-debug-trigger-www.swisz.cz HTTP/2.0" 403 153 "-" "Mozilla/5.0 (compatible; Amzn-SearchBot/1.0; +https://developer.amazon.com/support/amazonbot)" "-"
136.67.142.230 - - [14/Aug/2026:23:27:15 +0200] "GET /secrets.yml HTTP/2.0" 403 153 "-" "Mozilla/5.0 (compatible; Amzn-SearchBot/1.0; +https://developer.amazon.com/support/amazonbot)" "-"
136.67.142.230 - - [14/Aug/2026:23:27:15 +0200] "GET /serviceAccountKey.json HTTP/2.0" 403 153 "-" "Mozilla/5.0 (compatible; Amzn-SearchBot/1.0; +https://developer.amazon.
show less
Hacking
Web App Attack
πΊπΈ
35.243.178.94
14 Aug 2026
Fail2Ban automatic report:
Multiple forbidden requests in short amount of time:
35.243.178.94 - - [1 ...
show more
Fail2Ban automatic report:
Multiple forbidden requests in short amount of time:
35.243.178.94 - - [14/Aug/2026:23:17:55 +0200] "GET / HTTP/2.0" 403 555 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Safari/537.36" "-"
35.243.178.94 - - [14/Aug/2026:23:17:55 +0200] "GET /z9x8c7v6b5-debug-trigger-www.swisz.cz HTTP/2.0" 403 153 "-" "Mozilla/5.0 (compatible; Amzn-SearchBot/1.0; +https://developer.amazon.com/support/amazonbot)" "-"
35.243.178.94 - - [14/Aug/2026:23:17:55 +0200] "GET /console HTTP/2.0" 403 555 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Safari/537.36" "-"
35.243.178.94 - - [14/Aug/2026:23:17:55 +0200] "GET /auth/login HTTP/2.0" 403 555 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like
show less
Hacking
Web App Attack
πΊπΈ
34.181.208.116
14 Aug 2026
Fail2Ban automatic report:
Multiple forbidden requests in short amount of time:
34.181.208.116 - - [ ...
show more
Fail2Ban automatic report:
Multiple forbidden requests in short amount of time:
34.181.208.116 - - [14/Aug/2026:23:07:43 +0200] "GET / HTTP/2.0" 403 555 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Safari/537.36" "-"
34.181.208.116 - - [14/Aug/2026:23:07:44 +0200] "GET /.bash_profile HTTP/2.0" 403 153 "-" "Mozilla/5.0 (compatible; Amzn-SearchBot/1.0; +https://developer.amazon.com/support/amazonbot)" "-"
34.181.208.116 - - [14/Aug/2026:23:07:44 +0200] "GET /.profile HTTP/2.0" 403 153 "-" "Mozilla/5.0 (compatible; Amzn-SearchBot/1.0; +https://developer.amazon.com/support/amazonbot)" "-"
34.181.208.116 - - [14/Aug/2026:23:07:44 +0200] "GET /admin/login HTTP/2.0" 403 555 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Safari/537.
show less
Hacking
Web App Attack
π³π±
45.142.193.164
14 Aug 2026
Fail2Ban automatic report:
SSH multiple root login attempts:
Aug 14 22:48:29 serw sshd[474688]: Conn ...
show more
Fail2Ban automatic report:
SSH multiple root login attempts:
Aug 14 22:48:29 serw sshd[474688]: Connection closed by authenticating user root 45.142.193.164 port 34954 [preauth]
show less
Brute-Force
SSH
π©πͺ
51.116.232.28
14 Aug 2026
Fail2Ban automatic report:
Multiple forbidden requests in short amount of time:
51.116.232.28 - - [1 ...
show more
Fail2Ban automatic report:
Multiple forbidden requests in short amount of time:
51.116.232.28 - - [14/Aug/2026:22:23:59 +0200] "GET /wp-content/plugins/hellopress/wp_filemanager.php HTTP/1.1" 403 153 "-" "-" "-"
51.116.232.28 - - [14/Aug/2026:22:23:59 +0200] "GET /this_is_a_new_hello_world.php HTTP/1.1" 403 153 "-" "-" "-"
51.116.232.28 - - [14/Aug/2026:22:23:59 +0200] "GET //aa.php HTTP/1.1" 403 153 "-" "-" "-"
51.116.232.28 - - [14/Aug/2026:22:23:59 +0200] "GET //av.php HTTP/1.1" 403 153 "-" "-" "-"
51.116.232.28 - - [14/Aug/2026:22:23:59 +0200] "GET /media.php HTTP/1.1" 403 153 "-" "-" "-"
51.116.232.28 - - [14/Aug/2026:22:23:59 +0200] "GET /images.php HTTP/1.1" 403 153 "-" "-" "-"
51.116.232.28 - - [14/Aug/2026:22:23:59 +0200] "GET /admin.php HTTP/1.1" 403 153 "-" "-" "-"
51.116.232.28 - - [14/Aug/2026:22:23:59 +0200] "GET /222.php
show less
Hacking
Web App Attack
πΊπΈ
136.65.207.248
14 Aug 2026
Fail2Ban automatic report:
Multiple forbidden requests in short amount of time:
136.65.207.248 - - [ ...
show more
Fail2Ban automatic report:
Multiple forbidden requests in short amount of time:
136.65.207.248 - - [14/Aug/2026:22:16:48 +0200] "GET / HTTP/2.0" 403 555 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Safari/537.36" "-"
136.65.207.248 - - [14/Aug/2026:22:16:48 +0200] "GET /login HTTP/2.0" 403 555 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Safari/537.36" "-"
136.65.207.248 - - [14/Aug/2026:22:16:48 +0200] "GET /admin HTTP/2.0" 403 555 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Safari/537.36" "-"
136.65.207.248 - - [14/Aug/2026:22:16:48 +0200] "GET /console HTTP/2.0" 403 555 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/
show less
Hacking
Web App Attack
π¨π³
49.67.146.4
14 Aug 2026
Fail2Ban automatic report:
SSH brute-force:
Aug 14 21:42:47 serw sshd[473886]: Invalid user admin fr ...
show more
Fail2Ban automatic report:
SSH brute-force:
Aug 14 21:42:47 serw sshd[473886]: Invalid user admin from 49.67.146.4 port 46026
Aug 14 21:42:47 serw sshd[473886]: Disconnected from invalid user admin 49.67.146.4 port 46026 [preauth]
Aug 14 21:51:26 serw sshd[473966]: Invalid user habib from 49.67.146.4 port 40552
show less
Brute-Force
SSH
π¨π¦
158.69.197.98
14 Aug 2026
Fail2Ban automatic report:
SSH multiple root login attempts:
Aug 14 21:09:36 serw sshd[473409]: Conn ...
show more
Fail2Ban automatic report:
SSH multiple root login attempts:
Aug 14 21:09:36 serw sshd[473409]: Connection closed by authenticating user root 158.69.197.98 port 47872 [preauth]
show less
Brute-Force
SSH