๐ฉ๐ช
updown.io
2026-08-23 23:09:29
(37 minutes ago)
{"level":"info","ts":1787526567.8507216,"logger":"http.log.access.log1","msg":"handled request","req ...
show more
{"level":"info","ts":1787526567.8507216,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"34.26.205.99","remote_port":"37848","client_ip":"34.26.205.99","proto":"HTTP/2.0","method":"GET","host":"status.wowmedia.net","uri":"/manifest.json","headers":{"User-Agent":["Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Mobile Safari/537.36 EdgA/149.0.0.0"],"Sec-Ch-Ua":["\"Microsoft Edge\";v=\"149\", \"Chromium\";v=\"149\", \"Not)A;Brand\";v=\"24\""],"Sec-Fetch-Mode":["navigate"],"Sec-Ch-Ua-Platform":["\"Android\""],"Accept-Encoding":["gzip, deflate, br, zstd"],"Upgrade-Insecure-Requests":["1"],"Sec-Fetch-Dest":["document"],"Sec-Fetch-Site":["none"],"Priority":["u=0, i"],"Accept":["text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8"],"Sec-Ch-Ua-Mobile":["?1"],"Accept-Language":["en-US,en;q=0.9"],"Sec-Fetch-User":["?1"]},"tls":{"resumed":false,"version":772,"cipher_suite":4865,"proto":"h2"
...
show less
DDoS Attack
Web App Attack
๐ซ๐ฎ
paissangroup
2026-08-23 23:06:56
(40 minutes ago)
Multiple WAF Violations
Web App Attack
๐ฉ๐ฐ
ScamAware
2026-08-23 22:30:34
(1 hour ago)
Detected by Cloudflare Security Events via WordPress automation. Detection: sensitive_files (Sensiti ...
show more
Detected by Cloudflare Security Events via WordPress automation. Detection: sensitive_files (Sensitive files, source control, config, and backups). Hits from same IP in last 60 minutes: 5. Unique request paths counted internally: 5. Cloudflare action: block. Cloudflare source: firewallCustom.
show less
Web App Attack
๐ท๐ด
clauss
2026-08-23 21:56:49
(1 hour ago)
34.26.205.99 - - [24/Aug/2026:00:56:48 +0300] "GET /.docker/config.json HTTP/2.0" 404 201 "-" "Mozil ...
show more
34.26.205.99 - - [24/Aug/2026:00:56:48 +0300] "GET /.docker/config.json HTTP/2.0" 404 201 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot"
34.26.205.99 - - [24/Aug/2026:00:56:48 +0300] "GET /.vscode/launch.json HTTP/2.0" 404 201 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot"
...
show less
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-08-23 19:05:48
(4 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐ต๐ฑ
Budyn
2026-08-23 18:11:46
(5 hours ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: status.budyn.ovh | URI: /.aws/credentials | UA: CCBot/2.0 (https://commoncrawl.org/faq/) | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
jormaster3k
2026-08-23 16:41:20
(7 hours ago)
Attack against Apache (too many 404s)
Web App Attack
๐ต๐ฑ
Budyn
2026-08-23 10:14:33
(13 hours ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: metrics.budyn.ovh | URI: /.aws/credentials | UA: CCBot/2.0 (https://commoncrawl.org/faq/) | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
๐ฌ๐ง
openstrike.co.uk
2026-08-23 05:14:52
(18 hours ago)
71 attacks on config grabbing URLs (type 2), env grabbing URLs, PHP URLs, VC URLs, password grabbing ...
show more
71 attacks on config grabbing URLs (type 2), env grabbing URLs, PHP URLs, VC URLs, password grabbing URLs:
GET /src/amplifyconfiguration.json HTTP/1.1
GET /app/.env HTTP/1.1
GET /app_dev.php/_profiler HTTP/1.1
GET /.git/HEAD HTTP/1.1
GET /.aws/credentials HTTP/1.1
show less
Hacking
Web App Attack
๐ง๐ท
Peregrine
2026-08-23 03:12:17
(20 hours ago)
Fail2Ban Jail s2: tomcat-honeypot | Evidence: 34.26.205.99 108.162.238.19 - - [21/Aug/2026:15:31:37 ...
show more
Fail2Ban Jail s2: tomcat-honeypot | Evidence: 34.26.205.99 108.162.238.19 - - [21/Aug/2026:15:31:37 -0300] "GET /.git/config HTTP/1.1" 404 414
34.26.205.99 108.162.238.19 - - [21/Aug/2026:15:31:37 -0300] "GET /.env.local HTTP/1.1" 404 414
34.26.205.99 108.162.238.19 - - [21/Aug/2026:15:31:37 -0300] "GET /.aws/credentials HTTP/1.1" 404 414
34.26.205.99 108.162.238.19 - - [21/Aug/2026:15:31:37 -0300] "GET /.aws/config HTTP/1.1" 404 414
34.26.205.99 108.162.238.19 - - [21/Aug/2026:15:31:37 -0300] "GET /.env.backup HTTP/1.1" 404 414
34.26.205.99 108.162.238.20 - - [21/Aug/2026:15:31:38 -0300] "GET /.env.bak HTTP/1.1" 404 414
34.26.205.99 108.162.238.19 - - [21/Aug/2026:15:31:38 -0300] "GET /.git/HEAD HTTP/1.1" 404 414
34.26.205.99 108.162.238.19 - - [21/Aug/2026:15:31:38 -0300] "GET /.git-credentials HTTP/1.1" 404 414
34.26.205.99 108.162.238.19 - - [21/Aug/2026:15:31:38 -0300] "GET /.env.old HTTP/1.1" 404 414
show less
Bad Web Bot
๐ต๐ฑ
Budyn
2026-08-23 02:30:39
(21 hours ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: test.budyn.ovh | URI: /.git/config | UA: CCBot/2.0 (https://commoncrawl.org/faq/) | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
๐ต๐ฑ
sefinek.net
2026-08-23 01:36:44
(22 hours ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action: BLOCK | Protocol: HTTP/2 (GET) | Endpoint ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action: BLOCK | Protocol: HTTP/2 (GET) | Endpoint: /dev/.env | UA: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; OAI-SearchBot/1.0; +https://openai.com/searchbot โข Generated by: github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ฌ๐ง
andypiper
2026-08-23 01:02:59
(22 hours ago)
CrowdSec ban for AbuseIPDB Top List
Brute-Force
Web App Attack
Anonymous
2026-08-23 00:48:32
(22 hours ago)
Portscan: TCP/8443 (8x), TCP/8080 (10x)
Port Scan
๐ซ๐ท
mail.avx.gr
2026-08-23 00:10:08
(23 hours ago)
Plesk Fail2Ban jail: Plesk-Web-Exploits. Evidence: default-10-0-0-4:443 34.26.205.99 - - [21/Aug/202 ...
show more
Plesk Fail2Ban jail: Plesk-Web-Exploits. Evidence: default-10-0-0-4:443 34.26.205.99 - - [21/Aug/2026:01:19:52 +0300] "GET /.aws/credentials HTTP/1.1" 404 2428 "-" "Mozilla/5.0 (compatible; DeepSeekBot/1.0; +https://www.deepseek.com/bot)"
show less
Web App Attack