🇬🇧
andypiper
2026-08-23 01:01:47
(1 week ago)
CrowdSec ban for AbuseIPDB Top List
Brute-Force
Web App Attack
🇫🇷
mail.avx.gr
2026-08-23 00:12:39
(1 week ago)
Plesk Fail2Ban jail: Plesk-Web-Exploits. Evidence: 8.235.28.31 - - [17/Aug/2026:22:15:01 +0300] "GET ...
show more
Plesk Fail2Ban jail: Plesk-Web-Exploits. Evidence: 8.235.28.31 - - [17/Aug/2026:22:15:01 +0300] "GET /.git/config HTTP/2.0" 404 808 "-" "Mozilla/5.0 (compatible; Diffbot/1.0; +https://diffbot.com)"
show less
Web App Attack
🇬🇷
mail.avx.gr
2026-08-21 17:36:54
(2 weeks ago)
Plesk Fail2Ban jail: Plesk-Web-Exploits. Evidence: 8.235.28.31 - - [17/Aug/2026:22:15:01 +0300] "GET ...
show more
Plesk Fail2Ban jail: Plesk-Web-Exploits. Evidence: 8.235.28.31 - - [17/Aug/2026:22:15:01 +0300] "GET /.git/config HTTP/2.0" 404 808 "-" "Mozilla/5.0 (compatible; Diffbot/1.0; +https://diffbot.com)"
show less
Web App Attack
🇬🇧
openstrike.co.uk
2026-08-19 05:14:37
(2 weeks ago)
70 attacks on env grabbing URLs, config grabbing URLs (type 2), PHP URLs, password grabbing URLs, VC ...
show more
70 attacks on env grabbing URLs, config grabbing URLs (type 2), PHP URLs, password grabbing URLs, VC URLs:
GET /.env.development HTTP/1.1
GET /config/database.yml HTTP/1.1
GET /configuration.php.bak HTTP/1.1
GET /.aws/credentials HTTP/1.1
GET /.git/HEAD HTTP/1.1
show less
Hacking
Web App Attack
🇭🇺
DumaNet
2026-08-19 03:54:00
(2 weeks ago)
Web app attack attempts, scanning for vulnerability.
Date: 2026 Aug 18. 17:42:02
Source IP: 8.235. ...
show more
Web app attack attempts, scanning for vulnerability.
Date: 2026 Aug 18. 17:42:02
Source IP: 8.235.28.31
Portion of the log(s):
8.235.28.31 - [18/Aug/2026:17:42:02 +0200] "GET /.cursor/mcp.json HTTP/1.1" 404 153 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ClaudeBot/1.0; +mailto:[email protected] "
8.235.28.31 - [18/Aug/2026:17:42:02 +0200] "GET /.openclaw/openclaw.json HTTP/1.1" 404 153 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ClaudeBot/1.0; +mailto:[email protected] "
8.235.28.31 - [18/Aug/2026:17:42:02 +0200] "GET /.openclaw/.env HTTP/1.1" 404 153 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ClaudeBot/1.0; +mailto:[email protected] "
8.235.28.31 - [18/Aug/2026:17:42:02 +0200] "GET /ssl/localhost.key HTTP/1.1" 404 153 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ClaudeBot/1.0; +mailto:[email protected] "
8.235.28.31 - [18/Aug/2026:17:42:02 +0200] "GET /ssl/server.key HTTP/1.1" 404
show less
Web App Attack
🇳🇱
homeshowdomain.nl
2026-08-18 21:59:48
(2 weeks ago)
Auto-ban: >3000 req/min op 2026-08-18
Web App Attack
SSH
Hacking
🇺🇸
jormaster3k
2026-08-18 20:27:21
(2 weeks ago)
Attack against Apache (too many 404s)
Web App Attack
🇩🇪
paissangroup
2026-08-18 20:08:27
(2 weeks ago)
Multiple WAF Violations
Web App Attack
Anonymous
2026-08-18 18:36:09
(2 weeks ago)
Backdrop CMS module - malicious activity detected
Bad Web Bot
Web App Attack
🇷🇴
iulianh
2026-08-18 18:10:11
(2 weeks ago)
80,443
Brute-Force
SSH
🇪🇸
netfactotum
2026-08-18 17:15:46
(2 weeks ago)
Hacking
Web App Attack
🇳🇱
Site.eu
2026-08-18 17:13:21
(2 weeks ago)
Excessive multi-domain requests
Brute-Force
🇫🇷
Lacrimosa99
2026-08-18 17:04:11
(2 weeks ago)
8.235.28.31 - - [18/Aug/2026:19:04:07 +0200] "GET /admin/.env HTTP/2.0" 404 224 "-" "Mozilla/5.0 (co ...
show more
8.235.28.31 - - [18/Aug/2026:19:04:07 +0200] "GET /admin/.env HTTP/2.0" 404 224 "-" "Mozilla/5.0 (compatible; GrokBot/1.0; +https://x.ai/grokbot)"
8.235.28.31 - - [18/Aug/2026:19:04:08 +0200] "GET /firebase-adminsdk.json HTTP/2.0" 404 224 "-" "Mozilla/5.0 (compatible; GrokBot/1.0; +https://x.ai/grokbot)"
8.235.28.31 - - [18/Aug/2026:19:04:10 +0200] "GET /server-status HTTP/2.0" 403 227 "-" "Mozilla/5.0 (compatible; GrokBot/1.0; +https://x.ai/grokbot)"
...
show less
Web Spam
🇬🇧
thetomtaylor.co.uk
2026-08-18 16:02:02
(2 weeks ago)
Fail2Ban - [WAF]ModSecurity rule violation on modsecurity ... [mx03]
Hacking
SQL Injection
Web App Attack
🇩🇪
updown.io
2026-08-18 15:38:29
(2 weeks ago)
{"level":"info","ts":1787067506.7723205,"logger":"http.log.access.log0","msg":"handled request","req ...
show more
{"level":"info","ts":1787067506.7723205,"logger":"http.log.access.log0","msg":"handled request","request":{"remote_ip":"8.235.28.31","remote_port":"42404","client_ip":"8.235.28.31","proto":"HTTP/2.0","method":"GET","host":"g8h5.status.updown.io","uri":"/.profile","headers":{"Cookie":["REDACTED"],"User-Agent":["Mozilla/5.0 (compatible; cohere-ai/1.0; +https://cohere.com)"],"Accept-Encoding":["gzip, deflate"],"Accept":["*/*"]},"tls":{"resumed":false,"version":772,"cipher_suite":4865,"proto":"h2","server_name":"g8h5.status.updown.io","ech":false}},"bytes_read":0,"user_id":"","duration":0.000293491,"size":0,"status":429,"resp_headers":{"Server":["Caddy"],"Alt-Svc":["h3=\":443\"; ma=2592000"],"Retry-After":["1"]}}
{"level":"info","ts":1787067506.7752223,"logger":"http.log.access.log0","msg":"handled request","request":{"remote_ip":"8.235.28.31","remote_port":"42404","client_ip":"8.235.28.31","proto":"HTTP/2.0","method":"POST","host":"g8h5.status.updown.io","uri":"/graphql","headers":{"Sec-F
...
show less
DDoS Attack
Web App Attack