🇩🇪
Vegascosmetics
2026-09-06 03:57:17
(21 hours ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after SQL injection / SQLi probing. Evidenc ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after SQL injection / SQLi probing. Evidence: AttackPattern: (backup|src|source|sql|archive|snapshot|restore|recovery|deploy|artifact|bundle|package|app|frontend|backend)\.(zip|tar|gz...
show less
Hacking
Web App Attack
🇩🇪
gadix
2026-09-06 03:51:51
(21 hours ago)
[06/Sep/2026:05:51:49.326377 +0200] apzjVbupZ1RrYE_hQ7HWcgAAAAg 104.199.176.206 40440 127.0.0.1 7081 ...
show more
[06/Sep/2026:05:51:49.326377 +0200] apzjVbupZ1RrYE_hQ7HWcgAAAAg 104.199.176.206 40440 127.0.0.1 7081
[06/Sep/2026:05:51:49.335757 +0200] apzjVVi8geoOQLbtDPEXcAAAAAE 104.199.176.206 40458 127.0.0.1 7081
[06/Sep/2026:05:51:49.337665 +0200] apzjVQVrhA8bSsMk2qII9QAAAAU 104.199.176.206 40482 127.0.0.1 7081
...
show less
Web App Attack
🇩🇪
raph
2026-09-06 03:01:05
(22 hours ago)
[Wordpress] crawler /wp-admin/*, /wp-content/*, etc.
Bad Web Bot
Web App Attack
🇳🇱
debestelapp
2026-09-06 03:00:13
(22 hours ago)
Web App Attack
Anonymous
2026-09-06 02:33:25
(23 hours ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
🇷🇴
iulianh
2026-09-06 02:23:26
(23 hours ago)
80,443
Brute-Force
SSH
🇮🇳
evicky2002
2026-09-06 00:02:40
(1 day ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
🇬🇧
consul.to
2026-09-05 22:48:12
(1 day ago)
Web attack/malicious scanning detected
Web App Attack
🇳🇱
e.fierstra
2026-09-05 20:35:39
(1 day ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇺🇸
Starburst SysOp Team
2026-09-05 07:13:41
(1 day ago)
(mod_security-custom) mod_security (id:210492) triggered by 104.199.176.206 (TW/Taiwan/Taiwan/Taoyua ...
show more
(mod_security-custom) mod_security (id:210492) triggered by 104.199.176.206 (TW/Taiwan/Taiwan/Taoyuan/206.176.199.104.bc.googleusercontent.com/[AS396982 GOOGLE-CLOUD-PLATFORM]): 1 in the last 3600 secs (0-srv1)
show less
Hacking
🇺🇸
zwebvigil
2026-09-05 06:42:30
(1 day ago)
104.199.176.206 [04/Sep/2026:23:42:30 -0700] "GET /.env.bak HTTP/1.1" 404 2681 "-" port=37804 "crus ...
show more
104.199.176.206 [04/Sep/2026:23:42:30 -0700] "GET /.env.bak HTTP/1.1" 404 2681 "-" port=37804 "crusader-worker/1.0" "-" "-" "<ghost>ercontent.com" 914
104.199.176.206 [04/Sep/2026:23:42:30 -0700] "GET /crusader-404-probe HTTP/1.1" 404 2701 "-" port=37750 "crusader-worker/1.0" "-" "-" "<ghost>ercontent.com" 949
104.199.176.206 [04/Sep/2026:23:42:30 -0700] "GET /env HTTP/1.1" 404 2671 "-" port=37696 "crusader-worker/1.0" "-" "-" "<ghost>ercontent.com" 1049
104.199.176.206 [04/Sep/2026:23:42:30 -0700] "GET /wp-config.php.swp HTTP/1.1" 404 2699 "-" port=37820 "crusader-worker/1.0" "-" "-" "<ghost>ercontent.com" 643
104.199.176.206 [04/Sep/2026:23:42:30 -0700] "GET /_ignition/health-check HTTP/1.1" 404 2709 "-" port=37720 "crusader-worker/1.0" "-" "-" "<ghost>ercontent.com" 1389
104.199.176.206 [04/Sep/2026:23:42:30 -0700] "GET /.env.dev HTTP/1.1" 404 2681 "-" port=37792 "cru
show less
Web App Attack
🇳🇱
homeshowdomain.nl
2026-09-04 22:03:11
(2 days ago)
Auto-ban: >3000 req/min op 2026-09-04
Web App Attack
SSH
Hacking
🇺🇸
TPI-Abuse
2026-09-04 15:21:39
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 104.199.176.206 (206.176.199.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 104.199.176.206 (206.176.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 11:21:32.599386 2026] [security2:error] [pid 19482:tid 19482] [client 104.199.176.206:39672] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.imagea.net"] [uri "/.env.local"] [unique_id "aprh_EkdtYtR_qD0Whg-5AAAAC8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇭
lufi
2026-09-04 15:09:26
(2 days ago)
2026-09-04T17:09:26+02:00 lufischer04 ids442 2026-09-04 17:09:26 104.199.176.206: blacklisted Patter ...
show more
2026-09-04T17:09:26+02:00 lufischer04 ids442 2026-09-04 17:09:26 104.199.176.206: blacklisted Pattern: /.env.local
...
show less
Web Spam
Brute-Force
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 13:48:56
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 104.199.176.206 (206.176.199.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 104.199.176.206 (206.176.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 09:48:48.417872 2026] [security2:error] [pid 12152:tid 12152] [client 104.199.176.206:51658] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "agapeaccountingllc.com"] [uri "/.env.bak"] [unique_id "aprMQOPB90_hjmXddENjRAAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack