๐ฉ๐ช
XICTRON
2026-09-18 07:55:07
(1 hour ago)
ModSecurity rule violation detected by Fail2Ban
Web App Attack
๐ฉ๐ช
FD-IX
2026-09-18 07:14:25
(2 hours ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
๐ฌ๐ง
openstrike.co.uk
2026-09-18 05:14:01
(4 hours ago)
4994 attacks on config grabbing URLs (type 2), env grabbing URLs (type 2), directory traversals, pas ...
show more
4994 attacks on config grabbing URLs (type 2), env grabbing URLs (type 2), directory traversals, password/key grabbing URLs, PHP URLs, VC URLs, env grabbing URLs:
GET /config/firebase-admin.json HTTP/1.1
GET /_image?href=/proc/self/environ HTTP/1.1
GET /..%2f..%2f.env HTTP/1.1
GET /__vite_rsc_findSourceMapURL?filename=file:///root/.ssh/id_rsa&environmentName=rsc HTTP/1.1
POST /icecoder/lib/terminal-xhr.php HTTP/1.1
GET /.git/config HTTP/1.1
GET /pkg/.env HTTP/1.1
show less
Hacking
Web App Attack
๐ง๐ช
taivas.nl
2026-09-18 04:33:20
(5 hours ago)
Many_bad_calls
Web App Attack
๐ง๐ท
SvrAdmin
2026-09-18 03:34:45
(6 hours ago)
[204] (cpanel) Failed cPanel login from 136.69.195.83 (US/United States/83.195.69.136.bc.googleuserc ...
show more
[204] (cpanel) Failed cPanel login from 136.69.195.83 (US/United States/83.195.69.136.bc.googleusercontent.com): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CPANEL; Logs: [2026-09-18 00:34:35 -0300] info [cpaneld] 136.69.195.83 - - "GET /z9x8c7v6b5-debug-trigger-cpanel.portaldebeltrao.com.br HTTP/1.1" FAILED LOGIN cpaneld: login attempt without username
[2026-09-18 00:34:35 -0300] info [cpaneld] 136.69.195.83 - - "GET /assets/manifest.json HTTP/1.1" FAILED LOGIN cpaneld: login attempt without username
[2026-09-18 00:34:35 -0300] info [cpaneld] 136.69.195.83 - - "GET /serverless.yml HTTP/1.1" FAILED LOGIN cpaneld: login attempt without username
[2026-09-18 00:34:35 -0300] info [cpaneld] 136.69.195.83 - - "GET /config/env/aws_credentials.env HTTP/1.1" FAILED LOGIN cpaneld: login attempt without username
[2026-09-18 00:34:36 -0300] info [cpaneld] 136.69.195.83 - - "GET /.idea/WebServers.xml HTTP/1.1" FAILED LOGIN cpaneld: login attempt without username
show less
Port Scan
Hacking
Brute-Force
Exploited Host
๐ฎ๐น
VHosting
2026-09-18 03:20:03
(6 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
Anonymous
2026-09-18 02:31:19
(7 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
๐บ๐ธ
zcampbell
2026-09-18 02:12:05
(7 hours ago)
Web vulnerability scanning: probing for exposed sensitive files (.env). Detected and blocked automat ...
show more
Web vulnerability scanning: probing for exposed sensitive files (.env). Detected and blocked automatically.
show less
Web App Attack
Bad Web Bot
๐ซ๐ท
SpaceHost-Server
2026-09-17 22:15:49
(11 hours ago)
Brute-Force
Web App Attack
Anonymous
2026-09-17 19:54:20
(13 hours ago)
Aggressive web scan
Web App Attack
๐ฉ๐ช
Hazzard
2026-09-17 14:59:14
(18 hours ago)
(PERMBLOCK) 136.69.195.83 (US/United States/Oregon/The Dalles/83.195.69.136.bc.googleusercontent.com ...
show more
(PERMBLOCK) 136.69.195.83 (US/United States/Oregon/The Dalles/83.195.69.136.bc.googleusercontent.com/[redacted]) has had more than 4 temp blocks
show less
Hacking
Anonymous
2026-09-17 14:28:01
(19 hours ago)
Bot / scanning and/or hacking attempts: GET /.env_sample HTTP/2.0, GET /values.yaml HTTP/2.0, GET /a ...
show more
Bot / scanning and/or hacking attempts: GET /.env_sample HTTP/2.0, GET /values.yaml HTTP/2.0, GET /app/.env HTTP/2.0
show less
Hacking
Web App Attack
๐ฉ๐ช
Hazzard
2026-09-17 10:56:50
(22 hours ago)
(mod_security) mod_security triggered on hostname [redacted]): (CF_ENABLE)
SQL Injection
๐ฉ๐ช
Marc
2026-09-17 09:51:46
(23 hours ago)
136.69.195.83 - - [17/Sep/2026:11:51:45 +0200] "GET /secure HTTP/2.0" 404 291 "-" "Mozilla/5.0 (Maci ...
show more
136.69.195.83 - - [17/Sep/2026:11:51:45 +0200] "GET /secure HTTP/2.0" 404 291 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36" 136.69.195.83 - - [17/Sep/2026:11:51:45 +0200] "GET /sign-in HTTP/2.0" 404 269 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36" 136.69.195.83 - - [17/Sep/2026:11:51:45 +0200] "GET /.env.local?raw HTTP/2.0" 404 269 "-" "Mozilla/5.0 (compatible; ChatGLM-Spider/1.0; +https://zhipuai.cn/)"
show less
Brute-Force
๐ณ๐ฑ
Alt255
2026-09-17 09:38:26
(1 day ago)
[cb-13al] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail apac ...
show more
[cb-13al] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail apache-404. Example: 136.69.195.83 - - [17/Sep/2026:11:38:06 +0200] "GET /api/config HTTP/2.0" 404 1901 "-" "Mozilla/5.0 (compatible; PanguBot/1.0; +https://www.huaweicloud.com/)"
136.69.195.83 - - [17/Sep/2026:11:38:06 +0200] "GET /config.json HTTP/2.0" 404 1855 "-" "Mozilla/5.0 (compatible; GrokBot/1.0; +https://x.ai/)"
136.69.195.83 - - [17/Sep/2026:11:38:06 +0200] "GET /__/firebase/init.json HTTP/2.0" 404 1855 "-" "Mozilla/5.0 (compatible; MoonshotBot/1.0; +https://kimi.ai/)"
136.69.195.83 - - [17/Sep/2026:11:38:06 +0200] "GET /dist/manifest.json HTTP/2.0" 404 1855 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36"
136.69.195.83 - - [17/Sep/2026:11:38:
...
show less
Bad Web Bot
Web App Attack