Anonymous
2026-09-24 08:09:46
(6 hours ago)
[server.tmg.gr] httpd-suspicious-path: logs=/var/log/httpd/access_log; samples=/api/session/properti ...
show more
[server.tmg.gr] httpd-suspicious-path: logs=/var/log/httpd/access_log; samples=/api/session/properties
show less
Hacking
Web App Attack
๐ณ๐ฑ
Roderic
2026-09-24 07:28:15
(7 hours ago)
*Port Scan* detected from 169.40.142.239 (FR/France/-/-/-/[redacted]).
Port Scan
Anonymous
2026-09-23 18:23:55
(20 hours ago)
169.40.142.239 - - [24/Sep/2026:02:23:55 +0800] "GET /.env HTTP/1.1" 200 30682 "-" "Mozilla/5.0 (Win ...
show more
169.40.142.239 - - [24/Sep/2026:02:23:55 +0800] "GET /.env HTTP/1.1" 200 30682 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
Anonymous
2026-09-23 14:39:00
(23 hours ago)
COPSLICOM WEBEXPLOIT 169.40.142.239 (169.40.142.239)
Web App Attack
๐ต๐พ
armandosaucedo.me
2026-09-23 12:48:10
(1 day ago)
Threat Intelligence via ARMTI, Web Attack: POST /en
Web App Attack
๐ฎ๐ฉ
soc-yk
2026-09-23 11:30:16
(1 day ago)
Type: suspicious_network_activity
Risk: 81
Events: 25
Evidence:
- Persistent suspicious network act ...
show more
Type: suspicious_network_activity
Risk: 81
Events: 25
Evidence:
- Persistent suspicious network activity detected
- Repeated hostile operational behavior observed
- Threat escalation behavior observed
show less
Port Scan
Hacking
๐ง๐ช
cmbplf
2026-09-23 07:45:57
(1 day ago)
294 requests with url.path *.php.bak
198 requests with url.path */debug.log
195 requests with url ...
show more
294 requests with url.path *.php.bak
198 requests with url.path */debug.log
195 requests with url.path *debug.log
show less
Brute-Force
Bad Web Bot
๐ณ๐ฑ
Alt255
2026-09-23 07:01:57
(1 day ago)
[ti-14al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail <name>. Example: 169 ...
show more
[ti-14al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail <name>. Example: 169.40.142.239 - - \[23/Sep/2026:09:01:45 +0200\] "GET /wp-config.php.save HTTP/1.1" 301 5822 "-" "Mozilla/5.0 \(Windows NT 10.0\; Win64\; x64\) AppleWebKit/537.36 \(KHTML, like Gecko\) Chrome/126.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
๐ต๐ฑ
Budyn
2026-09-23 06:30:43
(1 day ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: budyn.wtf | URI: /.env.old | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
Anonymous
2026-09-23 06:18:28
(1 day ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
๐ง๐ช
taivas.nl
2026-09-23 06:02:12
(1 day ago)
Bad_requests
Bad Web Bot
๐ฉ๐ช
FeG Deutschland
2026-09-23 05:01:53
(1 day ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 127
Exploited Host
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-23 04:36:22
(1 day ago)
[ti-02ra] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-02ra] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 169.40.142.239 - - [23/Sep/2026:06:36:13 +0200] "GET /wp-config.php.bak HTTP/1.1" 404 24130 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 04:32:57
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 169.40.142.239 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 169.40.142.239 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 00:32:55.416571 2026] [security2:error] [pid 30486:tid 30486] [client 169.40.142.239:42000] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "crep-psych.org"] [uri "/wp-config.php.bak"] [unique_id "arNWdwd3jXvuIeVEaYmjFAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ท๐ด
iulianh
2026-09-23 04:32:40
(1 day ago)
80,443
Brute-Force
SSH