๐ฎ๐ฑ
spd.co.il
2026-09-18 18:02:16
(23 hours ago)
Web application attack detected
Hacking
Web App Attack
๐ง๐ท
Peregrine
2026-09-18 03:12:16
(1 day ago)
Fail2Ban Jail: tomcat-honeypot | Evidence: 204.236.220.243 172.70.174.203 - - [16/Sep/2026:23:35:50 ...
show more
Fail2Ban Jail: tomcat-honeypot | Evidence: 204.236.220.243 172.70.174.203 - - [16/Sep/2026:23:35:50 -0300] "GET /.github/.env HTTP/1.1" 404 414
204.236.220.243 172.70.174.203 - - [16/Sep/2026:23:35:54 -0300] "GET /config/env/aws_credentials.env HTTP/1.1" 404 414
204.236.220.243 172.70.174.203 - - [16/Sep/2026:23:35:54 -0300] "GET /secrets.env HTTP/1.1" 404 414
show less
Bad Web Bot
๐ซ๐ท
SpaceHost-Server
2026-09-17 22:18:43
(1 day ago)
Brute-Force
Web App Attack
๐ฌ๐ง
consul.to
2026-09-17 03:01:07
(2 days ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-17 02:57:00
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 204.236.220.243 (ec2-204-236-220-243.compute-1. ...
show more
(mod_security) mod_security (id:210730) triggered by 204.236.220.243 (ec2-204-236-220-243.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 22:56:55.769515 2026] [security2:error] [pid 15442:tid 15442] [client 204.236.220.243:0] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||portfoliolighting.net|F|2"] [data ".key"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "portfoliolighting.net"] [uri "/privatekey.key"] [unique_id "aqtW98f_J6mOvKpRm1FGbAAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Eric
2026-09-17 02:54:59
(2 days ago)
[Thu Sep 17 02:54:56.798453 2026] [security2:error] [pid 674746:tid 674746] [client 204.236.220.243: ...
show more
[Thu Sep 17 02:54:56.798453 2026] [security2:error] [pid 674746:tid 674746] [client 204.236.220.243:0] [client 204.236.220.243] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "pop-the-slots.com"] [uri "/privatekey.key"] [unique_id "aqtWgNWatMUcibnd7mIntQAAACA"]
[Thu Sep 17 02:54:58.815143 2026] [security2:error] [pid 674731:tid 674731] [client 204.236.220.243:0] [client 204.236.220.243] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score:
...
show less
Hacking
Web App Attack
๐ง๐ท
Peregrine
2026-09-17 02:35:55
(2 days ago)
Fail2Ban Jail: tomcat-honeypot | Evidence: 204.236.220.243 172.70.174.203 - - [16/Sep/2026:23:35:50 ...
show more
Fail2Ban Jail: tomcat-honeypot | Evidence: 204.236.220.243 172.70.174.203 - - [16/Sep/2026:23:35:50 -0300] "GET /.github/.env HTTP/1.1" 404 414
204.236.220.243 172.70.174.203 - - [16/Sep/2026:23:35:54 -0300] "GET /config/env/aws_credentials.env HTTP/1.1" 404 414
204.236.220.243 172.70.174.203 - - [16/Sep/2026:23:35:54 -0300] "GET /secrets.env HTTP/1.1" 404 414
show less
Bad Web Bot
๐บ๐ธ
abuse-opdc
2026-09-17 02:15:46
(2 days ago)
Malicious HTTP requests matching injection/exploit signatures.
Web App Attack
Brute-Force
๐ง๐ช
voormedia
2026-09-17 02:06:40
(2 days ago)
Accessed trap at '/.bash_profile'
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-17 02:01:33
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 204.236.220.243 (ec2-204-236-220-243.compute-1. ...
show more
(mod_security) mod_security (id:210730) triggered by 204.236.220.243 (ec2-204-236-220-243.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 22:01:28.748500 2026] [security2:error] [pid 25753:tid 25753] [client 204.236.220.243:60080] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ofertasdetrabajosyempleos.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ofertasdetrabajosyempleos.com"] [uri "/rclone.conf"] [unique_id "aqtJ-Ol4FcuLTn_NVnud4AAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ต๐ฑ
nfsec.pl
2026-09-17 01:44:05
(2 days ago)
204.236.220.243 - - [17/Sep/2026:01:44:04 +0000] "GET /.git-credentials HTTP/2.0" 403 1115 "-" "Mozi ...
show more
204.236.220.243 - - [17/Sep/2026:01:44:04 +0000] "GET /.git-credentials HTTP/2.0" 403 1115 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; GPTBot/1.3; +https://openai.com/gptbot)"
204.236.220.243 - - [17/Sep/2026:01:44:04 +0000] "GET /.git/HEAD HTTP/2.0" 403 1123 "-" "Mozilla/5.0 (compatible; Meta-ExternalAgent/1.0; +https://developers.facebook.com/docs/sharing/webmasters/crawler)"
204.236.220.243 - - [17/Sep/2026:01:44:04 +0000] "GET /.gitconfig HTTP/2.0" 403 1123 "-" "Mozilla/5.0 (compatible; Meta-ExternalAgent/1.0; +https://developers.facebook.com/docs/sharing/webmasters/crawler)"
204.236.220.243 - - [17/Sep/2026:01:44:04 +0000] "GET /.git/config HTTP/2.0" 403 1075 "-" "Mozilla/5.0 (compatible; Bravebot/1.0; +https://brave.com/search/)"
204.236.220.243 - - [17/Sep/2026:01:44:04 +0000] "GET /rclone.conf HTTP/2.0" 404 25037 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; [email protected] )"
...
show less
Web App Attack
Exploited Host
๐ฉ๐ช
netclix.gr
2026-09-17 01:39:21
(2 days ago)
(mod_security) mod_security triggered on hostname [redacted] 204.236.220.243 (US/United States/ec2-2 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 204.236.220.243 (US/United States/ec2-204-236-220-243.compute-1.amazonaws.com): (CF_ENABLE)
show less
SQL Injection
๐ณ๐ฑ
MyGlobalFlowers
2026-09-17 01:28:08
(2 days ago)
Multiple WAF Violations
Web App Attack
๐ณ๐ฑ
Savvii
2026-09-17 01:14:22
(2 days ago)
20 attempts against mh-misbehave-ban on onion
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ฌ
Cloudkul Cloudkul
2026-09-17 01:12:33
(2 days ago)
Attempted Not Found (404 status code) requests on our application, more than 30% of their total requ ...
show more
Attempted Not Found (404 status code) requests on our application, more than 30% of their total requests.
show less
Brute-Force
Web App Attack