๐ฎ๐ณ
evicky2002
2026-07-21 06:00:00
(1 day ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐ธ๐ช
EmK530
2026-07-21 02:28:10
(1 day ago)
URL flagged by RegEx: /phpinfo.php
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-21 02:17:14
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.116.231.235 (235.231.116.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.116.231.235 (235.231.116.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 22:17:07.034117 2026] [security2:error] [pid 14169:tid 14169] [client 34.116.231.235:45950] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "polish-boat-registration.com"] [uri "/.git/HEAD"] [unique_id "al7Wo0djaP3j5hFT2a4D3wAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-21 01:57:16
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.116.231.235 (235.231.116.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.116.231.235 (235.231.116.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 21:57:11.353584 2026] [security2:error] [pid 2209780:tid 2209780] [client 34.116.231.235:45866] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.keysenterprise.com"] [uri "/.git/config"] [unique_id "al7R9_5UBFqvD0WYaIpoWQAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-21 01:40:32
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.116.231.235 (235.231.116.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 34.116.231.235 (235.231.116.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 21:40:29.588756 2026] [security2:error] [pid 8992:tid 8992] [client 34.116.231.235:45406] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||bvnboysbasketball.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "bvnboysbasketball.com"] [uri "/rclone.conf"] [unique_id "al7ODQ-b6yL87oTRbCfY-QAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐น๐ญ
MWA SOC
2026-07-21 01:39:48
(1 day ago)
Hacking
๐ฒ๐พ
Rizzy
2026-07-21 01:34:03
(1 day ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐ณ๐ฟ
Antinson
2026-07-21 01:09:08
(1 day ago)
Scraping with a high error ratio and request rate
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-07-20 23:45:42
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.116.231.235 (235.231.116.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.116.231.235 (235.231.116.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 19:45:38.518343 2026] [security2:error] [pid 1688925:tid 1688925] [client 34.116.231.235:41952] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "buanamegah.com"] [uri "/.env.example"] [unique_id "al6zIrXFnEFLaoymAvyryQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-07-20 23:30:58
(1 day ago)
34.116.231.235 - - [21/Jul/2026:02:30:56 +0300] "GET /api/.env HTTP/1.1" 404 702 "-" "Mozilla/5.0 Ap ...
show more
34.116.231.235 - - [21/Jul/2026:02:30:56 +0300] "GET /api/.env HTTP/1.1" 404 702 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot"
34.116.231.235 - - [21/Jul/2026:02:30:57 +0300] "GET /config/.env HTTP/1.1" 404 650 "-" "anthropic-ai"
...
show less
Web App Attack
๐บ๐ธ
jormaster3k
2026-07-20 23:12:37
(2 days ago)
Attack against Apache (too many 404s)
Web App Attack
๐ฌ๐ง
blik2108
2026-07-20 22:58:46
(2 days ago)
www.nomadsailing.co.uk:443 34.116.231.235 - - [20/Jul/2026:23:58:45 +0100] "GET /__/firebase/init.js ...
show more
www.nomadsailing.co.uk:443 34.116.231.235 - - [20/Jul/2026:23:58:45 +0100] "GET /__/firebase/init.json HTTP/1.1" 404 3557 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot"
www.nomadsailing.co.uk:443 34.116.231.235 - - [20/Jul/2026:23:58:45 +0100] "GET /.git/config HTTP/1.1" 404 5344 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot"
www.nomadsailing.co.uk:443 34.116.231.235 - - [20/Jul/2026:23:58:45 +0100] "GET /.aws/config HTTP/1.1" 404 8382 "-" "Mozilla/5.0 (compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot)"
www.nomadsailing.co.uk:443 34.116.231.235 - - [20/Jul/2026:23:58:45 +0100] "GET /.aws/credentials HTTP/1.1" 404 8382 "-" "meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)"
www.nomadsailing.co.uk:443 34.116.231.235 - - [20/Jul/2026:23:58:45 +0100] "GET /api/openapi.json HTTP/1.1" 404 8382 "-" "
...
show less
Web App Attack
๐ธ๐ช
EmK530
2026-07-20 22:43:36
(2 days ago)
URL flagged by RegEx: /actuator/configprops
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-07-20 22:41:54
(2 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 1247
Exploited Host
Web App Attack
๐ง๐ช
voormedia
2026-07-20 22:24:15
(2 days ago)
Accessed trap at '/.aws/config'
Web App Attack