๐ฉ๐ช
hidemail.app
2026-10-01 07:07:12
(1 week ago)
Automated scan for exposed config/secret files and known web exploits (e.g. /.env, RCE probes); auto ...
show more
Automated scan for exposed config/secret files and known web exploits (e.g. /.env, RCE probes); auto-banned by fail2ban.
show less
Web App Attack
Hacking
๐ธ๐ฌ
simpeg-adm.bandung.go.id
2026-10-01 05:30:11
(1 week ago)
01/Oct/2026:05:30:10 +0000;34.118.139.21;"/z9x8c7v6b5-debug-trigger-vendors.afterfocus.co.uk"
01/Oct ...
show more
01/Oct/2026:05:30:10 +0000;34.118.139.21;"/z9x8c7v6b5-debug-trigger-vendors.afterfocus.co.uk"
01/Oct/2026:05:30:10 +0000;34.118.139.21;"/vqc9n3231h5kga482v2v"
01/Oct/2026:05:30:10 +0000;34.118.139.21;"/e9w3aoz8zpzjaprcu9xa"
01/Oct/2026:05:30:10 +0000;34.118.139.21;"/dist/manifest.json"
01/Oct/2026:05:30:10 +0000;34.118.139.21;"/lib/terminal-xhr.php"
01/Oct/2026:05:30:10 +0000;34.118.139.21;"/dist/.vite/manifest.json"
01/Oct/2026:05:30:10 +0000;34.118.139.21;"/.vite/manifest.json"
...
show less
Web Spam
Brute-Force
Web App Attack
๐ฌ๐ง
openstrike.co.uk
2026-10-01 05:13:23
(1 week ago)
234 attacks on PHP URLs, config grabbing URLs (type 2), env grabbing URLs (type 2), VC URLs, directo ...
show more
234 attacks on PHP URLs, config grabbing URLs (type 2), env grabbing URLs (type 2), VC URLs, directory traversals, password/key grabbing URLs, env grabbing URLs, shell probes:
POST /index.php?-d+allow_url_include%3don+-d+auto_prepend_file%3dphp://input HTTP/1.1
GET /appsettings.Production.json HTTP/1.1
GET /%2e%2e/%2e%2e/%2e%2e/%2e%2e/proc/self/environ HTTP/1.1
GET /.git/HEAD HTTP/1.1
GET /..%2f..%2f.env HTTP/1.1
GET /@fs/home/ubuntu/.aws/credentials?raw?? HTTP/1.1
GET /@fs/app/.env.production?import&raw?? HTTP/1.1
POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh HTTP/1.1
show less
Web App Attack
Hacking
๐ฌ๐ง
thetomtaylor.co.uk
2026-10-01 05:08:00
(1 week ago)
Fail2Ban - [WEB]Custom exploit pattern detected on customexploits ... [ice01,ice02]
Hacking
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 05:06:20
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.118.139.21 (21.139.118.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.118.139.21 (21.139.118.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 01:06:17.180447 2026] [security2:error] [pid 13620:tid 13620] [client 34.118.139.21:38728] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/Web.config" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.dragonfly.garden"] [uri "/web.config"] [unique_id "ar3qSTAic0cLKJd1O-ci6gAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-10-01 04:12:28
(1 week ago)
Web attack/malicious scanning detected
Web App Attack
๐ฌ๐ง
thetomtaylor.co.uk
2026-10-01 04:07:02
(1 week ago)
Fail2Ban - [WEB]Custom exploit pattern detected on customexploits ... [wa01,wa02]
Hacking
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 04:05:55
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.118.139.21 (21.139.118.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.118.139.21 (21.139.118.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 00:05:48.317723 2026] [security2:error] [pid 6373:tid 6373] [client 34.118.139.21:50800] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.natashahenry.co.uk"] [uri "/.//.env"] [unique_id "ar3cHINdj8M7YOZQGo0tKwAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 03:41:22
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 34.118.139.21 (21.139.118.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.118.139.21 (21.139.118.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 23:41:16.967840 2026] [security2:error] [pid 9745:tid 10185] [client 34.118.139.21:42864] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.furball.co.uk|F|2"] [data ".key"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.furball.co.uk"] [uri "/server.key"] [unique_id "ar3WXGELlPiSmevfTfOwSQAAANE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
โจ
2026-10-01 02:03:08
(1 week ago)
Domain : dennistounconservationsociety.org.uk
Rule : env
2026-10-01 02:02:06 ***hidden-privacy*** GE ...
show more
Domain : dennistounconservationsociety.org.uk
Rule : env
2026-10-01 02:02:06 ***hidden-privacy*** GET /.env raw?? 443 - 34.118.139.21 HTTP/2 Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-SearchBot/1.0; [email protected] ) - dennistounconservationsociety.org.uk 404 0 2 4923 628 85 - -
show less
Hacking
SQL Injection
๐ฉ๐ช
stinpriza
2026-10-01 01:56:00
(1 week ago)
common Web Exploits being scanned
Web App Attack
๐ซ๐ท
โจ
2026-10-01 01:23:16
(1 week ago)
Domain : redirect.netenergy.uk
Rule : admin
2026-10-01 01:20:36 217.194.210.152 GET /admin/login - 4 ...
show more
Domain : redirect.netenergy.uk
Rule : admin
2026-10-01 01:20:36 217.194.210.152 GET /admin/login - 443 - 34.118.139.21 HTTP/2 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36 - artsearch.org.uk 404 0 2 1524 890 84 - -
show less
Hacking
SQL Injection
Brute-Force
๐ซ๐ท
GabrielJST
2026-10-01 01:20:30
(1 week ago)
(mod_security) mod_security triggered on hostname [redacted] 34.118.139.21 (CA/Canada/21.139.118.34. ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.118.139.21 (CA/Canada/21.139.118.34.bc.googleusercontent.com): (CF_ENABLE)
show less
SQL Injection
๐ง๐ช
cmbplf
2026-10-01 00:38:17
(1 week ago)
2.046 requests with url.path *.env
453 requests with url.path */@fs/*
161 requests with url.path ...
show more
2.046 requests with url.path *.env
453 requests with url.path */@fs/*
161 requests with url.path */proc/*
124 requests with url.path *.ssh/*
117 requests with url.path *credentials.json
115 requests with url.path *config.json
103 requests with url.path *.aws/*
show less
Brute-Force
Bad Web Bot
๐ต๐ฑ
sigurg
2026-09-30 23:40:23
(1 week ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-bad-user-agent
Web App Attack
Bad Web Bot