๐ฎ๐ณ
evicky2002
2026-08-27 06:00:33
(4 days ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐ฌ๐ง
openstrike.co.uk
2026-08-27 05:13:56
(4 days ago)
215 attacks on env grabbing URLs, directory traversals, password grabbing URLs, VC URLs, site downlo ...
show more
215 attacks on env grabbing URLs, directory traversals, password grabbing URLs, VC URLs, site downloads, config grabbing URLs (type 2), PHP URLs:
GET /aws/.env.production HTTP/1.1
GET /..%252F..%252F..%252F..%252F..%252Fproc/self/environ HTTP/1.1
GET /.vscode/sftp.json HTTP/1.1
GET /.git/config HTTP/1.1
GET /database.sql HTTP/1.1
GET /appspec.yml HTTP/1.1
GET /info.php HTTP/1.1
show less
Hacking
Web App Attack
๐จ๐ญ
๐จ๐ญ Hosting
2026-08-27 05:10:24
(4 days ago)
Automated WAF report: 150-175 blocked requests from this IP detected by our WAF.
Bad Web Bot
Web App Attack
๐บ๐ธ
ALSCOยฎ๏ธ
2026-08-26 22:00:24
(4 days ago)
Report By ALSCO Security Team: Potential CSRF Attack Detected
Hacking
๐บ๐ธ
Secure Gatewayยฎ๏ธ
2026-08-26 22:00:23
(4 days ago)
Report By Secure Gateway Security Team: XSS Injection Attempt Detected
Hacking
๐ฉ๐ช
BlueWire Hosting
2026-08-26 19:03:44
(4 days ago)
High-confidence malicious configuration/VCS probe
Web App Attack
๐ธ๐ช
nekopavel
2026-08-26 16:33:03
(4 days ago)
34.125.247.9 - - [26/Aug/2026:18:32:59 +0200]"GET /.aws/credentials HTTP/1.1" 404 530"-" uwu.so "Moz ...
show more
34.125.247.9 - - [26/Aug/2026:18:32:59 +0200]"GET /.aws/credentials HTTP/1.1" 404 530"-" uwu.so "Mozilla/5.0 (iPhone; CPU iPhone OS 18_4 like Mac OS X) AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; +https://www.anthropic.com/claude-user) Chrome/91.0.3290.192 Mobile Safari/537.36""0.015" "0.000""Las Vegas" "US"
34.125.247.9 - - [26/Aug/2026:18:32:59 +0200]"GET /media../.env HTTP/1.1" 444 0"-" uwu.so "Mozilla/5.0 (compatible; GPTBot/1.2; +https://openai.com/gptbot)""0.000" "-""Las Vegas" "US"
34.125.247.9 - - [26/Aug/2026:18:33:00 +0200]"GET /.env HTTP/1.1" 444 0"-" uwu.so "Mozilla/5.0 (Macintosh; Intel Mac OS X 14_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.2281.234 Safari/537.36 Edg/126.0.2281.234; compatible; GPTBot/1.4; +https://openai.com/gptbot""0.000" "-""Las Vegas" "US"
...
show less
Hacking
Bad Web Bot
Web App Attack
Anonymous
2026-08-26 16:25:13
(4 days ago)
Bot / seems abusive / Apache connections: 102
DDoS Attack
Web Spam
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-08-26 14:13:52
(4 days ago)
Excessive multi-domain requests
Brute-Force
๐ฌ๐ง
consul.to
2026-08-26 14:03:52
(4 days ago)
Web attack/malicious scanning detected
Web App Attack
๐ณ๐ฟ
Tripwire
2026-08-26 12:44:00
(4 days ago)
Scanning for exploits - /@fs/etc/passwd?import&raw??
Web App Attack
๐ซ๐ท
Octopuce
2026-08-26 12:30:56
(4 days ago)
Aggressive web search of vulnerable pages: /static../.env /app/.env /media../.env /server/.env /api/ ...
show more
Aggressive web search of vulnerable pages: /static../.env /app/.env /media../.env /server/.env /api/.env ...
show less
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-08-26 12:20:08
(4 days ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
๐ฉ๐ช
yitzhaq
2026-08-26 12:13:22
(4 days ago)
34.125.247.9 - - [26/Aug/2026:14:13:20 +0200] "GET /jenkins/secrets/master.key HTTP/1.1" 404 760 "-" ...
show more
34.125.247.9 - - [26/Aug/2026:14:13:20 +0200] "GET /jenkins/secrets/master.key HTTP/1.1" 404 760 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14.5; rv:105.0) Gecko/20100101 Firefox/105.0; compatible; GrokBot/1.0; +https://x.ai/grokbot"
34.125.247.9 - - [26/Aug/2026:14:13:20 +0200] "GET /.env.development.local HTTP/1.1" 404 760 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Bytespider; +https://zhanzhang.toutiao.com/)"
34.125.247.9 - - [26/Aug/2026:14:13:20 +0200] "GET /.env.php HTTP/1.1" 404 577 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; GPTBot/1.2; +https://openai.com/gptbot)"
34.125.247.9 - - [26/Aug/2026:14:13:20 +0200] "GET /environment.js HTTP/1.1" 404 452 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_4 like Mac OS X) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.8793.218 Mobile Safari/537.36; compatible; Claude-User/1.0; [email]"
34.125.247.9 - - [26/Aug/2026:14:13:20 +0200] "GET /.env.local.php HTTP/1.1" 404 577 "-" "Mozilla/5.0 (c
show less
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-26 11:50:53
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.125.247.9 (9.247.125.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.125.247.9 (9.247.125.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 07:50:46.325300 2026] [security2:error] [pid 31286:tid 31286] [client 34.125.247.9:64542] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "folkdancers.org"] [uri "/static../.env"] [unique_id "ao7TFgQEvdTjm51DtfEV_QAAAI0"]
show less
Brute-Force
Bad Web Bot
Web App Attack