๐ฎ๐ณ
evicky2002
2026-08-01 06:00:00
(13 hours ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐ฌ๐ง
openstrike.co.uk
2026-08-01 05:14:22
(14 hours ago)
98 attacks on PHP URLs, VC URLs, shell probes, config grabbing URLs (type 2), env grabbing URLs, too ...
show more
98 attacks on PHP URLs, VC URLs, shell probes, config grabbing URLs (type 2), env grabbing URLs, too many concurrent requests, password grabbing URLs, site downloads:
POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
GET /.git/config HTTP/1.1
POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/bin/sh HTTP/1.1
GET /config.ini HTTP/1.1
GET /.env.development.local HTTP/1.1
GET /wp-config.php.save HTTP/1.1
GET /.aws/credentials HTTP/1.1
GET /database.sql HTTP/1.1
show less
Web App Attack
Hacking
Bad Web Bot
Anonymous
2026-08-01 01:08:47
(18 hours ago)
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: US, Attack patterns: Word ...
show more
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: US, Attack patterns: WordPress scanning, SQL injection, Backup file probing
show less
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-07-31 22:32:38
(21 hours ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.125.65.175 (US/United States/175.6 ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.125.65.175 (US/United States/175.65.125.34.bc.googleusercontent.com): 2 in the last 3600 secs (0-196)
show less
Hacking
๐ฉ๐ช
maxpower
2026-07-31 22:24:10
(21 hours ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 34.125.65.175 (US/United States/175.65.1 ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 34.125.65.175 (US/United States/175.65.125.34.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 34.125.65.175 - - [01/Aug/2026:00:24:03 +0200] "GET /secrets.yml HTTP/2.0" 200 1232 "-" "facebookexternalhit/1.1 (+http://www.facebook.com/externalhit_uatext.php)" "34.125.65.175" host=insegnesolution.it
show less
Port Scan
๐ฎ๐น
IRT@Unisi
2026-07-31 21:57:10
(21 hours ago)
Multiple web server 400 error codes from same source ip.
Bad Web Bot
๐ฉ๐ช
raph
2026-07-31 21:34:52
(21 hours ago)
[LIB DIR] crawler /vendor/*, /node_modules/*, /laravel/*, etc.
Bad Web Bot
Web App Attack
๐ฉ๐ช
updown.io
2026-07-31 20:10:09
(23 hours ago)
{"level":"info","ts":1785528594.2843792,"logger":"http.log.access.log1","msg":"handled request","req ...
show more
{"level":"info","ts":1785528594.2843792,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"34.125.65.175","remote_port":"28316","client_ip":"34.125.65.175","proto":"HTTP/1.1","method":"GET","host":"hosted.rikr.tech","uri":"/","headers":{"Accept":["*/*"],"Accept-Encoding":["gzip"],"User-Agent":["Mozilla/5.0 (X11; Linux x86_64; rv:150.0) Gecko/20100101 Firefox/150.0"]}},"bytes_read":0,"user_id":"","duration":0.000064973,"size":0,"status":308,"resp_headers":{"Server":["Caddy"],"Connection":["close"],"Location":["https://hosted.rikr.tech/"],"Content-Type":[]}}
{"level":"info","ts":1785528608.8816118,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"34.125.65.175","remote_port":"3934","client_ip":"34.125.65.175","proto":"HTTP/1.1","method":"GET","host":"hosted.rikr.tech","uri":"/.env.production","headers":{"User-Agent":["Mozilla/5.0 (compatible; ClaudeBot/1.0; [email protected] )"],"Accept":["text/html,application/xhtml+xml,ap
...
show less
DDoS Attack
Web App Attack
๐ธ๐ช
vaia.cloud
2026-07-31 20:00:02
(23 hours ago)
crowdsecurity/CVE-2017-9841
Brute-Force
Web App Attack
๐ณ๐ฑ
Cloud86 B.V.
2026-07-31 19:26:07
(1 day ago)
categories: DDoS Attack
DDoS Attack
๐ฎ๐น
CoreTech srl
2026-07-31 18:43:57
(1 day ago)
cloudlinux2 fail2ban: 2026-07-31 20:40:18,046 fail2ban.filter [1838]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-07-31 20:40:18,046 fail2ban.filter [1838]: INFO [plesk-modsecurity] Found 34.125.65.175 - 2026-07-31 20:40:17cloudlinux2 fail2ban: 2026-07-31 20:40:18,027 fail2ban.filter [1838]: INFO [plesk-modsecurity] Found 34.125.65.175 - 2026-07-31 20:40:17cloudlinux2 fail2ban: 2026-07-31 20:40:17,945 fail2ban.filter [1838]: INFO [plesk-modsecurity] Found 34.125.65.175 - 2026-07-31 20:40:17cloudlinux2 fail2ban: 2026-07-31 20:40:18,018 fail2ban.filter [1838]: INFO [plesk-modsecurity] Found 34.125.65.175 - 2026-07-31 20:40:17cloudlinux2 fail2ban: 2026-07-31 20:40:18,081 fail2ban.actions [1838]: NOTICE [plesk-modsecurity] Ban 34.125.65.175cloudlinux2 fail2ban: 2026-07-31 20:40:18,138 fail2ban.filter [1838]: INFO [plesk-modsecurity] Found 34.125.65.175 - 2026-07-31 20:40:17cloudlinux2 fail2ban: 2026-07-31 20:40:18,076 fail2ban.filter [1838]: INFO [plesk-modsecurity] Found 34.125.65.175 - 2026-07-31 20:40:17cloudlinux2 fail2ba
show less
Brute-Force
Anonymous
2026-07-31 18:01:46
(1 day ago)
34.125.65.175 - - [31/Jul/2026:20:01:25 +0200] "GET /application.yml HTTP/1.1" 404 30152
34.125.65.1 ...
show more
34.125.65.175 - - [31/Jul/2026:20:01:25 +0200] "GET /application.yml HTTP/1.1" 404 30152
34.125.65.175 - - [31/Jul/2026:20:01:25 +0200] "GET /config.js HTTP/1.1" 404 30237
34.125.65.175 - - [31/Jul/2026:20:01:25 +0200] "GET /actuator/configprops HTTP/1.1" 404 30035
34.125.65.175 - - [31/Jul/2026:20:01:25 +0200] "GET /keyfile.json HTTP/1.1" 404 30152
34.125.65.175 - - [31/Jul/2026:20:01:25 +0200] "GET /env.js HTTP/1.1" 404 30129
34.125.65.175 - - [31/Jul/2026:20:01:25 +0200] "GET /docker-compose.yml HTTP/1.1" 404 30103
34.125.65.175 - - [31/Jul/2026:20:01:25 +0200] "GET /key.json HTTP/1.1" 404 29981
34.125.65.175 - - [31/Jul/2026:20:01:32 +0200] "GET /secrets.yaml HTTP/1.1" 404 30080
34.125.65.175 - - [31/Jul/2026:20:01:32 +0200] "GET /secrets.yml HTTP/1.1" 404 29992
34.125.65.175 - - [31/Jul/2026:20:01:42 +0200] "GET /api/v0/run_sql?id=probe&sql=SELECT+1 HTTP/1.1" 404 30100
...
show less
Web Spam
Web App Attack
๐ณ๐ฑ
Savvii
2026-07-31 17:32:33
(1 day ago)
20 attempts against mh-misbehave-ban on ozone
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
BlueWire Hosting
2026-07-31 17:24:01
(1 day ago)
Probing websites for vulnerabilities
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-07-31 17:01:53
(1 day ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 27
Exploited Host
Web App Attack