🇺🇸
www.winos.me
2026-09-06 09:55:54
(32 seconds ago)
Scanning for sensitive files/paths: /.env
Hacking
Web App Attack
🇨🇦
polycoda
2026-09-06 09:40:28
(15 minutes ago)
AutoBlock: 🎯 Vulnerability Scanner (Non Decay-Based) - ⚙️ Configuration File Access (Non Decay-Based ...
show more
AutoBlock: 🎯 Vulnerability Scanner (Non Decay-Based) - ⚙️ Configuration File Access (Non Decay-Based) - ❌ Excessive 40X Errors (Decay-Based)
show less
Hacking
Bad Web Bot
Web App Attack
🇳🇱
Eric
2026-09-06 09:18:03
(38 minutes ago)
[Sun Sep 06 09:18:03.164427 2026] [security2:error] [pid 672891:tid 672891] [client 34.135.35.71:0] ...
show more
[Sun Sep 06 09:18:03.164427 2026] [security2:error] [pid 672891:tid 672891] [client 34.135.35.71:0] [client 34.135.35.71] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "pop-the-slots.com"] [uri "/@fs/home/ubuntu/.aws/credentials"] [unique_id "ap0vyynsbTT1VkIBEADi3AAAAAQ"]
[Sun Sep 06 09:18:03.180285 2026] [security2:error] [pid 670655:tid 670655] [client 34.135.35.71:0] [client 34.135.35.71] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total
...
show less
Hacking
Web App Attack
Anonymous
2026-09-06 09:17:07
(39 minutes ago)
Multiple web server 400 error codes from same source ip
Web App Attack
🇪🇸
el-brujo
2026-09-06 09:09:46
(46 minutes ago)
06/Sep/2026:11:09:45.607884 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client ...
show more
06/Sep/2026:11:09:45.607884 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 34.135.35.71] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1056"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".conf"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "warzone.elhacker.net"] [uri "/rclone.conf"] [uniqu
...
show less
Hacking
Web App Attack
🇳🇱
Savvii
2026-09-06 08:53:55
(1 hour ago)
20 attempts against mh-misbehave-ban on frost
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
H24
2026-09-06 08:48:46
(1 hour ago)
/credentials.js /config.php.bak /dist../.env /api/w/admins/jobs_u/get_log_file/../../../../proc/self ...
show more
/credentials.js /config.php.bak /dist../.env /api/w/admins/jobs_u/get_log_file/../../../../proc/self/environ /@fs/.env /@fs/var/task/.env /@fs/root/.aws/credentials /.env /@fs/app/.env /api/w/default/jobs_u/get_log_file/../../../../proc/self/environ
show less
Web App Attack
🇳🇱
Savvii
2026-09-06 08:27:29
(1 hour ago)
20 attempts against mh-misbehave-ban on ozone
Brute-Force
Bad Web Bot
Web App Attack
🇦🇺
rubixstudios
2026-09-06 08:21:02
(1 hour ago)
Excessive HTTP requests consistent with automated attack behaviour detected by Imunify360
DDoS Attack
Brute-Force
Web App Attack
🇳🇱
Savvii
2026-09-06 07:56:25
(2 hours ago)
20 attempts against mh_ha-misbehave-ban on virgo
Brute-Force
Bad Web Bot
Web App Attack
🇷🇴
clauss
2026-09-06 07:31:40
(2 hours ago)
34.135.35.71 - - [06/Sep/2026:10:31:38 +0300] "GET /rclone.conf HTTP/2.0" 403 129 "-" "Mozilla/5.0 ( ...
show more
34.135.35.71 - - [06/Sep/2026:10:31:38 +0300] "GET /rclone.conf HTTP/2.0" 403 129 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36"
34.135.35.71 - - [06/Sep/2026:10:31:39 +0300] "GET /secrets.yml HTTP/2.0" 404 5226 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36"
...
show less
Web App Attack
🇺🇸
CDO
2026-09-06 07:26:26
(2 hours ago)
URL Injection attempt detected. Automated web attack.
Hacking
Bad Web Bot
Web App Attack
🇫🇷
Octopuce
2026-09-06 07:20:22
(2 hours ago)
Aggressive web search of vulnerable pages: /.env.local?raw /.env.production?raw /.env.local?import&r ...
show more
Aggressive web search of vulnerable pages: /.env.local?raw /.env.production?raw /.env.local?import&raw /.env.development?raw /.env.production?i ...
show less
Web App Attack
🇳🇱
Savvii
2026-09-06 07:03:10
(2 hours ago)
20 attempts against mh-misbehave-ban on choy
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-06 06:46:25
(3 hours ago)
34.135.35.71 - - [06/Sep/2026:08:46:16 +0200] "GET /__vite_rsc_findSourceMapURL?filename=file:///pro ...
show more
34.135.35.71 - - [06/Sep/2026:08:46:16 +0200] "GET /__vite_rsc_findSourceMapURL?filename=file:///proc/self/environ&environmentName=rsc HTTP/1.1" 404 29449
34.135.35.71 - - [06/Sep/2026:08:46:16 +0200] "GET /__vite_rsc_findSourceMapURL?filename=file:///app/.env&environmentName=rsc HTTP/1.1" 404 29449
34.135.35.71 - - [06/Sep/2026:08:46:15 +0200] "GET /z9x8c7v6b5-debug-trigger-www.crypcool.com HTTP/1.1" 404 30085
34.135.35.71 - - [06/Sep/2026:08:46:16 +0200] "GET /__vite_rsc_findSourceMapURL?filename=file:///root/.aws/credentials&environmentName=rsc HTTP/1.1" 404 29449
34.135.35.71 - - [06/Sep/2026:08:46:16 +0200] "GET /@fs/var/run/secrets/kubernetes.io/serviceaccount/ca.crt?raw?? HTTP/1.1" 404 29449
34.135.35.71 - - [06/Sep/2026:08:46:18 +0200] "GET /@fs/proc/self/cmdline?raw?? HTTP/1.1" 404 29449
34.135.35.71 - - [06/Sep/2026:08:46:18 +0200] "GET /graphql HTTP/1.1" 404 30085
34.135.35.71 - - [06/Sep/2026:08:46:19 +0200] "GET /api/fs/read?path=/app/.env&allowOutsideWorkspace=true HTTP/1
...
show less
Web Spam
Web App Attack