🇮🇳
evicky2002
2026-09-08 00:01:54
(1 hour ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
🇬🇧
openstrike.co.uk
2026-09-07 05:13:48
(20 hours ago)
105 attacks on env grabbing URLs, password grabbing URLs, env grabbing URLs (type 2), PHP URLs, conf ...
show more
105 attacks on env grabbing URLs, password grabbing URLs, env grabbing URLs (type 2), PHP URLs, config grabbing URLs (type 2), VC URLs:
GET /static//app/.env HTTP/1.1
GET /.aws/credentials HTTP/1.1
GET /_image?href=/proc/self/environ HTTP/1.1
GET /wp-config.php.swp HTTP/1.1
GET /secrets.yml HTTP/1.1
GET /.git/HEAD HTTP/1.1
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 03:33:22
(21 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.138.169.178 (178.169.138.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 34.138.169.178 (178.169.138.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 23:33:17.659507 2026] [security2:error] [pid 28388:tid 28388] [client 34.138.169.178:45886] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||intersession.net|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "intersession.net"] [uri "/rclone.conf"] [unique_id "ap4wfUyylOU40g7tYOlhNQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
mnsf
2026-09-07 01:05:29
(1 day ago)
Too many Status 40X (21)
Scanning/Probing (14)
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 00:48:35
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.138.169.178 (178.169.138.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 34.138.169.178 (178.169.138.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 20:48:29.266247 2026] [security2:error] [pid 21561:tid 21561] [client 34.138.169.178:56010] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.nealschonsautographedguitars.com|F|2"] [data ".key"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.nealschonsautographedguitars.com"] [uri "/localhost.key"] [unique_id "ap4J3Tt_5yGuJib-Qu1IZQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
hghosting
2026-09-06 23:32:02
(1 day ago)
CrowdSec auto-report: crowdsecurity/http-probing — 11 events
Brute-Force
SSH
🇺🇸
TPI-Abuse
2026-09-06 22:50:08
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.138.169.178 (178.169.138.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 34.138.169.178 (178.169.138.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 18:50:03.510783 2026] [security2:error] [pid 30550:tid 30550] [client 34.138.169.178:48542] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||auracb.es|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "auracb.es"] [uri "/rclone.conf"] [unique_id "ap3uGy0Ro-7WwIlsp-Q-FAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Site.eu
2026-09-06 22:48:12
(1 day ago)
Excessive multi-domain requests
Brute-Force
🇺🇸
Sockets-AR
2026-09-06 22:33:02
(1 day ago)
CrowdSec: sensitive file probing detected (crowdsecurity/http-sensitive-files) at 2026-09-06T22:33:0 ...
show more
CrowdSec: sensitive file probing detected (crowdsecurity/http-sensitive-files) at 2026-09-06T22:33:02.088Z
show less
Web App Attack
🇫🇷
Baking333
2026-09-06 22:15:06
(1 day ago)
[redacted] 34.138.169.178 - - [06/Sep/2026:23:15:03 +0100] "GET /.[redacted] HTTP/1.1" 302 1538 0/10 ...
show more
[redacted] 34.138.169.178 - - [06/Sep/2026:23:15:03 +0100] "GET /.[redacted] HTTP/1.1" 302 1538 0/103173 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-SearchBot/1.0; +claudebot@[redacted])" [redacted] 34.138.169.178 - - [06/Sep/2026:23:15:03 +0100] "GET /.[redacted] HTTP/1.1" 302 1537 0/281911 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perplexity-User/1.0; +https://[redacted]/perplexitybot)"
show less
Bad Web Bot
Web App Attack
🇳🇱
Savvii
2026-09-06 21:21:11
(1 day ago)
20 attempts against mh-misbehave-ban on choy
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-06 20:58:48
(1 day ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
🇦🇺
rubixstudios
2026-09-06 20:32:02
(1 day ago)
Excessive HTTP requests consistent with automated attack behaviour detected by Imunify360
DDoS Attack
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 20:19:20
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.138.169.178 (178.169.138.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 34.138.169.178 (178.169.138.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 16:19:13.068133 2026] [security2:error] [pid 1298770:tid 1298871] [client 34.138.169.178:56234] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||starlinksales.net|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "starlinksales.net"] [uri "/rclone.conf"] [unique_id "ap3KwZUjPXe-IK_tUmB5rQAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
XICTRON
2026-09-06 20:05:09
(1 day ago)
ModSecurity rule violation detected by Fail2Ban
Web App Attack