๐ฎ๐ณ
evicky2002
2026-09-17 06:00:05
(21 hours ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐บ๐ธ
Secure Gatewayยฎ๏ธ
2026-09-16 22:00:44
(1 day ago)
Report By Secure Gateway Security Team: SQL Injection Attempt Detected
SQL Injection
๐บ๐ธ
ALSCOยฎ๏ธ
2026-09-16 22:00:44
(1 day ago)
Report By ALSCO Security Team: Potential CSRF Attack Detected
Hacking
๐ซ๐ท
geot
2026-09-16 10:13:19
(1 day ago)
POST /mcp HTTP/1.1
GET /@fs/app/.env.production?import&raw?? HTTP/1.1
GET /api/account HTTP/1.1
GET ...
show more
POST /mcp HTTP/1.1
GET /@fs/app/.env.production?import&raw?? HTTP/1.1
GET /api/account HTTP/1.1
GET /config.json.js HTTP/1.1
GET /.env.prod.bak HTTP/1.1
GET /.env.production?import&raw HTTP/1.1
GET /trace.axd HTTP/1.1
GET /userfiles/x?path=../../.env HTTP/1.1
GET /.well-known/jwks.json HTTP/1.1
GET /production/.env HTTP/1.1
GET /core/.env HTTP/1.1
show less
Hacking
Web App Attack
Anonymous
2026-09-16 06:51:49
(1 day ago)
malicious scanning tool activity
Web App Attack
๐ซ๐ท
dynamix
2026-09-16 05:59:23
(1 day ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 05:22:17
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.16.31.84 (84.31.16.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.16.31.84 (84.31.16.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 01:22:10.242098 2026] [security2:error] [pid 24531:tid 24546] [client 34.16.31.84:52928] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "workconfident.com"] [uri "/@fs/.env"] [unique_id "aqongiyOA_Qv5vtcCghDGwAAAM0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
WizardsToolkit
2026-09-16 05:21:38
(1 day ago)
tried to access forbidden files; attempted to access /@fs/app/.env?import&raw??
Web App Attack
๐ง๐ฌ
HighWay
2026-09-16 05:04:00
(1 day ago)
34.16.31.84 - - [16/Sep/2026:05:03:55 +0000] "POST /graphql HTTP/1.1" 404 770 "https://vhelectronics ...
show more
34.16.31.84 - - [16/Sep/2026:05:03:55 +0000] "POST /graphql HTTP/1.1" 404 770 "https://vhelectronics.com" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
34.16.31.84 - - [16/Sep/2026:05:03:55 +0000] "POST /api/graphql HTTP/1.1" 404 770 "https://vhelectronics.com" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
34.16.31.84 - - [16/Sep/2026:05:03:55 +0000] "GET /account/login HTTP/1.1" 404 4757 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
34.16.31.84 - - [16/Sep/2026:05:03:55 +0000] "GET /config/env/aws_credentials.env HTTP/1.1" 404 4758 "-" "Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; +https://kimi.ai/)"
34.16.31.84 - - [16/Sep/2026:05:03:55 +0000] "GET /login HTTP/1.1" 404 4756 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safa
...
show less
Bad Web Bot
Web App Attack
๐ฟ๐ฆ
vanderhost
2026-09-16 05:00:46
(1 day ago)
[Laravel HoneypotPlus] Automated report - Honeypot access detected on path: /config/env/aws_credenti ...
show more
[Laravel HoneypotPlus] Automated report - Honeypot access detected on path: /config/env/aws_credentials.env via rule: /config
show less
Web App Attack
Bad Web Bot
๐ซ๐ท
PacketFilter
2026-09-16 04:47:52
(1 day ago)
Fail2Ban
Hacking
Web App Attack
๐ฉ๐ฐ
HostingGroup
2026-09-16 04:36:54
(1 day ago)
Automated malicious activity (Honeypot Trap) detected and blocked at the CDN edge by NordicCDN Shiel ...
show more
Automated malicious activity (Honeypot Trap) detected and blocked at the CDN edge by NordicCDN Shield. Offenses: 6. First blocked: 2026-09-16.
show less
Bad Web Bot
Web App Attack
๐ซ๐ฎ
paissangroup
2026-09-16 03:55:52
(1 day ago)
Multiple WAF Violations
Web App Attack
Anonymous
2026-09-16 03:28:34
(1 day ago)
2026/09/16 03:28:33 [error] 4746#4746: *5 [client 34.16.31.84] ModSecurity: Access denied with code ...
show more
2026/09/16 03:28:33 [error] 4746#4746: *5 [client 34.16.31.84] ModSecurity: Access denied with code 403 (phase 2). Matched "Operator `Ge' with parameter `5' against variable `TX:BLOCKING_INBOUND_ANOMALY_SCORE' (Value: `5' ) [file "/usr/local/owasp-modsecurity-crs-4.11.0/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "222"] [id "949110"] [rev ""] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [data ""] [severity "0"] [ver "OWASP_CRS/4.29.0"] [maturity "0"] [accuracy "0"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "logiciensoft.com"] [uri "/settings/.env"] [unique_id "178952931344.833083"] [ref ""], client: 34.16.31.84, server: logiciensoft.com, request: "GET /settings%2F.env HTTP/2.0", host: "logiciensoft.com"
2026/09/16 03:28:33 [error] 4746#4746: *5 [client 34.16.31.84] ModSecurity: Access denied with code 403 (phase 2). Matched "Operator `Ge' with parameter `5' against variable `TX:BLOCKING_INBOUND_ANOMALY_SCORE' (Value: `5' ) [file "/usr/local/owasp-modsecurity-cr
...
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-16 03:17:00
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.16.31.84 (84.31.16.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.16.31.84 (84.31.16.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 23:16:53.032264 2026] [security2:error] [pid 4220:tid 4220] [client 34.16.31.84:46692] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||keystroke.info|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "keystroke.info"] [uri "/rclone.conf"] [unique_id "aqoKJWaGv_zDnugFIev8ygAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack