๐ณ๐ฑ
Alt255
2026-09-15 18:06:34
(3 days ago)
[ti-01ov] Web exploit scanning: 7 suspicious requests detected by fail2ban jail <name>. Example: 34. ...
show more
[ti-01ov] Web exploit scanning: 7 suspicious requests detected by fail2ban jail <name>. Example: 34.165.75.88 - - [10/Sep/2026:23:51:30 +0200] "GET /.git/config HTTP/1.1" 301 614 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.165.75.88 - - [10/Sep/2026:23:51:30 +0200] "GET /.env HTTP/1.1" 301 614 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.165.75.88 - - [10/Sep/2026:23:51:30 +0200] "GET /.env.local HTTP/1.1" 301 614 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.165.75.88 - - [10/Sep/2026:23:51:30 +0200] "GET /.env.production HTTP/1.1" 301 614 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
dot.mg
2026-09-15 08:56:02
(3 days ago)
Bad behaviour
Web Spam
๐บ๐ธ
TPI-Abuse
2026-09-15 08:13:53
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.165.75.88 (88.75.165.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.165.75.88 (88.75.165.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 04:13:49.215833 2026] [security2:error] [pid 24583:tid 24639] [client 34.165.75.88:50088] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "digitaltalkingbible.com"] [uri "/.git/config"] [unique_id "aqj-PUZJiSEMaWvWPEdvkAAAAdY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฟ๐ฆ
conure.sh
2026-09-15 08:10:40
(3 days ago)
csagent: score 20.4: secrets grab x2, 404 noise floor x2; 1 domain(s) in 2s
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 06:35:33
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.165.75.88 (88.75.165.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.165.75.88 (88.75.165.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 02:35:26.653460 2026] [security2:error] [pid 29969:tid 29969] [client 34.165.75.88:51376] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "digitalracemedia.com"] [uri "/.git/config"] [unique_id "aqjnLrmONc17xt37eUw1oAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ณ
evicky2002
2026-09-15 06:00:01
(3 days ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐ฉ๐ช
paissangroup
2026-09-15 05:41:58
(3 days ago)
Multiple WAF Violations
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-15 05:25:32
(3 days ago)
[ti-30al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-30al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 34.165.75.88 - - [15/Sep/2026:07:25:30 +0200] "GET /.git/config HTTP/1.1" 404 47304 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
๐จ๐ฆ
Anytech
2026-09-15 03:21:21
(3 days ago)
Blocked by ConnMonitor
Web App Attack
๐บ๐ธ
Victor Lรณpez
2026-09-15 03:15:51
(3 days ago)
34.165.75.88 - - [14/Sep/2026:22:15:49 -0500] "GET /mail/phpinfo.php HTTP/2.0" 404 7022 "-" "Mozilla ...
show more
34.165.75.88 - - [14/Sep/2026:22:15:49 -0500] "GET /mail/phpinfo.php HTTP/2.0" 404 7022 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.165.75.88 - - [14/Sep/2026:22:15:50 -0500] "GET /webmail/phpinfo.php HTTP/2.0" 404 7034 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
๐ณ๐ฟ
Antinson
2026-09-15 03:15:18
(3 days ago)
Scraping with a high error ratio and request rate
Bad Web Bot
๐บ๐ธ
kosada.com
2026-09-15 03:06:27
(3 days ago)
Repeated exploit attempts, for example: /.env.staging /.env (HTTP/1.1 port 443, user agent: "Mozilla ...
show more
Repeated exploit attempts, for example: /.env.staging /.env (HTTP/1.1 port 443, user agent: "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36")
show less
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-15 01:23:26
(3 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
Anonymous
2026-09-15 01:14:30
(3 days ago)
Aggressive web scan
Web App Attack
๐ธ๐ช
vaia.cloud
2026-09-14 22:35:01
(3 days ago)
crowdsecurity/http-admin-interface-probing
Brute-Force
Web App Attack