๐ฎ๐ณ
evicky2002
2026-07-21 06:00:00
(7 hours ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
Anonymous
2026-07-21 04:31:47
(9 hours ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
๐ฉ๐ช
macrob
2026-07-21 02:16:21
(11 hours ago)
2026/07/21 02:16:19 [error] 2087333#2087333: *394554313 access forbidden by rule, client: 34.17.69.1 ...
show more
2026/07/21 02:16:19 [error] 2087333#2087333: *394554313 access forbidden by rule, client: 34.17.69.1, server: binixo.pl, request: "GET /.aws/credentials HTTP/2.0", host: "binixo.pl", referrer: "https://api.binixo.pl/.aws/credentials"
2026/07/21 02:16:19 [error] 2087333#2087333: *394554646 access forbidden by rule, client: 34.17.69.1, server: binixo.pl, request: "GET /.aws/config HTTP/2.0", host: "binixo.pl", referrer: "https://api.binixo.pl/.aws/config"
2026/07/21 02:16:19 [error] 2087330#2087330: *394556254 access forbidden by rule, client: 34.17.69.1, server: binixo.pl, request: "GET /.env.example HTTP/2.0", host: "binixo.pl", referrer: "https://api.binixo.pl/.env.example"
...
show less
Web App Attack
๐ช๐ธ
masterguru
2026-07-21 02:01:50
(11 hours ago)
Inbound Anomaly Score Exceeded (Total Score: 5). Operator GE matched 5 at TX:anomaly_score. (949110- ...
show more
Inbound Anomaly Score Exceeded (Total Score: 5). Operator GE matched 5 at TX:anomaly_score. (949110-122)
show less
Hacking
๐ฉ๐ช
LRob
2026-07-21 01:57:55
(11 hours ago)
CrowdSec: crowdsecurity/http-probing | req: /api/settings | 11 distinct paths | UA: Mozilla/5.0 Appl ...
show more
CrowdSec: crowdsecurity/http-probing | req: /api/settings | 11 distinct paths | UA: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; OAI-SearchBot/1.0; +https://openai.com/searchbot
show less
Port Scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-21 01:56:53
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.17.69.1 (1.69.17.34.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:210492) triggered by 34.17.69.1 (1.69.17.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 21:56:45.145919 2026] [security2:error] [pid 30878:tid 30878] [client 34.17.69.1:48790] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.coloscopie.net"] [uri "/.git/config"] [unique_id "al7R3dYUjVPUK3y6s96wFQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-07-21 01:34:47
(12 hours ago)
34.17.69.1 - - [21/Jul/2026:04:34:46 +0300] "GET /.env HTTP/1.1" 404 650 "-" "Mozilla/5.0 (compatibl ...
show more
34.17.69.1 - - [21/Jul/2026:04:34:46 +0300] "GET /.env HTTP/1.1" 404 650 "-" "Mozilla/5.0 (compatible; Bytespider; [email protected] )"
...
show less
Web App Attack
๐ง๐ช
voormedia
2026-07-21 01:03:53
(12 hours ago)
Accessed trap at '/.aws/config'
Web App Attack
Anonymous
2026-07-21 01:02:00
(12 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 34.17.69.1 (IT/Italy/1.69.17.34.bc.goog ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.17.69.1 (IT/Italy/1.69.17.34.bc.googleusercontent.com)
show less
SQL Injection
๐ฌ๐ง
andypiper
2026-07-21 01:01:41
(12 hours ago)
CrowdSec ban for AbuseIPDB Top List
Brute-Force
Web App Attack
๐ฌ๐ง
Oakley
2026-07-21 00:54:21
(12 hours ago)
(confirmed_bot_sig) Confirmed bot
Hacking
Anonymous
2026-07-21 00:53:10
(12 hours ago)
Aggressive Robot or Attack DDOS
DDoS Attack
Anonymous
2026-07-21 00:14:02
(13 hours ago)
WEB attack
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-07-21 00:13:22
(13 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.17.69.1 (1.69.17.34.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:210730) triggered by 34.17.69.1 (1.69.17.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 20:13:16.784602 2026] [security2:error] [pid 3705160:tid 3705160] [client 34.17.69.1:42526] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mimrg.net|F|2"] [data ".env.backup"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mimrg.net"] [uri "/.env.backup"] [unique_id "al65nB2aaYGPKdGj9vWF6QAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ardexter
2026-07-21 00:11:00
(13 hours ago)
Wordpress attack and DDOS
DDoS Attack
Web App Attack