🇮🇳
evicky2002
2026-09-11 00:06:53
(2 days ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
🇬🇧
openstrike.co.uk
2026-09-10 05:13:32
(3 days ago)
251 attacks on PHP URLs, VC URLs, env grabbing URLs, config grabbing URLs (type 2):
GET /includes/ph ...
show more
251 attacks on PHP URLs, VC URLs, env grabbing URLs, config grabbing URLs (type 2):
GET /includes/phpinfo.php HTTP/1.1
GET /.git/config HTTP/1.1
GET /config/app/.env HTTP/1.1
GET /application_default_credentials.json HTTP/1.1
show less
Web App Attack
Hacking
🇩🇪
Hary74656
2026-09-09 21:32:54
(3 days ago)
Fail2Ban on schani.hostmi.at: jail=apache-modsecurity, failures=3. No raw log data included.
Web App Attack
🇺🇸
gamabe
2026-09-09 21:07:14
(3 days ago)
Detected crowdsecurity/http-sensitive-files attack pattern. Reported by CrowdSec IDS.
Hacking
🇨🇦
Not Fake
2026-09-09 15:25:56
(4 days ago)
$f2bV_matches
Web App Attack
🇺🇸
zwebvigil
2026-09-09 09:52:51
(4 days ago)
34.18.178.190 [09/Sep/2026:02:52:49 -0700] "GET /.git/config HTTP/1.1" 404 196 "-" port=53166 "Mozi ...
show more
34.18.178.190 [09/Sep/2026:02:52:49 -0700] "GET /.git/config HTTP/1.1" 404 196 "-" port=53166 "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-" "-" "img.<host>" 367
34.18.178.190 [09/Sep/2026:02:52:50 -0700] "GET /.env HTTP/1.1" 404 196 "-" port=53166 "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-" "-" "img.<host>" 394
34.18.178.190 [09/Sep/2026:02:52:50 -0700] "GET /.env.local HTTP/1.1" 404 196 "-" port=53166 "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-" "-" "img.<host>" 358
34.18.178.190 [09/Sep/2026:02:52:50 -0700] "GET /.env.production HTTP/1.1" 404 196 "-" port=53166 "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-" "-" "img.<host>" 263
34.18.178.190 [09/Sep/2026:02:5
show less
Web App Attack
Anonymous
2026-09-09 04:12:50
(4 days ago)
[server.tmg.gr] httpd-config-scan: sites=www.imeresd.gr; logs=/var/log/httpd/domains/imeresd.gr.log; ...
show more
[server.tmg.gr] httpd-config-scan: sites=www.imeresd.gr; logs=/var/log/httpd/domains/imeresd.gr.log; samples=/.git/config | /.env | /.env.local
show less
Hacking
Web App Attack
🇨🇭
🇨🇭 Hosting
2026-09-08 05:10:28
(5 days ago)
Automated WAF report: 200-300 blocked requests from this IP detected by our WAF.
Bad Web Bot
Web App Attack
🇳🇱
e.fierstra
2026-09-07 22:37:50
(5 days ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 18:22:03
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 34.18.178.190 (190.178.18.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.18.178.190 (190.178.18.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 14:21:57.192558 2026] [security2:error] [pid 18104:tid 18104] [client 34.18.178.190:52366] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hilltopfound.com"] [uri "/.git/config"] [unique_id "ap8Axf045iu-_Z2qIev8JAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 16:25:20
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 34.18.178.190 (190.178.18.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.18.178.190 (190.178.18.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 12:25:14.578754 2026] [security2:error] [pid 15564:tid 15564] [client 34.18.178.190:39116] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hillerhome.com"] [uri "/.git/config"] [unique_id "ap7lalIUIbvbTYTyROJBYAAAAG8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 15:49:16
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 34.18.178.190 (190.178.18.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.18.178.190 (190.178.18.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 11:49:10.655493 2026] [security2:error] [pid 22229:tid 22229] [client 34.18.178.190:51858] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hillconsultants.alhill.com"] [uri "/.git/config"] [unique_id "ap7c9v_H4Pv6cnPGy8rTnAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Site.eu
2026-09-07 14:54:16
(6 days ago)
Excessive multi-domain requests
Brute-Force
🇧🇪
cmbplf
2026-09-07 14:11:31
(6 days ago)
12.887 4xx requests in 1 hour (2w3d5m)
Brute-Force
Bad Web Bot
🇩🇪
MSC IT for Business GmbH
2026-09-07 13:50:09
(6 days ago)
GASTO/CrowdSec: gasto/modsec-critical triggered (via crowdsec-agent, categories 15,21)
Hacking
Web App Attack