🇮🇳
evicky2002
2026-09-10 06:00:02
(1 day ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
🇬🇧
openstrike.co.uk
2026-09-09 05:14:37
(2 days ago)
106 attacks on password/key grabbing URLs, config grabbing URLs (type 2), VC URLs, PHP URLs, env gra ...
show more
106 attacks on password/key grabbing URLs, config grabbing URLs (type 2), VC URLs, PHP URLs, env grabbing URLs, env grabbing URLs (type 2):
GET /id_ed25519 HTTP/1.1
GET /auth.json HTTP/1.1
GET /.git/config HTTP/1.1
GET /wp-config.php.old HTTP/1.1
GET /.hermes/.env HTTP/1.1
GET /@fs/proc/self/cwd/.config/gcloud/application_default_credentials.json?raw?? HTTP/1.1
show less
Hacking
Web App Attack
🇧🇪
taivas.nl
2026-09-09 04:32:58
(2 days ago)
Many_bad_calls
Web App Attack
🇧🇪
cmbplf
2026-09-08 21:39:27
(3 days ago)
155 requests with url.path *.ssh/*
Brute-Force
Bad Web Bot
🇫🇷
dynamix
2026-09-08 20:27:12
(3 days ago)
Multiple WAF Violations
Web App Attack
🇪🇸
pipeline.es
2026-09-08 20:09:00
(3 days ago)
Web scanning / probing for vulnerable paths | URL: /@fs/usr/src/app/.env?raw?? | Evidence: flytravel ...
show more
Web scanning / probing for vulnerable paths | URL: /@fs/usr/src/app/.env?raw?? | Evidence: flytravel.pt 34.180.123.199 - - [08/Sep/2026:22:08:04 +0200] \"GET /@fs/usr/src/app/.env?raw?? HTTP/1.1\" 404 20982 \"-\" \"Mozilla/5.0 (Windows NT 10.0; rv:150.16) Gecko/20100101 Firefox/150.16; compatible; GPTBot/1.4; +https://openai.com/gptbot\" GEOIP_COUNTRY_CODE=JP | ASN: GOOGLE-CLOUD-PLATFORM | Country: JP
show less
Port Scan
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 20:00:48
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.180.123.199 (199.123.180.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.180.123.199 (199.123.180.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 16:00:43.351518 2026] [security2:error] [pid 4164218:tid 4164218] [client 34.180.123.199:24464] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "transport.ic1.biz"] [uri "/@fs/src/.env"] [unique_id "aqBpa4kLKUWiMZ52IJdw1QAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 19:27:33
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.180.123.199 (199.123.180.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.180.123.199 (199.123.180.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 15:27:28.108892 2026] [security2:error] [pid 25903:tid 25903] [client 34.180.123.199:2710] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.boardinjapan.com"] [uri "/@fs/root/.env"] [unique_id "aqBhoMMZNYIHFQcxllVL_QAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Savvii
2026-09-08 19:17:13
(3 days ago)
20 attempts against mh-misbehave-ban on redirect
Brute-Force
Bad Web Bot
Web App Attack
🇿🇦
conure.sh
2026-09-08 19:05:45
(3 days ago)
csagent: score 19.9: secrets grab x2; 1 domain(s) in 10s
Web App Attack
Anonymous
2026-09-08 18:51:01
(3 days ago)
suspicious behavior
Blog Spam
Brute-Force
Web App Attack
🇨🇭
zynex
2026-09-08 17:51:02
(3 days ago)
URL Probing: /@fs/.env
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 17:44:58
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.180.123.199 (199.123.180.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.180.123.199 (199.123.180.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 13:44:52.974098 2026] [security2:error] [pid 4452:tid 4452] [client 34.180.123.199:39134] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.gotmaple.com"] [uri "/@fs/.env"] [unique_id "aqBJlKlqotuNSopviFzF7AAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-09-08 17:44:26
(3 days ago)
Web attack/malicious scanning detected
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 17:29:12
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.180.123.199 (199.123.180.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.180.123.199 (199.123.180.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 13:29:07.828917 2026] [security2:error] [pid 24740:tid 24740] [client 34.180.123.199:27124] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.belgiophar.com"] [uri "/@fs/root/.env"] [unique_id "aqBF40F5bXSXxNbbksK-IQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack