๐ฎ๐ฑ
spd.co.il
2026-08-29 18:03:06
(2 days ago)
Web application attack detected
Hacking
Web App Attack
๐ฎ๐ณ
evicky2002
2026-08-29 00:00:42
(3 days ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐ฉ๐ช
london2038.com
2026-08-27 23:11:47
(4 days ago)
Malformed or malicious web request
34.244.67.108 - - [28/Aug/2026:01:11:44 +0200] "POST /graphql HTT ...
show more
Malformed or malicious web request
34.244.67.108 - - [28/Aug/2026:01:11:44 +0200] "POST /graphql HTTP/2.0" 404 12697 "https://forum.<REDACTED>" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/148.0.0.0 Safari/537.36"
show less
Hacking
Web App Attack
๐ณ๐ฑ
BlueWire Hosting
2026-08-27 23:09:07
(4 days ago)
High-confidence malicious configuration/VCS probe
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 20:31:25
(4 days ago)
(mod_security) mod_security (id:210730) triggered by 34.244.67.108 (ec2-34-244-67-108.eu-west-1.comp ...
show more
(mod_security) mod_security (id:210730) triggered by 34.244.67.108 (ec2-34-244-67-108.eu-west-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 16:31:20.727595 2026] [security2:error] [pid 29723:tid 29723] [client 34.244.67.108:59346] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||marxistphilosophy.org|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "marxistphilosophy.org"] [uri "/rclone.conf"] [unique_id "apCemEXDNB61w4aDwStUFgAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ญ๐ท
bubausluge
2026-08-27 19:46:15
(4 days ago)
Blocked by https://aegis.hr โ Aegis Single-Hit โ Gibberish URL probe - (MITRE T1595.003), 1 attempts ...
show more
Blocked by https://aegis.hr โ Aegis Single-Hit โ Gibberish URL probe - (MITRE T1595.003), 1 attempts, Period: 2026-08-27 19:28:46 to 2026-08-27 19:28:46
show less
Port Scan
๐ง๐ท
Peregrine
2026-08-27 18:00:04
(4 days ago)
Fail2Ban Jail: tomcat-404 | Evidence: 34.244.67.108 162.158.38.64 - - [27/Aug/2026:14:59:57 -0300] " ...
show more
Fail2Ban Jail: tomcat-404 | Evidence: 34.244.67.108 162.158.38.64 - - [27/Aug/2026:14:59:57 -0300] "GET /manifest.json HTTP/1.1" 404 414
34.244.67.108 162.158.38.65 - - [27/Aug/2026:14:59:57 -0300] "GET /webpack-stats.json HTTP/1.1" 404 414
34.244.67.108 162.158.38.64 - - [27/Aug/2026:14:59:57 -0300] "GET /static/manifest.json HTTP/1.1" 404 414
34.244.67.108 162.158.38.64 - - [27/Aug/2026:14:59:57 -0300] "GET /dist/manifest.json HTTP/1.1" 404 414
34.244.67.108 162.158.38.65 - - [27/Aug/2026:14:59:57 -0300] "GET /assets/manifest.json HTTP/1.1" 404 414
34.244.67.108 162.158.38.65 - - [27/Aug/2026:14:59:57 -0300] "GET /asset-manifest.json HTTP/1.1" 404 414
34.244.67.108 162.158.38.64 - - [27/Aug/2026:14:59:57 -0300] "POST /graphql HTTP/1.1" 404 414
34.244.67.108 162.158.38.65 - - [27/Aug/2026:15:00:02 -0300] "POST /v1/graphql HTTP/1.1" 404 414
show less
Bad Web Bot
Web App Attack
๐ซ๐ท
Octopuce
2026-08-27 17:37:45
(4 days ago)
Aggressive web search of vulnerable pages: /.env /.env.local /api/.env /config/.env /admin/.env ...
Web App Attack
Anonymous
2026-08-27 15:34:03
(4 days ago)
Bot / scanning and/or hacking attempts: GET /config/.env HTTP/2.0, GET /.env.local HTTP/2.0, GET /se ...
show more
Bot / scanning and/or hacking attempts: GET /config/.env HTTP/2.0, GET /.env.local HTTP/2.0, GET /secrets.json HTTP/2.0, GET /auto-onderhoud/aircoservice-en-onderhoud HTTP/2.0, GET /secrets.yml HTTP/2.0
show less
Hacking
Web App Attack
๐ง๐ช
taivas.nl
2026-08-27 15:32:11
(4 days ago)
Site scraper
Web App Attack
๐ต๐ฑ
sefinek.net
2026-08-27 15:16:49
(4 days ago)
Triggered Cloudflare WAF (firewallCustom) from IE.
Action: BLOCK | Protocol: HTTP/2 (GET) | Endpoint ...
show more
Triggered Cloudflare WAF (firewallCustom) from IE.
Action: BLOCK | Protocol: HTTP/2 (GET) | Endpoint: /.openclaw/.env | UA: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; OAI-SearchBot/1.0; +https://openai.com/searchbot โข Generated by: github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
Anonymous
2026-08-27 14:40:03
(4 days ago)
| Suspicious URL access.
Web App Attack
Hacking
SQL Injection
๐ฉ๐ช
Inamin
2026-08-27 13:57:40
(4 days ago)
34.244.67.108 - - [27/Aug/2026:19:23:37 +0800] "GET /admin HTTP/2.0" 404 50978 "-" "Mozilla/5.0 (Win ...
show more
34.244.67.108 - - [27/Aug/2026:19:23:37 +0800] "GET /admin HTTP/2.0" 404 50978 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Safari/537.36"
34.244.67.108 - - [27/Aug/2026:21:57:40 +0800] "GET /login HTTP/2.0" 404 555 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Safari/537.36"
...
show less
Hacking
Bad Web Bot
Web App Attack
Anonymous
2026-08-27 13:04:07
(4 days ago)
[ns65.kdns.gr] httpd-config-scan: sites=www.digitalproject.gr; logs=/var/log/httpd/domains/digitalpr ...
show more
[ns65.kdns.gr] httpd-config-scan: sites=www.digitalproject.gr; logs=/var/log/httpd/domains/digitalproject.gr.log; samples=/.aws/config | /.git/HEAD | /.aws/credentials
show less
Hacking
Web App Attack
๐ง๐ช
voormedia
2026-08-27 12:55:16
(4 days ago)
Accessed trap at '/.aws/credentials'
Web App Attack