Anonymous
2026-07-20 11:04:04
(7 hours ago)
Bot / scanning and/or hacking attempts: [18/18] read: stream 0, , GET /woningaanbod/aanbod-koop HTT ...
show more
Bot / scanning and/or hacking attempts: [18/18] read: stream 0, , GET /woningaanbod/aanbod-koop HTTP/2.0, POST /api/graphql HTTP/2.0, GET /api/graphql HTTP/2.0, GET /diensten/woning-verkopen HTTP/2.0, POST /v1/graphql HTTP/2.0, GET /admin/.env HTTP/2.0, POST /graphql HTTP/2.0, GET /.boto HTTP/2.0, GET /.env HTTP/2.0
show less
Hacking
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-07-20 09:59:44
(8 hours ago)
34.27.65.91 - - [20/Jul/2026:12:59:42 +0300] "GET /.env HTTP/1.1" 404 650 "-" "Mozilla/5.0 AppleWebK ...
show more
34.27.65.91 - - [20/Jul/2026:12:59:42 +0300] "GET /.env HTTP/1.1" 404 650 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; Claude-User/1.0; +mailto:[email protected] "
34.27.65.91 - - [20/Jul/2026:12:59:43 +0300] "GET /api/.env HTTP/1.1" 404 702 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; Claude-SearchBot/1.0; +mailto:[email protected] "
...
show less
Web App Attack
๐ฌ๐ง
Apache
2026-07-20 09:55:42
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.27.65.91 (US/United States/91.65.27.34.bc.go ...
show more
(mod_security) mod_security (id:210492) triggered by 34.27.65.91 (US/United States/91.65.27.34.bc.googleusercontent.com): 5 in the last 300 secs (CF_ENABLE)
show less
Brute-Force
Web App Attack
๐ซ๐ท
bazter.pro
2026-07-20 09:17:23
(8 hours ago)
Fail2Ban: plesk-bot-aggressive - 15 failures
Port Scan
Bad Web Bot
Web App Attack
Anonymous
2026-07-20 08:54:39
(9 hours ago)
Aggressive web scan
Web App Attack
๐ซ๐ฎ
danskefilm.dk
2026-07-20 07:00:01
(11 hours ago)
wordpress login attempts
Web App Attack
๐ฎ๐ณ
evicky2002
2026-07-20 06:00:00
(12 hours ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐ณ๐ฑ
homeshowdomain.nl
2026-07-19 22:02:23
(20 hours ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-07-18.
show less
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-07-19 07:30:56
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.27.65.91 (91.65.27.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.27.65.91 (91.65.27.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 19 03:30:48.943764 2026] [security2:error] [pid 5368:tid 5368] [client 34.27.65.91:56344] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hydrometal-js.com"] [uri "/.git/config"] [unique_id "alx9KB6GF_jcb4vAIbDzlgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-19 06:46:33
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.27.65.91 (91.65.27.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.27.65.91 (91.65.27.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 19 02:46:27.204751 2026] [security2:error] [pid 9972:tid 9972] [client 34.27.65.91:60350] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||scermak.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "scermak.com"] [uri "/z9x8c7v6b5-debug-trigger-scermak.com"] [unique_id "alxyw-dpGbLDzaK7GV_cDAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-19 06:29:28
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.27.65.91 (91.65.27.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.27.65.91 (91.65.27.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 19 02:29:21.030561 2026] [security2:error] [pid 4024237:tid 4024261] [client 34.27.65.91:36588] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dhsandberg.com"] [uri "/.env"] [unique_id "alxuwZb9RsSTo844SaePwAAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-07-19 06:25:25
(1 day ago)
URL file extension is restricted by policy. String match within ".ani/ .asa/ .asax/ .ascx/ .backup/ ...
show more
URL file extension is restricted by policy. String match within ".ani/ .asa/ .asax/ .ascx/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .compositefont/ .config/ .conf/ .crt/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dist/ .dll/ .dos/ .dpkg-dist/ .drv/ .gadget/ .hta/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .inf/ .ini/ .jse/ .key/ .licx/ .lnk/ .log/ .mdb/ .msc/ .ocx/ .old/ .pass/ .pdb/ .pfx/ .pif/ .pem/ .pol/ .prf/ .printer/ .pwd/ .rdb/ .rdp/ .reg/ .resources/ .resx/ .scr/ .sct/ .shs/ .sql/ .swp/ .sys/ .tlb/ .tmp/ .url/ .vb/ .vbe/ .vbs/ .vbproj/ .vsdisco/ .vxd/ .webinfo/ .ws/ .wsc/ .wsf/ .wsh/ .xsd/ .xsx/" at TX:extension. (920440-196)
show less
Hacking
๐บ๐ธ
mnsf
2026-07-19 06:05:10
(1 day ago)
Too many Status 40X (13)
Scanning/Probing (12)
Brute-Force
Web App Attack
๐ฌ๐ง
openstrike.co.uk
2026-07-19 05:14:06
(1 day ago)
53 attacks on PHP URLs, config grabbing URLs (type 2), VC URLs, env grabbing URLs, password grabbing ...
show more
53 attacks on PHP URLs, config grabbing URLs (type 2), VC URLs, env grabbing URLs, password grabbing URLs:
GET /configuration.php.bak HTTP/1.1
GET /config/storage.yml HTTP/1.1
GET /.git/config HTTP/1.1
GET /app/.env HTTP/1.1
GET /.aws/credentials HTTP/1.1
show less
Web App Attack
Hacking
๐ณ๐ฑ
Site.eu
2026-07-19 03:17:46
(1 day ago)
Excessive multi-domain requests
Brute-Force