π§π·
radardatelecom
2026-09-30 22:26:03
(1 day ago)
Blocked by Radar da Telecom firewall β abuseipdb
Bad Web Bot
Web App Attack
π³π±
homeshowdomain.nl
2026-09-30 22:01:31
(1 day ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-29.
show less
Web App Attack
SSH
Hacking
π¬π§
openstrike.co.uk
2026-09-30 05:14:28
(2 days ago)
228 attacks on env grabbing URLs (type 2), env grabbing URLs, directory traversals, VC URLs, PHP URL ...
show more
228 attacks on env grabbing URLs (type 2), env grabbing URLs, directory traversals, VC URLs, PHP URLs, shell probes, password/key grabbing URLs, config grabbing URLs (type 2):
GET /@fs/proc/self/environ?import&raw?? HTTP/1.1
GET /_image?href=/../../../.env HTTP/1.1
GET /..%2f..%2f.env HTTP/1.1
GET /.git/HEAD HTTP/1.1
POST /index.php?-d+allow_url_include%3don+-d+auto_prepend_file%3dphp://input HTTP/1.1
POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh HTTP/1.1
GET /id_ecdsa HTTP/1.1
GET /src/amplifyconfiguration.json HTTP/1.1
show less
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-30 04:35:09
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 34.32.151.227 (227.151.32.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.32.151.227 (227.151.32.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 00:35:04.035414 2026] [security2:error] [pid 17622:tid 17622] [client 34.32.151.227:0] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||swarnar.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "swarnar.com"] [uri "/z9x8c7v6b5-debug-trigger-swarnar.com"] [unique_id "aryReJ0HjOJzSkxgVY2t1QAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
Alt255
2026-09-30 04:20:30
(2 days ago)
[ti-07al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-07al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 34.32.151.227 - - [30/Sep/2026:06:20:19 +0200] "GET /.env.php.bak HTTP/1.1" 404 2050 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-SearchBot/1.0; [email protected] )"
...
show less
Bad Web Bot
Web App Attack
π²π½
octageeks.com
2026-09-30 04:14:04
(2 days ago)
Wordpress malicious attack:[octablocked]
Web App Attack
π³π±
Alt255
2026-09-30 03:40:54
(2 days ago)
[ti-01ov] Web exploit scanning: 1 suspicious requests detected by fail2ban jail <name>. Example: 34. ...
show more
[ti-01ov] Web exploit scanning: 1 suspicious requests detected by fail2ban jail <name>. Example: 34.32.151.227 - - \[30/Sep/2026:05:40:39 +0200\] "GET /.env HTTP/1.1" 403 502 "-" "Mozilla/5.0 \(compatible\; Meta-ExternalAgent/1.0\; +https://developers.facebook.com/docs/sharing/webmasters/crawler\)"
...
show less
Bad Web Bot
Web App Attack
π³π΄
jad-abuse
2026-09-30 03:40:34
(2 days ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: env_probe ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: env_probe, path_traversal, actuator, server_status, ignition_debug, source_backup, aws_creds, git_exposure. Observed by 1 sensor(s); 289 hits.
show less
Hacking
Web App Attack
πͺπΈ
robotstxt
2026-09-30 02:20:02
(2 days ago)
34.32.151.227 - - [30/Sep/2026:02:19:22 +0000] "GET /cgi-bin/php-cgi.exe?%ADd+allow_url_include%3d1+ ...
show more
34.32.151.227 - - [30/Sep/2026:02:19:22 +0000] "GET /cgi-bin/php-cgi.exe?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input HTTP/2.0" 404 9488 "https://surefarmproject.eu/cgi-bin/php-cgi.exe?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input" rt="0.127" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot)" "-" h="www.surefarmproject.eu" sn="www.surefarmproject.eu" ru="/cgi-bin/php-cgi.exe?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input" u="/index.php" ucs="-" ua="unix:/var/run/php/surefarmproject82.sock" us="404" uct="0.000" urt="0.127"
34.32.151.227 - - [30/Sep/2026:02:19:22 +0000] "GET /cgi-bin/php?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input HTTP/2.0" 404 9488 "https://surefarmproject.eu/cgi-bin/php?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input" rt="0.138" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" "-" h="w
...
show less
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-09-30 02:15:16
(2 days ago)
(mod_security) mod_security (id:210580) triggered by 34.32.151.227 (227.151.32.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210580) triggered by 34.32.151.227 (227.151.32.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 22:15:09.038141 2026] [security2:error] [pid 6882:tid 6882] [client 34.32.151.227:41492] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "proc/self/environ" at ARGS:apis. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/08_Global_Other.conf"] [line "57"] [id "210580"] [rev "2"] [msg "COMODO WAF: OS File Access Attempt||www.sushamalka.royal-barbershop.com|F|2"] [data "Matched Data: proc/self/environ found within ARGS:apis: ../../../../../../proc/self/environ"] [severity "CRITICAL"] [tag "CWAF"] [tag "Other"] [hostname "www.sushamalka.royal-barbershop.com"] [uri "/api/console/api_server"] [unique_id "arxwreG25bwm3P24N1jo1wAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
Hans Renses
2026-09-30 02:08:09
(2 days ago)
Web app attack: 9 requests for known vulnerable paths (.env, xmlrpc.php, web shells, config backups) ...
show more
Web app attack: 9 requests for known vulnerable paths (.env, xmlrpc.php, web shells, config backups) within one hour. Reported automatically by BotZoom.
show less
Web App Attack
Hacking
πͺπΈ
robotstxt
2026-09-30 01:35:28
(2 days ago)
34.32.151.227 - - [30/Sep/2026:01:35:02 +0000] "GET /.vite/manifest.json HTTP/2.0" 403 25475 "-" "Mo ...
show more
34.32.151.227 - - [30/Sep/2026:01:35:02 +0000] "GET /.vite/manifest.json HTTP/2.0" 403 25475 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36" "-" edge="34.32.151.227"
34.32.151.227 - - [30/Sep/2026:01:35:03 +0000] "GET //.env HTTP/2.0" 403 20 "-" "Mozilla/5.0 (compatible; xAI-Grok/1.0; +https://x.ai/)" "-" edge="34.32.151.227"
34.32.151.227 - - [30/Sep/2026:01:35:03 +0000] "GET /.//.env HTTP/2.0" 403 20 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot" "-" edge="34.32.151.227"
34.32.151.227 - - [30/Sep/2026:01:35:03 +0000] "GET /api/.env/public/.env HTTP/2.0" 403 26836 "-" "Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; +https://kimi.ai/)" "-" edge="34.32.151.227"
34.32.151.227 - - [30/Sep/2026:01:35:04 +0000] "GET /.env HTTP/2.0" 403 26841 "-" "Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; +https://kimi.ai/)" "-" edge="34.32.151.227"
...
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-30 01:18:24
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.32.151.227 (227.151.32.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.32.151.227 (227.151.32.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 21:18:21.296725 2026] [security2:error] [pid 7150:tid 7219] [client 34.32.151.227:42958] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "soluciona.biz"] [uri "/%2E%2E/%2E%2E/%2E%2E/%2E%2E/.env"] [unique_id "arxjXblud-zucnB4Ywye5gAAAQQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-30 01:06:07
(2 days ago)
Trying to access config files
Web App Attack
π«π·
masterguru
2026-09-30 00:29:19
(2 days ago)
HTTP header is restricted by policy (/x-middleware-subrequest/). String match within "/content-encod ...
show more
HTTP header is restricted by policy (/x-middleware-subrequest/). String match within "/content-encoding/ /proxy/ /lock-token/ /content-range/ /if/ /x-http-method-override/ /x-http-method/ /x-method-override/ /x-middleware-subrequest/ /expect/" at TX:header_name_920450_x-middleware-subrequest. (920450-201)
show less
Bad Web Bot