๐ณ๐ฑ
homeshowdomain.nl
2026-10-09 21:59:59
(1 day ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-10-08.
show less
Web App Attack
SSH
Hacking
Anonymous
2026-10-09 06:30:04
(1 day ago)
CrowdSec decision: crowdsecurity/http-admin-interface-probing (origin: crowdsec)
Web App Attack
๐ต๐ฑ
MatStef132
2026-10-09 06:02:53
(1 day ago)
MatShield L7: blocked on api.klovy.chat (suspicious behaviour)
DDoS Attack
๐ฌ๐ง
openstrike.co.uk
2026-10-09 05:15:01
(1 day ago)
143 attacks on config grabbing URLs (type 2), VC URLs, PHP URLs, directory traversals, env grabbing ...
show more
143 attacks on config grabbing URLs (type 2), VC URLs, PHP URLs, directory traversals, env grabbing URLs, shell probes, password/key grabbing URLs, env grabbing URLs (type 2):
GET /secrets.json HTTP/1.1
GET /.git/HEAD HTTP/1.1
POST /index.php?-d+allow_url_include%3don+-d+auto_prepend_file%3dphp://input HTTP/1.1
GET /..%2f..%2f.env HTTP/1.1
GET /%2e%2e/%2e%2e/%2e%2e/%2e%2e/.env HTTP/1.1
POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh HTTP/1.1
GET /__vite_rsc_findSourceMapURL?filename=file:///root/.ssh/id_rsa&environmentName=rsc HTTP/1.1
GET /%2e%2e/%2e%2e/%2e%2e/%2e%2e/proc/self/environ HTTP/1.1
show less
Hacking
Web App Attack
๐ง๐ช
taivas.nl
2026-10-09 04:32:56
(1 day ago)
Many_bad_calls
Web App Attack
๐ฉ๐ช
raph
2026-10-09 04:07:22
(1 day ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack
๐ฉ๐ช
Gwyneth Llewelyn
2026-10-09 04:04:34
(1 day ago)
34.39.183.107 - - [09/Oct/2026:05:04:32 +0100] "POST /cgi-bin/php-cgi.exe?%ADd+allow_url_include%3d1 ...
show more
34.39.183.107 - - [09/Oct/2026:05:04:32 +0100] "POST /cgi-bin/php-cgi.exe?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input HTTP/2.0" 404 994 "-" "Mozilla/5.0 (compatible; YouBot/1.0; +https://you.com/bot)"
show less
Bad Web Bot
๐บ๐ธ
JustMeHere
2026-10-09 04:02:38
(1 day ago)
[Fri Oct 09 00:02:34.085106 2026] [security2:error] [pid 1249:tid 1279] [client 34.39.183.107:57926] ...
show more
[Fri Oct 09 00:02:34.085106 2026] [security2:error] [pid 1249:tid 1279] [client 34.39.183.107:57926] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [ver "OWASP_CRS/4.15.0"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "yorknation.com"] [uri "/"] [unique_id "ashnWpGlSUsbYuhhFIApnAAAAMI"]
...
show less
Web App Attack
๐ฉ๐ช
sigurg
2026-10-09 03:39:03
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-path-traversal-probing
Web App Attack
Hacking
๐ซ๐ฎ
NoaQT
2026-10-09 03:11:22
(1 day ago)
2026-10-09T03:11:15.155149+00:00 ingress-1 haproxy[275]: 34.39.183.107:48202 [09/Oct/2026:03:11:15.1 ...
show more
2026-10-09T03:11:15.155149+00:00 ingress-1 haproxy[275]: 34.39.183.107:48202 [09/Oct/2026:03:11:15.154] https_in~ https_in/<NOSRV> 0/-1/-1/-1/0 429 225 - - PR-- 149/149/0/0/0 0/0 "GET https://mentis.si/@fs/src/.env?raw?? HTTP/2.0"
2026-10-09T03:11:15.158307+00:00 ingress-1 haproxy[275]: 34.39.183.107:48202 [09/Oct/2026:03:11:15.158] https_in~ https_in/<NOSRV> 0/-1/-1/-1/0 429 225 - - PR-- 149/149/0/0/0 0/0 "GET https://mentis.si/@fs/../.env?raw?? HTTP/2.0"
2026-10-09T03:11:15.179561+00:00 ingress-1 haproxy[275]: 34.39.183.107:48202 [09/Oct/2026:03:11:15.179] https_in~ https_in/<NOSRV> 0/-1/-1/-1/0 429 225 - - PR-- 149/149/0/0/0 0/0 "GET https://mentis.si/@fs/root/.aws/credentials?raw?? HTTP/2.0"
2026-10-09T03:11:15.887871+00:00 ingress-1 haproxy[275]: 34.39.183.107:48202 [09/Oct/2026:03:11:15.887] https_in~ https_in/<NOSRV> 0/-1/-1/-1/0 429 225 - - PR-- 150/150/0/0/0 0/0 "GET https://mentis.si/@fs/..%252f..%252f..%252f..%252f..%252froot/.env?raw?? HTTP/2.0"
2026-10-09T03:11:15.889089+0
...
show less
DDoS Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 03:08:59
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.39.183.107 (107.183.39.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.39.183.107 (107.183.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 23:08:53.762001 2026] [security2:error] [pid 28909:tid 28909] [client 34.39.183.107:53848] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mapleleaf-marketing.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mapleleaf-marketing.com"] [uri "/z9x8c7v6b5-debug-trigger-mapleleaf-marketing.com"] [unique_id "ashaxWfJro8HfQrPMkZ9UQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ต๐ฑ
lns.bz
2026-10-09 02:53:56
(1 day ago)
Web app attack [PL.Lu]
Exploited Host
Web App Attack
๐ฎ๐ฉ
Burayot
2026-10-09 02:22:30
(2 days ago)
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 34.39.183.107 (BR/Brazil/107.183.39. ...
show more
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 34.39.183.107 (BR/Brazil/107.183.39.34.bc.googleusercontent.com): 2 in the last 3600 secs
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 02:15:03
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 34.39.183.107 (107.183.39.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.39.183.107 (107.183.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 22:14:55.102929 2026] [security2:error] [pid 22427:tid 22427] [client 34.39.183.107:56300] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||koolstra.net|F|2"] [data ".key"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "koolstra.net"] [uri "/server.key"] [unique_id "ashOH8fzMYFaoS3_yappPwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-10-09 01:18:43
(2 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/grafana-cve-2021-43798
Web App Attack
Hacking