๐ฎ๐ณ
evicky2002
2026-09-17 06:00:05
(1 day ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐ฎ๐น
paoloartone
2026-09-17 05:00:20
(1 day ago)
Reverse proxy TCO: 2197 richieste malevole bloccate (scan/exploit/brute-force WordPress) il 16/09/20 ...
show more
Reverse proxy TCO: 2197 richieste malevole bloccate (scan/exploit/brute-force WordPress) il 16/09/2026.
show less
Web App Attack
Hacking
Port Scan
๐ฌ๐ง
openstrike.co.uk
2026-09-16 05:14:39
(2 days ago)
173 attacks on directory traversals, VC URLs, config grabbing URLs (type 2), env grabbing URLs, pass ...
show more
173 attacks on directory traversals, VC URLs, config grabbing URLs (type 2), env grabbing URLs, password/key grabbing URLs, PHP URLs, env grabbing URLs (type 2):
GET /..%2f..%2f.env HTTP/1.1
GET /.git/HEAD HTTP/1.1
GET /config/gcp-credentials.json HTTP/1.1
GET /_image?href=/../../../.env HTTP/1.1
GET /__vite_rsc_findSourceMapURL?filename=file:///root/.ssh/id_rsa&environmentName=rsc HTTP/1.1
POST /icecoder/lib/terminal-xhr.php HTTP/1.1
GET /_image?href=/proc/self/environ HTTP/1.1
show less
Hacking
Web App Attack
๐ฎ๐น
paoloartone
2026-09-16 05:00:25
(2 days ago)
Reverse proxy TCO: 5403 richieste malevole bloccate (scan/exploit/brute-force WordPress) il 15/09/20 ...
show more
Reverse proxy TCO: 5403 richieste malevole bloccate (scan/exploit/brute-force WordPress) il 15/09/2026.
show less
Web App Attack
Hacking
Port Scan
Anonymous
2026-09-15 15:32:29
(2 days ago)
Portscan: TCP/8080 (3x), TCP/8443 (3x)
Port Scan
๐ฎ๐ช
RoboSOC
2026-09-15 15:32:27
(2 days ago)
Langflow Unauthenticated Remote Code Execution Vulnerability, PTR: 98.184.44.34.bc.googleusercontent ...
show more
Langflow Unauthenticated Remote Code Execution Vulnerability, PTR: 98.184.44.34.bc.googleusercontent.com.
show less
Hacking
Anonymous
2026-09-15 13:45:21
(2 days ago)
Observed scanned 41 known-sensitive endpoint(s), e.g.: /.//.env, /.bashrc, /.env, /.env.bak, /.env.d ...
show more
Observed scanned 41 known-sensitive endpoint(s), e.g.: /.//.env, /.bashrc, /.env, /.env.bak, /.env.development, /.env.example
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
EvilTurkey
2026-09-15 12:23:33
(2 days ago)
Web app attack against financial institution website.
Web App Attack
Hacking
๐ณ๐ฑ
Alboweb B.V.
2026-09-15 12:11:03
(2 days ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
๐ฉ๐ช
rh24
2026-09-15 11:56:16
(2 days ago)
(badbots) Bad bot user-agent [redacted] from 34.44.184.98 (US/United States/98.184.44.34.bc.googleus ...
show more
(badbots) Bad bot user-agent [redacted] from 34.44.184.98 (US/United States/98.184.44.34.bc.googleusercontent.com)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-15 11:55:05
(2 days ago)
(mod_security) mod_security (id:210580) triggered by 34.44.184.98 (98.184.44.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210580) triggered by 34.44.184.98 (98.184.44.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 07:54:57.099639 2026] [security2:error] [pid 10957:tid 10957] [client 34.44.184.98:40130] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "proc/self/environ" at ARGS:path. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/08_Global_Other.conf"] [line "57"] [id "210580"] [rev "2"] [msg "COMODO WAF: OS File Access Attempt||sipco.cl|F|2"] [data "Matched Data: proc/self/environ found within ARGS:path: ../../../../proc/self/environ"] [severity "CRITICAL"] [tag "CWAF"] [tag "Other"] [hostname "sipco.cl"] [uri "/userfiles"] [unique_id "aqkyEbiGOP-QAYOejaVIuQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-15 11:42:26
(2 days ago)
[ns67.kdns.gr] httpd-config-scan: sites=kapaweb.gr,www.kweb.gr; logs=/var/www/vhosts/kapaweb.gr/logs ...
show more
[ns67.kdns.gr] httpd-config-scan: sites=kapaweb.gr,www.kweb.gr; logs=/var/www/vhosts/kapaweb.gr/logs/access_ssl_log,/var/www/vhosts/system/kapaweb.gr/logs/access_ssl_log,/var/www/vhosts/system/kapaweb.gr/logs/proxy_access_ssl_log; samples=/.aws/credentials | /.aws/config | /.git/config
show less
Hacking
Web App Attack
Anonymous
2026-09-15 11:40:23
(2 days ago)
Observed scanned 1 known-sensitive endpoint(s), e.g.: /.env.production
Bad Web Bot
Web App Attack
๐ฌ๐ง
Aetherweb Ark
2026-09-15 11:38:17
(2 days ago)
(mod_security) mod_security (id:949110) triggered by 34.44.184.98 (US/United States/98.184.44.34.bc. ...
show more
(mod_security) mod_security (id:949110) triggered by 34.44.184.98 (US/United States/98.184.44.34.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 11:35:57
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.44.184.98 (98.184.44.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.44.184.98 (98.184.44.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 07:35:51.405190 2026] [security2:error] [pid 26560:tid 26560] [client 34.44.184.98:38438] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "georgetownca.com"] [uri "/%2e%2e/%2e%2e/%2e%2e/%2e%2e/.env"] [unique_id "aqktl9h9ldTf--W72WE61AAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack