Anonymous
2026-09-19 08:07:36
(22 hours ago)
Trying to access config files
Web App Attack
๐ฎ๐ณ
evicky2002
2026-09-19 06:00:05
(1 day ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐ซ๐ท
AdminPL
2026-09-18 22:50:06
(1 day ago)
Automated malicious scan on custom CMS. Path: /info.php.bak
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-18 14:26:30
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.47.97.10 (10.97.47.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.47.97.10 (10.97.47.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 18 10:26:27.528879 2026] [security2:error] [pid 27460:tid 27460] [client 34.47.97.10:51976] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "red-jacket.com"] [uri "/.git/config"] [unique_id "aq1KE586ACrLnExgwpnaKAAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FD-IX
2026-09-18 13:53:52
(1 day ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-18 11:34:43
(1 day ago)
Excessive multi-domain requests
Brute-Force
๐ฉ๐ช
LRob
2026-09-18 08:49:28
(1 day ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.git/config (+4 more) | 2026-09-18 08:49 UTC
show less
Hacking
Web App Attack
๐ฌ๐ง
consul.to
2026-09-18 08:12:47
(1 day ago)
Web attack/malicious scanning detected
Web App Attack
๐ซ๐ท
spot
2026-09-18 07:39:31
(1 day ago)
34.47.97.10 - - [18/Sep/2026:08:39:28 +0100] "GET /.git/config HTTP/1.1" 404 607 "-" "Mozilla/5.0 (M ...
show more
34.47.97.10 - - [18/Sep/2026:08:39:28 +0100] "GET /.git/config HTTP/1.1" 404 607 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Web App Attack
Hacking
Anonymous
2026-09-18 05:53:16
(2 days ago)
34.47.97.10 - - [18/Sep/2026:07:53:09 +0200] "POST / HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Macintosh; ...
show more
34.47.97.10 - - [18/Sep/2026:07:53:09 +0200] "POST / HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.47.97.10 - - [18/Sep/2026:07:53:10 +0200] "POST / HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.47.97.10 - - [18/Sep/2026:07:53:10 +0200] "POST / HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.47.97.10 - - [18/Sep/2026:07:53:11 +0200] "GET /.git/config HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.47.97.10 - - [18/Sep/2026:07:53:11 +0200] "GET /.env HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.47.97.10
...
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-09-18 02:21:16
(2 days ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-18 01:39:54
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.47.97.10 (10.97.47.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.47.97.10 (10.97.47.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 21:39:48.040521 2026] [security2:error] [pid 3132:tid 3132] [client 34.47.97.10:41970] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "recorplast.com"] [uri "/.git/config"] [unique_id "aqyWZALPNpof3ULkujFICAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-17 22:21:56
(2 days ago)
Banned by Fail2Ban on server
Web App Attack
๐ซ๐ท
baphomet
2026-09-17 20:48:26
(2 days ago)
Probed planted web canary URI (not a real app path).
HTTP request completed against planted URIs (.e ...
show more
Probed planted web canary URI (not a real app path).
HTTP request completed against planted URIs (.env/wp-login/xmlrpc/phpmyadmin/.git).
jail=nginx-canary proto=tcp port=80,443 failures>=2 class=web-app-probe
these paths are not real apps on this host; hit is hostile recon
when=2026-09-17T20:48:26Z sensor=fail2ban role=web-canary
src=34.47.97.10
show less
Web App Attack
๐บ๐ธ
antlac1
2026-09-17 16:43:59
(2 days ago)
crowdsecurity/http-probing
Brute-Force
Web App Attack