๐บ๐ธ
TPI-Abuse
2026-09-01 13:57:44
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.48.65.23 (23.65.48.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.48.65.23 (23.65.48.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 09:57:37.178010 2026] [security2:error] [pid 18995:tid 18995] [client 34.48.65.23:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.hvacs-aircon.com"] [uri "/.env.backup"] [unique_id "apbZ0SvhsuHcJuw1muVY6QAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
sockominfo
2026-09-01 13:00:52
(6 hours ago)
Active Response: IP 34.48.65.23 Blocked via Firewall Drop. Threat Score: 3.8/10 (LOW). Confidence: 3 ...
show more
Active Response: IP 34.48.65.23 Blocked via Firewall Drop. Threat Score: 3.8/10 (LOW). Confidence: 30%. CVSS v3.1: 0/10 (None). CVSS Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:N. Bayesian Probability: 32%. MITRE ATT&CK: T1016 (System Network Configuration Discovery). Tactic: TA0001. Freshness: Very Fresh. Source Reputation: UNKNOWN. Methodology: CVSS 3.1 + Bayesian + Temporal + Environmental + MITRE ATT&CK + OWASP. Standards: ISO/IEC 27065:2022, NIST SP 800-30, IEEE S&P 2020. Reported by TangerangKota-CSIRT
show less
Hacking
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-09-01 12:18:51
(6 hours ago)
Try to access /.env
Web App Attack
๐ฑ๐ป
garmtech.com
2026-09-01 10:55:21
(8 hours ago)
Attempted access to sensitive endpoint (/.env.example) detected. Automated scan or unauthorized prob ...
show more
Attempted access to sensitive endpoint (/.env.example) detected. Automated scan or unauthorized probing.
show less
Web App Attack
๐ซ๐ฎ
iamxorum
2026-09-01 10:14:15
(9 hours ago)
CrowdSec: custom/insta-ban-probes
Port Scan
๐ซ๐ท
masterguru
2026-09-01 10:10:29
(9 hours ago)
URL file extension is restricted by policy. String match within ".ani/ .asa/ .asax/ .ascx/ .backup/ ...
show more
URL file extension is restricted by policy. String match within ".ani/ .asa/ .asax/ .ascx/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .compositefont/ .config/ .conf/ .crt/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dist/ .dll/ .dos/ .dpkg-dist/ .drv/ .gadget/ .hta/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .inf/ .ini/ .jse/ .key/ .licx/ .lnk/ .log/ .mdb/ .msc/ .ocx/ .old/ .pass/ .pdb/ .pfx/ .pif/ .pem/ .pol/ .prf/ .printer/ .pwd/ .rdb/ .rdp/ .reg/ .resources/ .resx/ .scr/ .sct/ .shs/ .sql/ .swp/ .sys/ .tlb/ .tmp/ .url/ .vb/ .vbe/ .vbs/ .vbproj/ .vsdisco/ .vxd/ .webinfo/ .ws/ .wsc/ .wsf/ .wsh/ .xsd/ .xsx/" at TX:extension. (920440-196)
show less
Hacking
๐บ๐ฆ
URAN Publishing Service
2026-09-01 10:07:54
(9 hours ago)
[01/Sep/2026:13:07:54 +0300] -- 34.48.65.23 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET /wp ...
show more
[01/Sep/2026:13:07:54 +0300] -- 34.48.65.23 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET /wp-config.php.bak HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐ท๐ด
clauss
2026-09-01 09:50:22
(9 hours ago)
34.48.65.23 - - [01/Sep/2026:12:50:22 +0300] "GET /actuator/configprops HTTP/2.0" 301 281 "-" "crusa ...
show more
34.48.65.23 - - [01/Sep/2026:12:50:22 +0300] "GET /actuator/configprops HTTP/2.0" 301 281 "-" "crusader-worker/1.0"
34.48.65.23 - - [01/Sep/2026:12:50:22 +0300] "GET /_ignition/health-check HTTP/2.0" 301 281 "-" "crusader-worker/1.0"
...
show less
Web App Attack
๐ซ๐ท
masterguru
2026-09-01 09:42:24
(9 hours ago)
URL file extension is restricted by policy. String match within ".ani/ .asa/ .asax/ .ascx/ .back/ .b ...
show more
URL file extension is restricted by policy. String match within ".ani/ .asa/ .asax/ .ascx/ .back/ .backup/ .bak/ .bck/ .bk/ .bkp/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .cnf/ .com/ .compositefont/ .config/ .conf/ .copy/ .crt/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dist/ .dll/ .dos/ .dpkg-dist/ .drv/ .gadget/ .hta/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .inf/ .ini/ .jks/ .jse/ .key/ .licx/ .lnk/ .log/ .mdb/ .msc/ .ocx/ .old/ .pass/ .pdb/ .pfx/ .pif/ .pem/ .pol/ .prf/ .printer/ .pwd/ .rdb/ .rdp/ .reg/ .resources/ .resx/ .sav/ .save/ .scr/ .sct/ .sh/ .shs/ .sql/ .sqlite/ .sqlite3/ .swap/ .swo/ .swp/ .sys/ .temp/ .tfstate/ .tlb/ .tmp/ .vb/ .vbe/ .vbs/ .vbproj/ .vsdisco/ .vxd/ .webinfo/ .ws/ .wsc/ .wsf/ .wsh/ .xsd/ .xsx/" at TX:extension. (920440-193)
show less
Hacking
๐ฟ๐ฆ
conure.sh
2026-09-01 09:32:34
(9 hours ago)
csagent: score 20.5: secrets grab x2, 404 noise floor x2; 1 domain(s) in 0s
Web App Attack
๐ฉ๐ช
raph
2026-09-01 09:16:03
(9 hours ago)
[Wordpress] crawler /wp-admin/*, /wp-content/*, etc.
Bad Web Bot
Web App Attack
๐ฉ๐ช
Vegascosmetics
2026-09-01 08:33:45
(10 hours ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after PHP/CMS/webshell exploit probe (possi ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after PHP/CMS/webshell exploit probe (possible exploited host). Evidence: AttackPattern: /wp-config\.php (Match: /wp-config.php)
show less
Hacking
Exploited Host
Web App Attack
๐ฌ๐ง
consul.to
2026-09-01 08:21:37
(10 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐ฎ๐น
CoreTech srl
2026-09-01 08:01:16
(11 hours ago)
[DC: IP:151.1.252.27] ntopng alert: blacklisted_server_contact
Hacking
๐ฎ๐ฉ
Burayot
2026-09-01 07:41:56
(11 hours ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 34.48.65.23 (US/United States/23.65 ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 34.48.65.23 (US/United States/23.65.48.34.bc.googleusercontent.com): 1 in the last 3600 secs
show less
Web App Attack