๐ณ๐ฑ
Mr. Sky
2026-08-31 03:07:46
(3 days ago)
Inbound malicious web activity detected and blocked by perimeter IDS/IPS.
Observed 1 blocked IDS/IP ...
show more
Inbound malicious web activity detected and blocked by perimeter IDS/IPS.
Observed 1 blocked IDS/IPS event.
Observed IDS/IPS evidence:
- ET WEB_SERVER Tilde in URI - potential .php~ source disclosure vulnerability
Target service: HTTP / TCP port 80
Severity: 9/10
First seen: 2026-08-30T02:51:30.795Z
Last seen: 2026-08-30T02:51:30.795Z
show less
Web App Attack
๐ณ๐ฑ
Mr. Sky
2026-08-30 03:07:42
(4 days ago)
Laravel application probing detected against a public web server.
15 suspicious requests
13 critica ...
show more
Laravel application probing detected against a public web server.
15 suspicious requests
13 critical requests
Observed requests:
GET /wp-config.php.swp
GET /wp-config.php~
GET /wp-config.php.bak
GET /storage/logs/laravel.log
GET /_ignition/health-check
Risk level: CRITICAL
Reference: STI-20260830-050742-34-58-194-160
show less
Web App Attack
๐จ๐ณ
PrivateLiu
2026-08-30 01:51:01
(4 days ago)
[AbuseIPDB auto-report] Rules: Rule2, Rule5. Region: non-CN. Broad path scanning: 9 x 404/403 respon ...
show more
[AbuseIPDB auto-report] Rules: Rule2, Rule5. Region: non-CN. Broad path scanning: 9 x 404/403 responses in short window indicating automated scanner; Known vulnerability path probing: targeting CMS (WordPress/Drupal), phpMyAdmin, actuator endpoints, or other known vulnerable paths. Sample paths: /storage/logs/laravel.log, /wp-config.php~, /crusader-404-probe, /wp-config.php.swp, /wp-config.php.bak, /env, /actuator/env, /actuator/configprops, /_ignition/health-check. Statuses: 404. Methods: GET. UA: N/A
show less
Port Scan
Web App Attack
๐ฉ๐ช
ecs.ge
2026-08-30 01:07:14
(4 days ago)
Automatic Fail2Ban report from jail plesk-modsecurity: multiple matching events detected.
Web App Attack
Hacking
๐ณ๐ฑ
homeshowdomain.nl
2026-08-29 22:01:23
(4 days ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-08-28.
show less
Web App Attack
SSH
Hacking
๐ฒ๐พ
Rizzy
2026-08-29 03:41:57
(5 days ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐บ๐ธ
factor1
2026-08-29 02:31:42
(5 days ago)
CrowdSec at atlas Reports Abuse
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 02:22:47
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 34.58.194.160 (160.194.58.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.58.194.160 (160.194.58.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 22:22:41.689560 2026] [security2:error] [pid 31921:tid 31921] [client 34.58.194.160:44768] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "1derfulwaysrv.com"] [uri "/.env"] [unique_id "apJCcU70GTRqlaaHYJIB2wAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-29 02:20:38
(5 days ago)
Web App Attack
Brute-Force
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 01:57:38
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 34.58.194.160 (160.194.58.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.58.194.160 (160.194.58.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 21:57:32.485336 2026] [security2:error] [pid 17780:tid 17780] [client 34.58.194.160:37150] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.rvtrips.robin5on.com"] [uri "/wp-config.php~"] [unique_id "apI8jKGIVqLc1z6pkNLGOQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
niedson
2026-08-29 01:30:02
(5 days ago)
Automated scanning for exposed secrets: repeated requests for multiple distinct credential paths (.e ...
show more
Automated scanning for exposed secrets: repeated requests for multiple distinct credential paths (.env variants, .git metadata, .ssh private keys, .aws/credentials). Unsolicited. Reported automatically.
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 01:09:33
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 34.58.194.160 (160.194.58.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.58.194.160 (160.194.58.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 21:09:29.093545 2026] [security2:error] [pid 4711:tid 4711] [client 34.58.194.160:58626] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.custominktees.postermodelsworldwideinc.com"] [uri "/.env.bak"] [unique_id "apIxSfwEYULvGHFJ7wBv2gAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
2000cn.com.au
2026-08-29 00:30:27
(5 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐ฉ๐ช
Philister11
2026-08-29 00:18:35
(5 days ago)
CrowdSec: crowdsecurity/http-probing (US/AS396982)
Web App Attack
Hacking
๐จ๐ญ
Ribeye375
2026-08-29 00:10:10
(5 days ago)
HIPS web-exfiltration - Block tcp/0:65535
Web App Attack