๐ณ๐ฑ
e.fierstra
2026-09-16 06:53:25
(5 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐ธ๐ฌ
Cloudkul Cloudkul
2026-09-16 06:21:07
(5 hours ago)
Attempted Not Found (404 status code) requests on our application, more than 30% of their total requ ...
show more
Attempted Not Found (404 status code) requests on our application, more than 30% of their total requests.
show less
Brute-Force
Web App Attack
๐ฉ๐ฐ
HostingGroup
2026-09-16 05:31:54
(6 hours ago)
Automated malicious activity (Honeypot Trap) detected and blocked at the CDN edge by NordicCDN Shiel ...
show more
Automated malicious activity (Honeypot Trap) detected and blocked at the CDN edge by NordicCDN Shield. Offenses: 7. First blocked: 2026-09-16.
show less
Bad Web Bot
Web App Attack
๐ง๐ท
dominioz
2026-09-16 05:30:37
(6 hours ago)
2026-09-16 05:30:22 GET /.env - - 34.59.20.78 HTTP/2 Mozilla/5.0+AppleWebKit/537.36+(KHTML,+like+Gec ...
show more
2026-09-16 05:30:22 GET /.env - - 34.59.20.78 HTTP/2 Mozilla/5.0+AppleWebKit/537.36+(KHTML,+like+Gecko;+compatible;+GPTBot/1.3;++https://openai.com/gptbot) - 301 530
2026-09-16 05:30:23 GET /.env import&raw - 34.59.20.78 HTTP/2 Mozilla/5.0+AppleWebKit/537.36+(KHTML,+like+Gecko;+compatible;+Claude-User/1.0;[email protected] ) - 301 556
2026-09-16 05:30:23 GET /.env import&url&inline - 34.59.20.78 HTTP/2 Mozilla/5.0+(compatible;+xAI-Grok/1.0;++https://x.ai/) - 301 574
2026-09-16 05:30:23 GET /.env.local raw - 34.59.20.78 HTTP/2 CCBot/2.0+(https://commoncrawl.org/faq/) - 301 550
2026-09-16 05:30:23 GET /.env.production raw - 34.59.20.78 HTTP/2 Mozilla/5.0+(compatible;+Qwenbot/1.0;++https://qwen.alibaba.com/) - 301 560
2026-09-16 05:30:23 GET /.env.local import&raw - 34.59.20.78 HTTP/2 Mozilla/5.0+(compatible;+xAI-Grok/1.0;++https://x.ai/) - 301 568
2026-09-16 05:30:23 GET /.env raw - 34.59.20.78 HTTP/2 Mozilla/5.0+AppleWebKit/537.36+(KHTML,+like+Gecko;+compatible;+OAI-SearchBot/1.0
...
show less
Web App Attack
๐บ๐ธ
jormaster3k
2026-09-16 05:04:04
(6 hours ago)
Attack against Apache (too many 404s)
Web App Attack
๐บ๐ธ
lime
2026-09-16 04:54:51
(7 hours ago)
34.59.20.78 - - [16/Sep/2026:04:54:51 +0000] "GET /@fs/var/run/secrets/kubernetes.io/serviceaccount/ ...
show more
34.59.20.78 - - [16/Sep/2026:04:54:51 +0000] "GET /@fs/var/run/secrets/kubernetes.io/serviceaccount/token?raw?? HTTP/1.1" 404 466 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
show less
Hacking
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-16 03:37:29
(8 hours ago)
Excessive multi-domain requests
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-16 03:23:33
(8 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.59.20.78 (78.20.59.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.59.20.78 (78.20.59.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 23:23:28.361306 2026] [security2:error] [pid 29289:tid 29322] [client 34.59.20.78:43422] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||jd-web-designs.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "jd-web-designs.com"] [uri "/z9x8c7v6b5-debug-trigger-jd-web-designs.com"] [unique_id "aqoLsCag_cjWayyFR7f-6AAAAVE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-16 02:49:12
(9 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-cve-2021-41773
Web App Attack
Hacking
๐บ๐ธ
interbiznw.com
2026-09-16 02:34:56
(9 hours ago)
malicious-web-requests-vulnerability-scanning
Hacking
Brute-Force
Exploited Host
Web App Attack
๐บ๐ธ
WizardsToolkit
2026-09-16 02:02:17
(9 hours ago)
tried to access forbidden files; attempted to access /@fs/app/.env?raw??
Web App Attack
๐ซ๐ท
Catalin Negru
2026-09-16 01:57:01
(10 hours ago)
2026-09-16 04:56:45,973 fail2ban.actions [736]: NOTICE [apache-security] Ban 34.59.20.78
202 ...
show more
2026-09-16 04:56:45,973 fail2ban.actions [736]: NOTICE [apache-security] Ban 34.59.20.78
2026-09-16 04:56:46,165 fail2ban.actions [736]: NOTICE [apache-404] Ban 34.59.20.78
2026-09-16 04:56:46,338 fail2ban.actions [736]: NOTICE [apache-scan] Ban 34.59.20.78
2026-09-16 04:56:46,679 fail2ban.actions [736]: NOTICE [web-scanner] Ban 34.59.20.78
2026-09-16 04:56:50,617 fail2ban.actions [736]: NOTICE [laravel-auth] Ban 34.59.20.78
...
show less
Brute-Force
Web App Attack
๐ฉ๐ช
netclix.gr
2026-09-16 00:22:34
(11 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 34.59.20.78 (US/United States/78.20.59. ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.59.20.78 (US/United States/78.20.59.34.bc.googleusercontent.com): (CF_ENABLE)
show less
SQL Injection
๐ฎ๐ณ
evicky2002
2026-09-16 00:02:04
(11 hours ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐ฉ๐ช
FD-IX
2026-09-15 23:24:12
(12 hours ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack