๐ณ๐ฑ
homeshowdomain.nl
2026-09-17 22:03:09
(5 days ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-16.
show less
Web App Attack
SSH
Hacking
๐ณ๐ฑ
e.fierstra
2026-09-16 06:13:29
(6 days ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐ฉ๐ช
MarkGGN
2026-09-16 05:52:48
(6 days ago)
Web attack. 34.63.104.52 - - [16/Sep/2026:07:52:48 +0200] "GET /.env?raw HTTP/2.0" 444 0 "-" "Mozill ...
show more
Web attack. 34.63.104.52 - - [16/Sep/2026:07:52:48 +0200] "GET /.env?raw HTTP/2.0" 444 0 "-" "Mozilla/5.0 (compatible; MistralAI-User/1.0; +https://mistral.ai/)"
34.63.104.52 - - [16/Sep/2026:07:52:48 +0200] "GET /.env?import&url&inline HTTP/2.0" 444 0 "-" "Mozilla/5.0 (compatible; Meta-ExternalAgent/1.0; +https://developers.facebook.com/docs/sharing/webmasters/crawler)"
show less
Web App Attack
๐ต๐ฑ
dzpk
2026-09-16 04:39:22
(6 days ago)
34.63.104.52 - - [15/Sep/2026:14:41:39 +0200] "GET /wp-json HTTP/2.0" 404 848 "-" "Mozilla/5.0 (comp ...
show more
34.63.104.52 - - [15/Sep/2026:14:41:39 +0200] "GET /wp-json HTTP/2.0" 404 848 "-" "Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; +https://kimi.ai/)"
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
ConsulHosting
2026-09-16 01:30:12
(6 days ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack
๐ฉ๐ช
EGP Abuse Dept
2026-09-16 01:14:06
(6 days ago)
Scanning for web/db/file exploits on www.krootinstallatie.nl
SQL Injection
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 01:10:16
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 34.63.104.52 (52.104.63.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.63.104.52 (52.104.63.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 21:10:09.425291 2026] [security2:error] [pid 2397:tid 2397] [client 34.63.104.52:59416] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kronrod.com"] [uri "/.env.old"] [unique_id "aqnscT2Sh4oscSimR0AzaAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
โจ
2026-09-16 00:54:14
(6 days ago)
Domain : krobodanbeads.com
Rule : hack
2026-09-16 00:52:08 ***hidden-privacy*** GET /proc/self/cmdli ...
show more
Domain : krobodanbeads.com
Rule : hack
2026-09-16 00:52:08 ***hidden-privacy*** GET /proc/self/cmdline - 443 - 34.63.104.52 HTTP/2 Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; [email protected] ) - krobodanbeads.com 404 0 2 1553 438 103 - -
show less
Hacking
SQL Injection
Brute-Force
๐ณ๐ฑ
Site.eu
2026-09-16 00:42:13
(6 days ago)
Excessive multi-domain requests
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-16 00:30:42
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 34.63.104.52 (52.104.63.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.63.104.52 (52.104.63.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 20:30:35.621716 2026] [security2:error] [pid 22998:tid 22998] [client 34.63.104.52:49666] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kristinmoore.com"] [uri "/.git/HEAD"] [unique_id "aqnjK-xpydECt9I8ltMpGAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ณ
evicky2002
2026-09-16 00:02:04
(1 week ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐ญ๐บ
kranem
2026-09-16 00:00:37
(1 week ago)
Triggered Cloudflare WAF from US.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Protocol: HTTP/2 (GET ...
show more
Triggered Cloudflare WAF from US.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Protocol: HTTP/2 (GET method)
Endpoint: /config/prod.exs
Timestamp: 2026-09-15T21:20:15Z
User-Agent: Mozilla/5.0 (compatible; KimiBot/1.0; +https://kimi.ai/)
show less
Bad Web Bot
๐ณ๐ฑ
debestelapp
2026-09-15 23:10:16
(1 week ago)
Web App Attack
๐ฌ๐ง
consul.to
2026-09-15 21:44:48
(1 week ago)
Web attack/malicious scanning detected
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-15 21:29:57
(1 week ago)
[ti-24al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-24al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 34.63.104.52 - - [15/Sep/2026:23:29:51 +0200] "GET /@fs/root/.aws/credentials?raw?? HTTP/2.0" 301 345 "-" "Mozilla/5.0 (compatible; DeepSeekBot/1.0; +https://www.deepseek.com/)"
...
show less
Bad Web Bot
Web App Attack