๐ณ๐ฑ
homeshowdomain.nl
2026-09-18 22:00:35
(1 day ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-17.
show less
Web App Attack
SSH
Hacking
๐ฌ๐ง
openstrike.co.uk
2026-09-18 05:14:10
(2 days ago)
251 attacks on env grabbing URLs, VC URLs, config grabbing URLs (type 2), PHP URLs:
GET /config/app/ ...
show more
251 attacks on env grabbing URLs, VC URLs, config grabbing URLs (type 2), PHP URLs:
GET /config/app/.env HTTP/1.1
GET /.git/config HTTP/1.1
GET /application_default_credentials.json HTTP/1.1
GET /includes/phpinfo.php HTTP/1.1
show less
Hacking
Web App Attack
๐จ๐ฆ
polycoda
2026-09-17 10:01:16
(3 days ago)
AutoBlock: ๐ฏ Vulnerability Scanner (Non Decay-Based) - โ๏ธ Configuration File Access (Non Decay-Based ...
show more
AutoBlock: ๐ฏ Vulnerability Scanner (Non Decay-Based) - โ๏ธ Configuration File Access (Non Decay-Based)
show less
Hacking
Bad Web Bot
Web App Attack
๐ซ๐ท
Octopuce
2026-09-17 09:04:48
(3 days ago)
Aggressive web search of vulnerable pages: / /.env /.env.local /app/.env /apps/.env ...
Web App Attack
๐ธ๐ฌ
securejdprop
2026-09-17 03:53:21
(3 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/vpatch-CVE-2025-55182.
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-17 03:01:22
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.65.243.16 (16.243.65.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.243.16 (16.243.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 23:01:16.938793 2026] [security2:error] [pid 16041:tid 16041] [client 34.65.243.16:45252] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sullico.com"] [uri "/.git/config"] [unique_id "aqtX_KxFSEmGT3wwBBi2bAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-17 02:23:46
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.65.243.16 (16.243.65.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.243.16 (16.243.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 22:23:40.020949 2026] [security2:error] [pid 7923:tid 7942] [client 34.65.243.16:41278] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sujugada.com"] [uri "/.git/config"] [unique_id "aqtPLP2vNAcxQeQ2YL_I_AAAAFI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
LSPCCU
2026-09-15 19:46:34
(4 days ago)
TSEC Honeypot Network report. Threat score: 70/100. Categories: Hacking, Brute-Force, Web App Attack ...
show more
TSEC Honeypot Network report. Threat score: 70/100. Categories: Hacking, Brute-Force, Web App Attack, SSH. Honeypot: galah, h0neytr4p. Context: Attacker IP 34.65.243.16 observed using TLS client fingerprint 'Unknown TLS Client (e1db13f18329)' 3 times when connecting to a energy sector honeypot between 2026-09-15 17:37 and 2026-09-15 17:38 UTC.
show less
Hacking
Brute-Force
Web App Attack
SSH
๐บ๐ธ
TPI-Abuse
2026-09-15 18:19:13
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.65.243.16 (16.243.65.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.243.16 (16.243.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 14:19:08.171530 2026] [security2:error] [pid 17557:tid 17557] [client 34.65.243.16:42224] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "scala-global.com"] [uri "/.git/config"] [unique_id "aqmMHOQQP_hzzy-G82xz-gAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
MatCat
2026-09-15 18:05:06
(4 days ago)
Banned by fail2ban: apache-webprobe
Port Scan
Bad Web Bot
Anonymous
2026-09-15 17:53:47
(4 days ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
๐ธ๐ช
vaia.cloud
2026-09-15 17:45:04
(4 days ago)
crowdsecurity/http-admin-interface-probing
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 17:40:36
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.65.243.16 (16.243.65.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.243.16 (16.243.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 13:40:30.966383 2026] [security2:error] [pid 17466:tid 17466] [client 34.65.243.16:55570] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "scadainthecloud.com"] [uri "/.git/config"] [unique_id "aqmDDgxGwfQmvbfnDFFa7QAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Savvii
2026-09-15 17:22:33
(4 days ago)
20 attempts against mh_ha-misbehave-ban on boron
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-09-15 15:30:04
(5 days ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack