๐ซ๐ท
IRISIO
2026-09-16 10:46:01
(4 days ago)
scans/SQL injection/spam posts : 576 queries
Web App Attack
SQL Injection
๐ง๐ช
taivas.nl
2026-09-16 04:34:30
(4 days ago)
Many_bad_calls
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-09-16 03:14:31
(4 days ago)
excessive HTTP 404 errors
Bad Web Bot
Anonymous
2026-09-16 02:40:04
(4 days ago)
| Multiple common web attacks from same source ip. (multiple servers)
Web App Attack
Hacking
SQL Injection
๐ธ๐ฌ
Cloudkul Cloudkul
2026-09-16 02:30:29
(4 days ago)
Attempted Brute Force on our application
Brute-Force
Web App Attack
๐ฌ๐ง
andypiper
2026-09-16 01:01:00
(4 days ago)
CrowdSec ban for AbuseIPDB Top List
Brute-Force
Web App Attack
๐ซ๐ท
โจ
2026-09-16 00:42:09
(4 days ago)
Domain : wims.pk
Rule : env
2026-09-16 00:40:45 ***hidden-privacy*** GET /static/.env - 80 - 34.67.2 ...
show more
Domain : wims.pk
Rule : env
2026-09-16 00:40:45 ***hidden-privacy*** GET /static/.env - 80 - 34.67.248.143 HTTP/1.1 Mozilla/5.0 (compatible; xAI-Grok/1.0; https://x.ai/) - wims.pk 404 0 0 3531 353 102 - -
show less
Hacking
SQL Injection
๐ณ๐ฑ
Site.eu
2026-09-16 00:38:36
(4 days ago)
Excessive multi-domain requests
Brute-Force
๐ฉ๐ช
rh24
2026-09-16 00:14:53
(4 days ago)
(badbots) Bad bot user-agent [redacted] from 34.67.248.143 (US/United States/143.248.67.34.bc.google ...
show more
(badbots) Bad bot user-agent [redacted] from 34.67.248.143 (US/United States/143.248.67.34.bc.googleusercontent.com)
show less
Hacking
๐ฎ๐ณ
evicky2002
2026-09-16 00:02:04
(4 days ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-09-15 22:40:27
(4 days ago)
(mod_security) mod_security (id:210730) triggered by 34.67.248.143 (143.248.67.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.67.248.143 (143.248.67.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 18:40:20.988880 2026] [security2:error] [pid 31218:tid 31218] [client 34.67.248.143:47430] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||luckypupdesigns.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "luckypupdesigns.com"] [uri "/z9x8c7v6b5-debug-trigger-luckypupdesigns.com"] [unique_id "aqnJVKfb_CFIEo3huU5bbwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 21:53:50
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.67.248.143 (143.248.67.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.67.248.143 (143.248.67.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 17:53:42.376163 2026] [security2:error] [pid 30310:tid 30310] [client 34.67.248.143:40218] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "luciferdirective.com"] [uri "/appearance/../../.env"] [unique_id "aqm-ZsoarXew-nMWgktNHAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
maxpower
2026-09-15 20:51:18
(4 days ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 34.67.248.143 (US/United States/143.248. ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 34.67.248.143 (US/United States/143.248.67.34.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 34.67.248.143 - - [15/Sep/2026:22:51:13 +0200] "GET /.aws/credentials HTTP/2.0" 200 12155 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot)" "-" host=lucadipa.com
show less
Port Scan
๐ฌ๐ง
Andrew
2026-09-15 20:21:24
(4 days ago)
34.67.248.143 - - [15/Sep/2026:21:21:23 +0100] "GET /.git/config HTTP/1.1" 404 20276 "-" "DuckAssist ...
show more
34.67.248.143 - - [15/Sep/2026:21:21:23 +0100] "GET /.git/config HTTP/1.1" 404 20276 "-" "DuckAssistBot/1.1 (https://duckduckgo.com/duckassistbot)"
34.67.248.143 - - [15/Sep/2026:21:21:23 +0100] "GET /.git/HEAD HTTP/1.1" 404 20274 "-" "Mozilla/5.0 (compatible; Meta-ExternalAgent/1.0; +https://developers.facebook.com/docs/sharing/webmasters/crawler)"
34.67.248.143 - - [15/Sep/2026:21:21:23 +0100] "GET /.git-credentials HTTP/1.1" 404 18365 "-" "Mozilla/5.0 (compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot)"
34.67.248.143 - - [15/Sep/2026:21:21:23 +0100] "GET /.gitconfig HTTP/1.1" 404 18359 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot)"
34.67.248.143 - - [15/Sep/2026:21:21:23 +0100] "GET /.gitlab-ci.yml HTTP/1.1" 404 18363 "-" "Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; +https://kimi.ai/)"
34.67.248.143 - - [15/Sep/2026:21:21:23 +0100] "GET /.github/workflows/deploy.yml HTTP/1.1" 404
...
show less
Hacking
Web App Attack
๐ฉ๐ช
Hazzard
2026-09-15 20:12:28
(4 days ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted]): (CF_ENABLE)
Bad Web Bot