๐ฟ๐ฆ
conure.sh
2026-09-23 12:13:48
(3 days ago)
csagent: score 18.7: 404 noise floor x35, secrets grab x1; 1 domain(s) in 2s
Web App Attack
Anonymous
2026-09-23 03:30:02
(3 days ago)
CrowdSec decision: crowdsecurity/http-admin-interface-probing (origin: crowdsec)
Web App Attack
๐น๐ผ
tyebstx
2026-09-23 03:22:45
(3 days ago)
Wazuh Alert Evidence: 2026/09/23 03:22:43 [error] 875287#875287: *24593 [client 34.77.95.18] ModSecu ...
show more
Wazuh Alert Evidence: 2026/09/23 03:22:43 [error] 875287#875287: *24593 [client 34.77.95.18] ModSecurity: Access denied with code 403 (phase 2). Matched "Operator `Ge' with parameter `5' against variable `TX:ANOMALY_SCORE' (Value: `15' ) [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "81"] [id "949110"] [rev ""] [msg "Inbound Anomaly Score Exceeded (Total Score: 15)"] [data ""] [severity "2"] [ver "OWASP_CRS/3.3.5"] [maturity "0"] [accuracy "0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "192.168.102.88"] [uri "/"] [unique_id "179013376361.285548"] [ref ""], client: 34.77.95.18, server: uat.bitstreetx.com, request: "POST / HTTP/2.0", host: "uat.bitstreetx.com"
show less
Web App Attack
Anonymous
2026-09-23 02:32:59
(3 days ago)
XSS Attempt
Hacking
๐ณ๐ฑ
Savvii
2026-09-23 01:36:46
(3 days ago)
20 attempts against mh-misbehave-ban on burne
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
robotstxt
2026-09-23 00:18:13
(3 days ago)
34.77.95.18 - - [23/Sep/2026:00:17:48 +0000] "GET /@fs/..%252f..%252f..%252f..%252f..%252froot/.env? ...
show more
34.77.95.18 - - [23/Sep/2026:00:17:48 +0000] "GET /@fs/..%252f..%252f..%252f..%252f..%252froot/.env?raw?? HTTP/2.0" 403 49646 "https://www.economipedia.com/@fs/..%252f..%252f..%252f..%252f..%252froot/.env?raw??" "Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; +https://kimi.ai/)" "-"
34.77.95.18 - - [23/Sep/2026:00:17:49 +0000] "GET /static/home/user/.env HTTP/2.0" 403 49652 "https://www.economipedia.com/static//home/user/.env" "Mozilla/5.0 (compatible; GrokBot/1.0; +https://x.ai/)" "-"
34.77.95.18 - - [23/Sep/2026:00:17:49 +0000] "GET /static/app/.env HTTP/2.0" 403 49653 "https://www.economipedia.com/static//app/.env" "Mozilla/5.0 (compatible; DeepSeekBot/1.0; +https://www.deepseek.com/)" "-"
34.77.95.18 - - [23/Sep/2026:00:17:49 +0000] "GET /files../.env HTTP/2.0" 403 49650 "https://www.economipedia.com/files../.env" "Mozilla/5.0 (compatible; Hunyuan/1.0; +https://hunyuan.tencent.com/)" "-"
34.77.95.18 - - [23/Sep/2026:00:17:49 +0000] "GET /static/home/user/.env HTTP/2.0" 403 49652 "htt
...
show less
Web App Attack
๐ฆ๐บ
A.i.D.A.N.N
2026-09-22 23:52:11
(3 days ago)
A.i.D.A.N.N: Anomaly Detected - Signature match Web Service - Web vulnerability scanning detected
Web App Attack
๐ซ๐ท
SpaceHost-Server
2026-09-22 22:24:45
(3 days ago)
Brute-Force
Web App Attack
๐ฌ๐ง
Apache
2026-09-22 20:47:31
(3 days ago)
(mod_security) mod_security (id:930130) triggered by 34.77.95.18 (BE/Belgium/18.95.77.34.bc.googleus ...
show more
(mod_security) mod_security (id:930130) triggered by 34.77.95.18 (BE/Belgium/18.95.77.34.bc.googleusercontent.com): 5 in the last 300 secs (CF_ENABLE)
show less
Brute-Force
Web App Attack
๐บ๐ธ
Epimetheus
2026-09-22 19:34:34
(3 days ago)
Zombie network / Bot scanner detected:
[GET] /configuration.js
[GET] /@fs/home/ec2-user/.aws/creden ...
show more
Zombie network / Bot scanner detected:
[GET] /configuration.js
[GET] /@fs/home/ec2-user/.aws/credentials
[GET] /.env.save
[GET] /images../.env
[GET] /admin%2F.env
[GET] /docker/.env
[GET] /static//.env
[GET] /backend/.env
[GET] /debug/pprof
[GET] /.env
[GET] /trace.axd
[GET] /swagger.json
[GET] /pi.php
[POST] /api/designer/v1/file-content
[GET] /docker-compose.yml
[GET] /.bashrc
[GET] /@fs/home/ec2-user/.aws/credentials
[GET] /img../.env
[GET] /app_dev.php/_profiler
[GET] /credentials.js
[GET] /v1/graphql
[GET] /i.php
[GET] /api/config
[GET] /api/w/default/jobs_u/get_log_file/../../../../proc/self/environ
[GET] /build../.env
[GET] /dist../.env
[GET] /actuator/configprops
[GET] /docker-compose.yaml
[GET] /@fs/proc/self/cmdline
[GET] /api%2F.env
[GET] /openapi.json
[GET] /userfiles
[GET] /serverless.yml
[GET] /images../.env
[GET] /@fs/var/run/secrets/kubernetes.io/serviceaccount/token
[GET] /@fs/.env
[GET] /@fs/app/.env
[GET] /@fs/.env
[GET] /__vite_rsc_findSourceMapURL
[
...(Truncated)
show less
Bad Web Bot
Exploited Host
Web App Attack
๐ฌ๐ง
Apache
2026-09-22 15:20:41
(3 days ago)
(mod_security) mod_security (id:930120) triggered by 34.77.95.18 (BE/Belgium/18.95.77.34.bc.googleus ...
show more
(mod_security) mod_security (id:930120) triggered by 34.77.95.18 (BE/Belgium/18.95.77.34.bc.googleusercontent.com): 5 in the last 300 secs (CF_ENABLE)
show less
Brute-Force
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-22 15:08:23
(4 days ago)
[ti-05al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-05al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 34.77.95.18 - - [22/Sep/2026:17:08:18 +0200] "GET /.env.dev HTTP/2.0" 404 1855 "-" "Mozilla/5.0 (compatible; YiBot/1.0; +https://01.ai/)"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 15:06:52
(4 days ago)
(mod_security) mod_security (id:210730) triggered by 34.77.95.18 (18.95.77.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.77.95.18 (18.95.77.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 11:06:44.023680 2026] [security2:error] [pid 1953:tid 1953] [client 34.77.95.18:38784] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||bigredgraphicdesign.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "bigredgraphicdesign.com"] [uri "/z9x8c7v6b5-debug-trigger-bigredgraphicdesign.com"] [unique_id "arKZhMtWjNvePW0_8W7NXgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Stara
2026-09-22 14:23:22
(4 days ago)
ModSecurity detected web attack - .env/config probing or SQLi/Code injection (Rule 949110)
Brute-Force
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 14:17:00
(4 days ago)
(mod_security) mod_security (id:210730) triggered by 34.77.95.18 (18.95.77.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.77.95.18 (18.95.77.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 10:16:57.329123 2026] [security2:error] [pid 29530:tid 29530] [client 34.77.95.18:42678] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||billhumphreyresearch.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "billhumphreyresearch.com"] [uri "/z9x8c7v6b5-debug-trigger-billhumphreyresearch.com"] [unique_id "arKN2ZXPDClpQRHpXaqO4QAAADs"]
show less
Brute-Force
Bad Web Bot
Web App Attack