๐ฎ๐ณ
evicky2002
2026-09-24 06:00:03
(3 hours ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐ฟ๐ฆ
conure.sh
2026-09-23 12:13:52
(21 hours ago)
csagent: score 23.2: 404 noise floor x13, secrets grab x2; 1 domain(s) in 2s
Web App Attack
Anonymous
2026-09-23 11:00:44
(22 hours ago)
34.80.153.197 - - [22/Sep/2026:14:48:57 -0500] "GET /.env HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compat ...
show more
34.80.153.197 - - [22/Sep/2026:14:48:57 -0500] "GET /.env HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; cohere-ai; +https://cohere.com/crawler)" 34.80.153.197
34.80.153.197 - - [22/Sep/2026:14:48:57 -0500] "GET /.env.example HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; MistralAI-User/1.0; +https://mistral.ai/)" 34.80.153.197
34.80.153.197 - - [22/Sep/2026:14:48:57 -0500] "GET /.env.local HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; Qwenbot/1.0; +https://qwen.alibaba.com/)" 34.80.153.197
34.80.153.197 - - [22/Sep/2026:14:48:57 -0500] "GET /.env.backup HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; YouBot/1.0; +https://you.com/bot)" 34.80.153.197
34.80.153.197 - - [22/Sep/2026:14:48:57 -0500] "GET /.env.production HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; MistralAI-User/1.0; +https://mistral.ai/)" 34.80.153.197
34.80.153.197 - - [22/Sep/2026:14:48:57 -0500] "GET /.env.bak HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; Qwenbot/1.0; +https://qwen.alibaba.com/)" 34.80.153.19
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-23 03:15:32
(1 day ago)
Excessive multi-domain requests
Brute-Force
๐ซ๐ท
Zundapper
2026-09-22 23:44:10
(1 day ago)
34.80.153.197 - - [23/Sep/2026:01:44:10 +0200] "GET /z9x8c7v6b5-debug-trigger-www.modulilaser.com HT ...
show more
34.80.153.197 - - [23/Sep/2026:01:44:10 +0200] "GET /z9x8c7v6b5-debug-trigger-www.modulilaser.com HTTP/2.0" 404 106 "https://www.modulilaser.com/z9x8c7v6b5-debug-trigger-www.modulilaser.com" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; [email protected] )"
34.80.153.197 - - [23/Sep/2026:01:44:10 +0200] "GET /login HTTP/2.0" 404 167 "https://www.modulilaser.com/login" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Mobile Safari/537.36"
34.80.153.197 - - [23/Sep/2026:01:44:10 +0200] "GET /login HTTP/2.0" 404 167 "https://www.modulilaser.com/login" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Mobile Safari/537.36"
34.80.153.197 - - [23/Sep/2026:01:44:10 +0200] "GET /signin HTTP/2.0" 404 167 "https://www.modulilaser.com/signin" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Mobile Safari/537.36"
...
show less
Web App Attack
Port Scan
๐บ๐ธ
oralunal
2026-09-22 22:17:31
(1 day ago)
IP banned by Fail2Ban in jail ente-suss ente.com-ssl_log mvfnds
...
Bad Web Bot
Web App Attack
๐ซ๐ท
Zundapper
2026-09-22 22:08:56
(1 day ago)
34.80.153.197 - - [23/Sep/2026:00:08:55 +0200] "GET /users/login HTTP/2.0" 404 167 "-" "Mozilla/5.0 ...
show more
34.80.153.197 - - [23/Sep/2026:00:08:55 +0200] "GET /users/login HTTP/2.0" 404 167 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Mobile Safari/537.36"
34.80.153.197 - - [23/Sep/2026:00:08:55 +0200] "GET /user/login HTTP/2.0" 404 167 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Mobile Safari/537.36"
34.80.153.197 - - [23/Sep/2026:00:08:55 +0200] "GET /z9x8c7v6b5-debug-trigger-modulilaser.com HTTP/2.0" 404 106 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; [email protected] )"
34.80.153.197 - - [23/Sep/2026:00:08:55 +0200] "GET /auth HTTP/2.0" 404 167 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Mobile Safari/537.36"
34.80.153.197 - - [23/Sep/2026:00:08:55 +0200] "GET /secure HTTP/2.0" 404 167 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Mobile
...
show less
Web App Attack
Port Scan
๐บ๐ธ
TPI-Abuse
2026-09-22 20:52:59
(1 day ago)
(mod_security) mod_security (id:210580) triggered by 34.80.153.197 (197.153.80.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210580) triggered by 34.80.153.197 (197.153.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 16:52:54.342840 2026] [security2:error] [pid 13796:tid 13796] [client 34.80.153.197:34288] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "proc/self/environ" at ARGS:vars[1][]. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/08_Global_Other.conf"] [line "57"] [id "210580"] [rev "2"] [msg "COMODO WAF: OS File Access Attempt||slattery-law.com|F|2"] [data "Matched Data: proc/self/environ found within ARGS:vars[1][]: /proc/self/environ"] [severity "CRITICAL"] [tag "CWAF"] [tag "Other"] [hostname "slattery-law.com"] [uri "/index.php"] [unique_id "arLqphALHsi0wIrsFJndPQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ต๐น
Subnet Phantom Veil
2026-09-22 20:34:49
(1 day ago)
[CRITICAL][Security Alert] Targeted exploit scanning against Textbook Vulnerabilities. Bot hunting f ...
show more
[CRITICAL][Security Alert] Targeted exploit scanning against Textbook Vulnerabilities. Bot hunting for PHP backdoors. [Method]: => GET. [Request]: => /graphql. Access revoked. [User-Agent]: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Mobile Safari/537.36 EdgA/153.0.0.0. [OS]: Unknown. [IP Address]: 34.80.153.197.[RPM] 23+ requests per minute (RPM) overshoot. [IoA Datetime]: 2026-09-22 15:14:42 UTC.
show less
Bad Web Bot
Hacking
Port Scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 20:06:29
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.80.153.197 (197.153.80.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.80.153.197 (197.153.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 16:06:25.358045 2026] [security2:error] [pid 1800:tid 1800] [client 34.80.153.197:55318] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||solmedsolicitors.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "solmedsolicitors.com"] [uri "/z9x8c7v6b5-debug-trigger-solmedsolicitors.com"] [unique_id "arLfwd7k7WdjY44UogDU7gAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Starburst SysOp Team
2026-09-22 19:09:48
(1 day ago)
HTTP header is restricted by policy (/x-middleware-subrequest/). String match within "/content-encod ...
show more
HTTP header is restricted by policy (/x-middleware-subrequest/). String match within "/content-encoding/ /proxy/ /lock-token/ /content-range/ /if/ /x-http-method-override/ /x-http-method/ /x-method-override/ /x-middleware-subrequest/ /expect/" at TX:header_name_920450_x-middleware-subrequest. (920450-mnz6-1)
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-22 19:06:42
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.80.153.197 (197.153.80.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.80.153.197 (197.153.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 15:06:36.851870 2026] [security2:error] [pid 27907:tid 27907] [client 34.80.153.197:37422] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||startordoro.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "startordoro.com"] [uri "/z9x8c7v6b5-debug-trigger-startordoro.com"] [unique_id "arLRvBjZrWrf6kHRC6wACQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
IndigoRidge
2026-09-22 18:08:05
(1 day ago)
[22/Sep/2026:14:08:02.442627 --0400] arLEAjyU3MP@KjLCLeJ-zgAAAQ4 34.80.153.197 39116 205.233.18.17 7 ...
show more
[22/Sep/2026:14:08:02.442627 --0400] arLEAjyU3MP@KjLCLeJ-zgAAAQ4 34.80.153.197 39116 205.233.18.17 7081
[22/Sep/2026:14:08:03.507056 --0400] arLEAzyU3MP@KjLCLeJ-0QAAAQ0 34.80.153.197 39366 205.233.18.17 7081
[22/Sep/2026:14:08:04.154979 --0400] arLEBGFUv-nl5S52aM8MUgAAAFA 34.80.153.197 39446 205.233.18.17 7081
[22/Sep/2026:14:08:04.180929 --0400] arLEBFoVN4IVXHjS5OaeMAAAANU 34.80.153.197 39458 205.233.18.17 7081
[22/Sep/2026:14:08:04.462524 --0400] arLEBFoVN4IVXHjS5OaeMgAAAMY 34.80.153.197 39490 205.233.18.17 7081
...
show less
Hacking
Anonymous
2026-09-22 17:30:39
(1 day ago)
Bot traffic targeting WordPress resources
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 17:02:46
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.80.153.197 (197.153.80.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.80.153.197 (197.153.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 13:02:41.262459 2026] [security2:error] [pid 19161:tid 19161] [client 34.80.153.197:39978] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||tausiet.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "tausiet.com"] [uri "/z9x8c7v6b5-debug-trigger-tausiet.com"] [unique_id "arK0sWusNNoO1FZ7yEj_uwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack