๐ฎ๐ณ
evicky2002
2026-09-24 06:00:03
(12 hours ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐ฌ๐ง
openstrike.co.uk
2026-09-23 05:15:03
(1 day ago)
168 attacks on PHP URLs, env grabbing URLs (type 2), directory traversals, password/key grabbing URL ...
show more
168 attacks on PHP URLs, env grabbing URLs (type 2), directory traversals, password/key grabbing URLs, VC URLs, env grabbing URLs, config grabbing URLs (type 2):
POST /icecoder/lib/terminal-xhr.php HTTP/1.1
GET /public/plugins/alertlist/../../../../../../../../proc/self/environ HTTP/1.1
GET /..%2f..%2f.env HTTP/1.1
GET /@fs/home/ec2-user/.aws/credentials?raw?? HTTP/1.1
GET /.git/HEAD HTTP/1.1
GET /_nuxt/../.env HTTP/1.1
GET /config/gcp-credentials.json HTTP/1.1
show less
Web App Attack
Hacking
๐บ๐ธ
wbsouza
2026-09-23 03:24:19
(1 day ago)
CrowdSec: crowdsecurity/http-sensitive-files โ automated firewall drops on self-hosted IDS sensor
Hacking
๐ฌ๐ง
thetomtaylor.co.uk
2026-09-22 16:08:00
(2 days ago)
Fail2Ban - [WAF]ModSecurity OWASP CRS rule violation on nginx-modsecurity ... [ice01,ice02,wa01,wa02 ...
show more
Fail2Ban - [WAF]ModSecurity OWASP CRS rule violation on nginx-modsecurity ... [ice01,ice02,wa01,wa02]
show less
Hacking
SQL Injection
Web App Attack
๐ซ๐ฎ
Christopher Hughes
2026-09-22 15:53:44
(2 days ago)
34.81.52.15 - - [22/Sep/2026:16:53:43 +0100] "GET /wp-config.php.bak HTTP/2.0" 200 1456 "-" "Mozilla ...
show more
34.81.52.15 - - [22/Sep/2026:16:53:43 +0100] "GET /wp-config.php.bak HTTP/2.0" 200 1456 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
...
show less
Web App Attack
Anonymous
2026-09-22 15:45:13
(2 days ago)
IP banned by Fail2Ban in jail nginx-abusive-ips
Web App Attack
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-22 14:22:29
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 34.81.52.15 (15.52.81.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.81.52.15 (15.52.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 10:22:23.513971 2026] [security2:error] [pid 13971:tid 13971] [client 34.81.52.15:45074] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.djmrmusic.com|F|2"] [data ".djmrmusic.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.djmrmusic.com"] [uri "/z9x8c7v6b5-debug-trigger-www.djmrmusic.com"] [unique_id "arKPH5MPSp-Mzuc6zENxLAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Aetherweb Ark
2026-09-22 13:19:53
(2 days ago)
(mod_security) mod_security (id:949110) triggered by 34.81.52.15 (TW/Taiwan/15.52.81.34.bc.googleuse ...
show more
(mod_security) mod_security (id:949110) triggered by 34.81.52.15 (TW/Taiwan/15.52.81.34.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 12:59:32
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 34.81.52.15 (15.52.81.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.81.52.15 (15.52.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 08:59:27.391598 2026] [security2:error] [pid 15958:tid 15958] [client 34.81.52.15:47566] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.dewsales.com|F|2"] [data ".dewsales.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.dewsales.com"] [uri "/z9x8c7v6b5-debug-trigger-www.dewsales.com"] [unique_id "arJ7r8lwFRuNGLi9Z9V9-QAAADk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
Anytech
2026-09-22 12:21:34
(2 days ago)
Blocked by ConnMonitor
Web App Attack
Anonymous
2026-09-22 11:20:36
(2 days ago)
| [Dangerous/Taiwan] Aggressive IP 34.81.52.15 (~30 hits). Type: DoS Defender- Web server 400 error ...
show more
| [Dangerous/Taiwan] Aggressive IP 34.81.52.15 (~30 hits). Type: DoS Defender- Web server 400 error code
show less
Web App Attack
Hacking
SQL Injection
๐ณ๐ฑ
ConsulHosting
2026-09-22 11:14:38
(2 days ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 11:03:33
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 34.81.52.15 (15.52.81.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.81.52.15 (15.52.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 07:03:28.564465 2026] [security2:error] [pid 18811:tid 18811] [client 34.81.52.15:57450] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||disnet-m.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "disnet-m.com"] [uri "/z9x8c7v6b5-debug-trigger-disnet-m.com"] [unique_id "arJggBa-I6oZ6akp3e0VawAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 09:47:23
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 34.81.52.15 (15.52.81.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.81.52.15 (15.52.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 05:47:20.494571 2026] [security2:error] [pid 24031:tid 24031] [client 34.81.52.15:59340] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||divesfl.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "divesfl.com"] [uri "/z9x8c7v6b5-debug-trigger-divesfl.com"] [unique_id "arJOqAZgTlypG8BJObghhgAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-22 09:24:26
(2 days ago)
fail2ban jail apache-secrets-probe: 34.81.52.15 - - [22/Sep/2026:02:24:21 -0700] "GET /.env.www HTTP ...
show more
fail2ban jail apache-secrets-probe: 34.81.52.15 - - [22/Sep/2026:02:24:21 -0700] "GET /.env.www HTTP/1.1" 404 58458 "-" "Mozilla/5.0 (compatible; PanguBot/1.0; +https://www.huaweicloud.com/)"
show less
Web App Attack