๐ฌ๐ง
consul.to
2026-08-28 13:11:54
(14 minutes ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
cwytech
2026-08-28 10:59:37
(2 hours ago)
Fleet-wide ban from the Ghostfleet ๐ป. Triggered by scenario: crowdsecurity/http-probing.
Bad Web Bot
Web App Attack
๐ฉ๐ช
Vegascosmetics
2026-08-28 09:58:00
(3 hours ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after sensitive config/credentials exposure ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after sensitive config/credentials exposure probe. Evidence: AttackPattern: /\.aws/credentials (Match: /.aws/credentials)
show less
Hacking
Brute-Force
Web App Attack
๐จ๐ญ
4server
2026-08-28 08:39:43
(4 hours ago)
[FriAug2810:39:36.6839552026][security2:error][pid615214:tid615374][client34.84.42.246:0]ModSecurity ...
show more
[FriAug2810:39:36.6839552026][security2:error][pid615214:tid615374][client34.84.42.246:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".env\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"610\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"mail.npdesign360.ch\"][uri\"/@fs/../.env\"][unique_id\"apFJSNhQbGdt1foE_M6RsgAAAEo\"]
show less
Hacking
Web App Attack
๐ท๐บ
DZBOT
2026-08-28 08:10:23
(5 hours ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐ซ๐ท
masterguru
2026-08-28 08:00:21
(5 hours ago)
Restricted File Access Attempt. Matched phrase "/@fs/" at REQUEST_FILENAME. (930130-193)
Hacking
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-08-28 06:55:45
(6 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 127
Exploited Host
Web App Attack
๐ต๐ฑ
Budyn
2026-08-28 06:45:04
(6 hours ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit Block. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: astropot.website | URI: /@fs/root/.aws/credentials.backup?raw?? | UA: Mozilla/5.0 (Linux; Android 15; SM-S918B) AppleWebKit/537.36 (KHTML, like Gecko; compatible; GPTBot/1.2; +https://openai.com/gptbot) Chrome/136.0.224.59 Mobile Safari/537.36 | BODY: [Empty / GET Request]
show less
Hacking
Web App Attack
๐บ๐ธ
TAY
2026-08-28 06:43:55
(6 hours ago)
34.84.42.246 - - [28/Aug/2026:14:43:42 +0800] "GET /@fs/../.env?raw?? HTTP/1.1" 404 2050 "-" "Mozill ...
show more
34.84.42.246 - - [28/Aug/2026:14:43:42 +0800] "GET /@fs/../.env?raw?? HTTP/1.1" 404 2050 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:133.14) Gecko/20100101 Firefox/133.14; compatible; Bytespider; +https://zhanzhang.toutiao.com/"
34.84.42.246 - - [28/Aug/2026:14:43:42 +0800] "GET /@fs/../../.env?raw?? HTTP/1.1" 400 2057 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; GrokBot/1.0; +https://x.ai/grokbot)"
34.84.42.246 - - [28/Aug/2026:14:43:55 +0800] "GET /@fs/var/www/html/wp-config.php?raw?? HTTP/1.1" 404 2598 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko; compatible; OAI-SearchBot/1.3; +https://openai.com/searchbot) Chrome/124.0.4407.150 Safari/537.36"
34.84.42.246 - - [28/Aug/2026:14:43:55 +0800] "GET /@fs/../../../../../app/.env?raw?? HTTP/1.1" 400 2057 "-" "Mozilla/5.0 (Windows NT 10.0; rv:78.3) Gecko/20100101 Firefox/78.3; compatible; meta-externalagent/1.1; +https://developers.facebook.com/docs/sharing/webmasters/
...
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-08-28 06:42:11
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.84.42.246 (246.42.84.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.84.42.246 (246.42.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 02:42:03.701987 2026] [security2:error] [pid 6537:tid 6602] [client 34.84.42.246:2910] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dcsindo.dcs.co.id"] [uri "/@fs/src/.env"] [unique_id "apEtu5Eq9V0mT4wJ0kmJEAAAAMo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-28 06:28:08
(6 hours ago)
Web scanner: GET /@fs/.env.production?raw??
Web App Attack
Hacking
๐ฆ๐น
Erpelstolz
2026-08-28 05:32:16
(7 hours ago)
VM 131: 34.84.42.246 - - [28/Aug/2026:07:32:16 +0200] "GET /@fs/etc/passwd?raw?? HTTP/1.1" 404 6205
Hacking
Web App Attack
Anonymous
2026-08-28 05:09:09
(8 hours ago)
34.84.42.246 - - [28/Aug/2026:07:09:09 +0200] "GET /@fs/.env?raw?? HTTP/1.1" 403 183 "-" "Mozilla/5. ...
show more
34.84.42.246 - - [28/Aug/2026:07:09:09 +0200] "GET /@fs/.env?raw?? HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.7731.23 Safari/537.36; compatible; Twitterbot/1.0"
34.84.42.246 - - [28/Aug/2026:07:09:09 +0200] "GET /@fs/src/.env?raw?? HTTP/1.1" 403 124 "-" "Mozilla/5.0 (compatible; TelegramBot/1.0)"
34.84.42.246 - - [28/Aug/2026:07:09:09 +0200] "GET /@fs/proc/self/environ?raw?? HTTP/1.1" 403 183 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.1548.86 Safari/537.36; compatible; OAI-SearchBot/1.3; +https://openai.com/searchbot"
34.84.42.246 - - [28/Aug/2026:07:09:09 +0200] "GET /@fs/..%252f..%252f..%252f..%252f..%252fproc/self/environ?raw?? HTTP/1.1" 403 124 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot)"
34.84.42.246 - - [28/Aug/2026:07:09:09 +0200] "GET /@fs/app/.env?raw?? HTTP/
...
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-08-28 04:50:12
(8 hours ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-28 04:46:04
(8 hours ago)
Bot / scanning and/or hacking attempts: GET /api/v1/settings HTTP/1.1, GET /firebase-adminsdk.json H ...
show more
Bot / scanning and/or hacking attempts: GET /api/v1/settings HTTP/1.1, GET /firebase-adminsdk.json HTTP/1.1, GET /wp-config.php.bak HTTP/1.1
show less
Hacking
Web App Attack