๐ฟ๐ฆ
conure.sh
2026-09-16 12:07:37
(12 hours ago)
csagent: score 20.2: secrets grab x2, 404 noise floor x1; 1 domain(s) in 2s
Web App Attack
๐ฌ๐ง
openstrike.co.uk
2026-09-16 05:14:33
(19 hours ago)
173 attacks on config grabbing URLs (type 2), env grabbing URLs, VC URLs, directory traversals, env ...
show more
173 attacks on config grabbing URLs (type 2), env grabbing URLs, VC URLs, directory traversals, env grabbing URLs (type 2), PHP URLs, password/key grabbing URLs:
GET /app-config.json HTTP/1.1
GET /.env.js HTTP/1.1
GET /.git/HEAD HTTP/1.1
GET /..%2f..%2f.env HTTP/1.1
GET /api/w/starter/jobs_u/get_log_file/../../../../proc/self/environ HTTP/1.1
POST /icecoder/lib/terminal-xhr.php HTTP/1.1
GET /__vite_rsc_findSourceMapURL?filename=file:///root/.ssh/id_rsa&environmentName=rsc HTTP/1.1
show less
Hacking
Web App Attack
๐ง๐ฌ
HighWay
2026-09-16 04:33:14
(19 hours ago)
34.9.198.161 - - [16/Sep/2026:04:33:06 +0000] "GET /serverless.yaml HTTP/1.1" 404 4758 "-" "Mozilla/ ...
show more
34.9.198.161 - - [16/Sep/2026:04:33:06 +0000] "GET /serverless.yaml HTTP/1.1" 404 4758 "-" "Mozilla/5.0 (compatible; ChatGLM-Spider/1.0; +https://zhipuai.cn/)"
34.9.198.161 - - [16/Sep/2026:04:33:06 +0000] "GET /secrets.env HTTP/1.1" 404 4757 "-" "Mozilla/5.0 (compatible; Qwenbot/1.0; +https://qwen.alibaba.com/)"
34.9.198.161 - - [16/Sep/2026:04:33:07 +0000] "POST /graphql HTTP/1.1" 404 770 "https://vhelectronics.com" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
34.9.198.161 - - [16/Sep/2026:04:33:07 +0000] "GET /id_rsa HTTP/1.1" 404 770 "-" "Mozilla/5.0 (compatible; Google-Extended; +http://www.google.com/bot.html)"
34.9.198.161 - - [16/Sep/2026:04:33:07 +0000] "GET /id_dsa HTTP/1.1" 404 770 "-" "Mozilla/5.0 (compatible; ChatGLM-Spider/1.0; +https://zhipuai.cn/)"
34.9.198.161 - - [16/Sep/2026:04:33:07 +0000] "POST /api/graphql HTTP/1.1" 404 770 "https://vhelectronics.com" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) Ap
...
show less
Bad Web Bot
Web App Attack
๐ฟ๐ฆ
vanderhost
2026-09-16 04:31:56
(19 hours ago)
[Laravel HoneypotPlus] Automated report - Honeypot access detected on path: /storage/logs/laravel.lo ...
show more
[Laravel HoneypotPlus] Automated report - Honeypot access detected on path: /storage/logs/laravel.log via rule: /storage/logs
show less
Web App Attack
Bad Web Bot
๐ช๐ธ
robotstxt
2026-09-16 04:13:58
(20 hours ago)
34.9.198.161 - - [16/Sep/2026:04:13:38 +0000] "GET /dist/.vite/manifest.json HTTP/2.0" 403 2 "https: ...
show more
34.9.198.161 - - [16/Sep/2026:04:13:38 +0000] "GET /dist/.vite/manifest.json HTTP/2.0" 403 2 "https://starship.xyz/dist/.vite/manifest.json" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36 Edg/152.0.0.0" "-" edge="34.9.198.161"
34.9.198.161 - - [16/Sep/2026:04:13:38 +0000] "GET /dist/manifest.json HTTP/2.0" 403 2 "https://starship.xyz/dist/manifest.json" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36 Edg/152.0.0.0" "-" edge="34.9.198.161"
34.9.198.161 - - [16/Sep/2026:04:13:38 +0000] "GET /build/manifest.json HTTP/2.0" 403 2 "https://starship.xyz/build/manifest.json" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36 Edg/152.0.0.0" "-" edge="34.9.198.161"
34.9.198.161 - - [16/Sep/2026:04:13:38 +0000] "GET /credentials.json HTTP/2.0" 403 20 "https://starship.xyz/credentials.json"
...
show less
Web App Attack
Anonymous
2026-09-16 04:09:54
(20 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
๐บ๐ธ
jormaster3k
2026-09-16 03:56:32
(20 hours ago)
Attack against Apache (too many 404s)
Web App Attack
๐ณ๐ฑ
Savvii
2026-09-16 03:48:12
(20 hours ago)
20 attempts against mh-misbehave-ban on milky
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
dot.mg
2026-09-16 03:29:03
(20 hours ago)
Bad behaviour
Web Spam
๐บ๐ธ
TPI-Abuse
2026-09-16 02:04:16
(22 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.9.198.161 (161.198.9.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.9.198.161 (161.198.9.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 22:04:08.990209 2026] [security2:error] [pid 25202:tid 25202] [client 34.9.198.161:51340] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||planettony.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "planettony.com"] [uri "/rclone.conf"] [unique_id "aqn5GAK8HKzTSOzarD5vQQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฏ๐ต
ZEROVOX
2026-09-16 00:41:34
(23 hours ago)
CrowdSec: crowdsecurity/http-probing detected
Web App Attack
๐บ๐ธ
Mundo Bueno
2026-09-16 00:00:18
(1 day ago)
[ISILIA Protection v2.1] Tentative d'accรจs: /api/uploads/%2e%2e%2f%2e%2e%2f.env | Pays: US | UA: Moz ...
show more
[ISILIA Protection v2.1] Tentative d'accรจs: /api/uploads/%2e%2e%2f%2e%2e%2f.env | Pays: US | UA: Mozilla/5.0 (compatible; xAI-Grok/1.0; +https://x.ai/)
show less
Hacking
Web App Attack
๐ซ๐ฎ
paissangroup
2026-09-15 23:49:41
(1 day ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
agenciahypelab.com.br
2026-09-15 22:44:21
(1 day ago)
WordPress login brute-force detectado e bloqueado pelo CSF/LFD. Trigger: LF_TRIGGER
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-09-15 21:48:35
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.9.198.161 (161.198.9.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.9.198.161 (161.198.9.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 17:48:30.252204 2026] [security2:error] [pid 28578:tid 28578] [client 34.9.198.161:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pixacast.com"] [uri "/.env"] [unique_id "aqm9Lk-FESYd7A7gJoxseAAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack