๐ฉ๐ช
FeG Deutschland
2026-09-18 07:03:13
(9 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 1247
Exploited Host
Web App Attack
๐ฎ๐ณ
evicky2002
2026-09-18 06:00:02
(10 hours ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐บ๐ธ
Epimetheus
2026-09-17 23:37:03
(16 hours ago)
Unauthorized access attempts:
[GET] /credentials.json
[GET] /docs/phpinfo.php
[GET] /administrator/ ...
show more
Unauthorized access attempts:
[GET] /credentials.json
[GET] /docs/phpinfo.php
[GET] /administrator/phpinfo.php
[GET] /sa.json
[GET] /_profiler/phpinfo
[GET] /smtp/phpinfo.php
[GET] /prestashop/.env
[GET] /wordpress/.env
[GET] /api/v3/.env
[GET] /.env.old
UA: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36
show less
Web App Attack
๐ธ๐ช
vaia.cloud
2026-09-17 22:35:01
(17 hours ago)
crowdsecurity/http-probing
Brute-Force
Web App Attack
๐ฉ๐ช
Gwyneth Llewelyn
2026-09-17 19:14:43
(20 hours ago)
2026/09/17 20:14:36 [error] 2807822#2807822: *377190 access forbidden by rule, client: 34.94.2.197, ...
show more
2026/09/17 20:14:36 [error] 2807822#2807822: *377190 access forbidden by rule, client: 34.94.2.197, server: webapp.gwynethllewelyn.net, request: "GET /.env HTTP/1.1", host: "webapp.gwynethllewelyn.net"
34.94.2.197 - - [17/Sep/2026:20:14:36 +0100] "GET /.env HTTP/1.1" 403 1178 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
2026/09/17 20:14:41 [error] 2807822#2807822: *377190 access forbidden by rule, client: 34.94.2.197, server: webapp.gwynethllewelyn.net, request: "GET /app/.env HTTP/1.1", host: "webapp.gwynethllewelyn.net"
show less
Brute-Force
Web App Attack
๐ฉ๐ช
webanyone
2026-09-17 17:47:30
(22 hours ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
๐ฉ๐ช
LRob
2026-09-17 17:35:18
(22 hours ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.git/config (+3 more) | 2026-09-17 17:35 UTC
show less
Hacking
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-17 17:31:37
(22 hours ago)
Excessive multi-domain requests
Brute-Force
Anonymous
2026-09-17 17:13:13
(22 hours ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
Anonymous
2026-09-17 16:55:44
(23 hours ago)
Blocked by siteaihub.com: auto: matched exact:/.git/config
Hacking
Bad Web Bot
Anonymous
2026-09-17 16:13:02
(23 hours ago)
Bot / scanning and/or hacking attempts: GET /.env1 HTTP/1.1, GET /.env.uat HTTP/1.1, GET /backend/.e ...
show more
Bot / scanning and/or hacking attempts: GET /.env1 HTTP/1.1, GET /.env.uat HTTP/1.1, GET /backend/.env HTTP/1.1, GET /site/.env HTTP/1.1, GET /core/app/.env HTTP/1.1, GET /config/.env HTTP/1.1, GET /.env.txt HTTP/1.1, GET /.env.yml HTTP/1.1, GET /core/.env HTTP/1.1, GET /.env.yaml HTTP/1.1, GET /frontend/.env HTTP/1.1, GET /server/.env HTTP/1.1, GET /src/.env HTTP/1.1, GET /.env.json HTTP/1.1, GET /admin/.env HTTP/1.1, GET /public/.env HTTP/1.1
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-17 15:38:06
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.94.2.197 (197.2.94.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.94.2.197 (197.2.94.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 11:38:02.934730 2026] [security2:error] [pid 25161:tid 25161] [client 34.94.2.197:48958] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "web71.dnchosting.com"] [uri "/.git/config"] [unique_id "aqwJWpewLu2pHY-Qnno8xwAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-17 14:56:08
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.94.2.197 (197.2.94.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.94.2.197 (197.2.94.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 10:56:04.643612 2026] [security2:error] [pid 6521:tid 6521] [client 34.94.2.197:58332] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "web50.dnchosting.com"] [uri "/.git/config"] [unique_id "aqv_hJrzMhoo_CSwMHu6FwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
Inartis
2026-09-17 14:53:16
(1 day ago)
34.94.2.197 - - [17/Sep/2026:16:53:15 +0200] "GET /.git/config HTTP/1.1" 404 418 "-" "Mozilla/5.0 (W ...
show more
34.94.2.197 - - [17/Sep/2026:16:53:15 +0200] "GET /.git/config HTTP/1.1" 404 418 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Vert Paysage
2026-09-17 14:41:36
(1 day ago)
SecurityShield WAF: Signature WAF [CRS-942180] critical โ Detects basic SQL authentication bypass at ...
show more
SecurityShield WAF: Signature WAF [CRS-942180] critical โ Detects basic SQL authentication bypass attempts 1/3
show less
Hacking