๐ฉ๐ช
MBombeck
2026-09-16 18:46:08
(1 day ago)
Fail2Ban/traefik-botsearch on apps-01: banned after 5 failures
Web App Attack
Anonymous
2026-09-16 13:45:03
(1 day ago)
Observed scanned 8 known-sensitive endpoint(s), e.g.: /.ssh/id_ed25519, /@fs/src/.env, /api/.env.bak ...
show more
Observed scanned 8 known-sensitive endpoint(s), e.g.: /.ssh/id_ed25519, /@fs/src/.env, /api/.env.bak, /api/templates/preview, /frontend/.env, /i.php
show less
Bad Web Bot
Web App Attack
๐ซ๐ท
IRISIO
2026-09-16 07:21:32
(1 day ago)
scans/SQL injection/spam posts : 1838 queries
Web App Attack
SQL Injection
๐ฌ๐ง
openstrike.co.uk
2026-09-16 05:14:49
(1 day ago)
311 attacks on password/key grabbing URLs, env grabbing URLs (type 2), PHP URLs, directory traversal ...
show more
311 attacks on password/key grabbing URLs, env grabbing URLs (type 2), PHP URLs, directory traversals, VC URLs, env grabbing URLs, config grabbing URLs (type 2):
GET /__vite_rsc_findSourceMapURL?filename=file:///root/.ssh/id_rsa&environmentName=rsc HTTP/1.1
GET /api/w/admins/jobs_u/get_log_file/../../../../proc/self/environ HTTP/1.1
POST /icecoder/lib/terminal-xhr.php HTTP/1.1
GET /..%2f..%2f.env HTTP/1.1
GET /.git/config HTTP/1.1
GET /__vite_rsc_findSourceMapURL?filename=file:///app/.env&environmentName=rsc HTTP/1.1
GET /secrets.json HTTP/1.1
show less
Hacking
Web App Attack
๐ง๐ช
taivas.nl
2026-09-16 04:34:48
(1 day ago)
Many_bad_calls
Web App Attack
๐ฎ๐ฉ
Burayot
2026-09-16 04:28:48
(1 day ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 35.185.65.129 (US/United States/129 ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 35.185.65.129 (US/United States/129.65.185.35.bc.googleusercontent.com): 1 in the last 3600 secs
show less
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-16 01:51:50
(1 day ago)
[cb-09al] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail apac ...
show more
[cb-09al] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail apache-404. Example: 35.185.65.129 - - [16/Sep/2026:03:51:48 +0200] "GET /z9x8c7v6b5-debug-trigger-12306.freightlounge.network HTTP/2.0" 404 1855 "-" "Mozilla/5.0 (compatible; Meta-ExternalAgent/1.0; +https://developers.facebook.com/docs/sharing/webmasters/crawler)"
35.185.65.129 - - [16/Sep/2026:03:51:48 +0200] "GET /.aws/config HTTP/2.0" 404 1855 "-" "Mozilla/5.0 (compatible; PanguBot/1.0; +https://www.huaweicloud.com/)"
35.185.65.129 - - [16/Sep/2026:03:51:48 +0200] "GET /api/.env HTTP/2.0" 404 1855 "-" "Mozilla/5.0 (compatible; YiBot/1.0; +https://01.ai/)"
35.185.65.129 - - [16/Sep/2026:03:51:48 +0200] "GET /sign-in HTTP/2.0" 404 1855 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWe
...
show less
Bad Web Bot
Web App Attack
๐ง๐ฌ
HighWay
2026-09-16 00:32:55
(1 day ago)
35.185.65.129 - - [16/Sep/2026:00:32:42 +0000] "GET /wp-json HTTP/1.1" 404 4756 "-" "Mozilla/5.0 (co ...
show more
35.185.65.129 - - [16/Sep/2026:00:32:42 +0000] "GET /wp-json HTTP/1.1" 404 4756 "-" "Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; +https://kimi.ai/)"
35.185.65.129 - - [16/Sep/2026:00:32:43 +0000] "GET /@fs/proc/self/cmdline?raw?? HTTP/1.1" 404 4757 "-" "Mozilla/5.0 (compatible; Google-Extended; +http://www.google.com/bot.html)"
35.185.65.129 - - [16/Sep/2026:00:32:43 +0000] "POST /graphql HTTP/1.1" 404 770 "https://vhelectronics.com" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
35.185.65.129 - - [16/Sep/2026:00:32:43 +0000] "POST /api/graphql HTTP/1.1" 404 770 "https://vhelectronics.com" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
35.185.65.129 - - [16/Sep/2026:00:32:43 +0000] "POST /v1/graphql HTTP/1.1" 404 770 "https://vhelectronics.com" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.
...
show less
Bad Web Bot
Web App Attack
๐ง๐ช
taivas.nl
2026-09-16 00:32:14
(1 day ago)
Site scraper
Web App Attack
๐ฎ๐ณ
evicky2002
2026-09-16 00:02:04
(1 day ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐บ๐ธ
thieuleu
2026-09-15 23:35:33
(1 day ago)
Unauthorized connection attempt blocked by firewall policy. Web application hardening active.
Brute-Force
Exploited Host
๐ช๐ธ
robotstxt
2026-09-15 23:21:14
(1 day ago)
35.185.65.129 - - [15/Sep/2026:23:20:44 +0000] "GET /wp-content/cache/autoptimize/js/autoptimize_35d ...
show more
35.185.65.129 - - [15/Sep/2026:23:20:44 +0000] "GET /wp-content/cache/autoptimize/js/autoptimize_35defa136bac878503da6272bb32cf5d.js HTTP/2.0" 403 165 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36 Edg/152.0.0.0" "-" edge="35.185.65.129"
35.185.65.129 - - [15/Sep/2026:23:20:45 +0000] "GET /?2f320d=5f7e84d405.js& HTTP/2.0" 403 2 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36 Edg/152.0.0.0" "-" edge="35.185.65.129"
35.185.65.129 - - [15/Sep/2026:23:20:45 +0000] "GET /wp-includes/js/dist/script-modules/block-library/navigation/view.min.js?ver=1bf28ded04f9f188bdcb HTTP/2.0" 403 15500 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36 Edg/152.0.0.0" "-" edge="35.185.65.129"
35.185.65.129 - - [15/Sep/2026:23:20:45 +0000] "GET /wp-includes/js/jquery/jquery.min.js HTTP/2.0"
...
show less
Web App Attack
๐ธ๐ฌ
Cloudkul Cloudkul
2026-09-15 23:11:33
(1 day ago)
Attempted Not Found (404 status code) requests on our application, more than 30% of their total requ ...
show more
Attempted Not Found (404 status code) requests on our application, more than 30% of their total requests.
show less
Brute-Force
Web App Attack
๐ซ๐ท
regishoussin
2026-09-15 23:02:57
(1 day ago)
Automated web scanning detected by Wazuh (rule 100241): repeated 400/404 errors from mass probing of ...
show more
Automated web scanning detected by Wazuh (rule 100241): repeated 400/404 errors from mass probing of admin/backdoor paths (e.g. wp-login.php, known CMS shell filenames) on an Apache web server, on 2026-09-15 23:02 UTC.
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
ecs.ge
2026-09-15 22:02:02
(1 day ago)
Automatic Fail2Ban report from jail plesk-modsecurity: multiple matching events detected.
Web App Attack
Hacking