๐บ๐ธ
deskpass.com
2026-09-19 13:38:12
(23 hours ago)
POST /lib/terminal-xhr.php
Web App Attack
๐บ๐ธ
kosada.com
2026-09-19 12:16:00
(1 day ago)
Repeated exploit attempts, for example: /api/graphql {x22queryx22:x22{ __schema { types { name field ...
show more
Repeated exploit attempts, for example: /api/graphql {x22queryx22:x22{ __schema { types { name fields { name args { name defaultValue } } } } }x22} (HTTP/2.0 port 443, user agent: "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36")
show less
Web App Attack
๐บ๐ธ
deskpass.com
2026-09-19 08:20:31
(1 day ago)
POST /icecoder/lib/terminal-xhr.php
Web App Attack
๐ฆ๐ช
CG
2026-09-19 00:56:05
(1 day ago)
Web application attack, Automated scan
Web App Attack
Hacking
SQL Injection
Anonymous
2026-09-18 21:53:45
(1 day ago)
malicious scanning tool activity
Web App Attack
๐จ๐ญ
dalslab ltd
2026-09-18 14:42:40
(1 day ago)
[18/Sep/2026:16:42:39 +0200] - 405 405 - POST https ai.dalslab.com "/" [Client 35.187.234.142] [Leng ...
show more
[18/Sep/2026:16:42:39 +0200] - 405 405 - POST https ai.dalslab.com "/" [Client 35.187.234.142] [Length 31] [Gzip -] [Sent-to 10.1.1.246] "Mozilla/5.0 (compatible; Google-Extended; +http://www.google.com/bot.html)" "-"
[18/Sep/2026:16:42:39 +0200] - 404 404 - GET https ai.dalslab.com "/static/manifest.json" [Client 35.187.234.142] [Length 22] [Gzip -] [Sent-to 10.1.1.246] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36" "-"
[18/Sep/2026:16:42:39 +0200] - 405 405 - POST https ai.dalslab.com "/graphql" [Client 35.187.234.142] [Length 31] [Gzip -] [Sent-to 10.1.1.246] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36" "https://ai.dalslab.com"
[18/Sep/2026:16:42:40 +0200] - 405 405 - POST https ai.dalslab.com "/api/graphql" [Client 35.187.234.142] [Length 31] [Gzip -] [Sent-to 10.1.1.246] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.
...
show less
Web Spam
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-18 11:31:54
(2 days ago)
Portscan: TCP/8080 (3x), TCP/8443 (3x)
Port Scan
๐ซ๐ท
vtchost.com
2026-09-18 05:57:12
(2 days ago)
scanning closed ports
...
Port Scan
๐ช๐ธ
robotstxt
2026-09-18 03:54:52
(2 days ago)
35.187.234.142 - - [18/Sep/2026:03:53:50 +0000] "GET /@fs/src/.env?import&raw?? HTTP/2.0" 403 27649 ...
show more
35.187.234.142 - - [18/Sep/2026:03:53:50 +0000] "GET /@fs/src/.env?import&raw?? HTTP/2.0" 403 27649 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot)" "35.187.234.142" edge="162.158.170.139"
35.187.234.142 - - [18/Sep/2026:03:53:50 +0000] "GET /z9x8c7v6b5-debug-trigger-intranet.ccoo.app HTTP/2.0" 403 27700 "-" "Mozilla/5.0 (compatible; Bravebot/1.0; +https://brave.com/search/)" "35.187.234.142" edge="162.158.170.139"
35.187.234.142 - - [18/Sep/2026:03:53:50 +0000] "GET /public../.env HTTP/2.0" 403 27649 "-" "Mozilla/5.0 (compatible; xAI-Grok/1.0; +https://x.ai/)" "35.187.234.142" edge="162.158.170.139"
35.187.234.142 - - [18/Sep/2026:03:53:50 +0000] "GET /@fs/../.env?import&raw?? HTTP/2.0" 403 27649 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexitybot)" "35.187.234.142" edge="162.158.170.139"
35.187.234.142 - - [18/Sep/2026:03:53:50 +0000]
...
show less
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-09-18 01:17:03
(2 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 1247
Exploited Host
Web App Attack
๐ธ๐ฌ
Cloudkul Cloudkul
2026-09-18 00:55:10
(2 days ago)
Attempted Brute Force on our application
Brute-Force
Web App Attack
Anonymous
2026-09-17 18:10:48
(2 days ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-17 16:09:47
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.187.234.142 (142.234.187.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.187.234.142 (142.234.187.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 12:09:41.100812 2026] [security2:error] [pid 2602:tid 2602] [client 35.187.234.142:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.portfoliolighting.net"] [uri "/__vite_rsc_findSourceMapURL"] [unique_id "aqwQxba_pH1iHsbvZg7tVAAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ต๐น
WebTejo
2026-09-17 16:01:57
(2 days ago)
Detected multiple authentication failures and invalid user attempts in LF_CPANEL from IP address 35. ...
show more
Detected multiple authentication failures and invalid user attempts in LF_CPANEL from IP address 35.187.234.142 on [PT] Tucano Node.
show less
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-09-17 15:53:21
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.187.234.142 (142.234.187.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.187.234.142 (142.234.187.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 11:53:16.672656 2026] [security2:error] [pid 9234:tid 9234] [client 35.187.234.142:37408] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.cephedanisman.com"] [uri "/@fs/proc/self/cwd/.env"] [unique_id "aqwM7CqBuB8upzGEWFEj_QAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack