๐ฉ๐ช
raph
2026-09-16 06:28:08
(19 hours ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack
๐ฌ๐ง
openstrike.co.uk
2026-09-16 05:14:12
(20 hours ago)
167 attacks on VC URLs, config grabbing URLs (type 2), env grabbing URLs, PHP URLs, env grabbing URL ...
show more
167 attacks on VC URLs, config grabbing URLs (type 2), env grabbing URLs, PHP URLs, env grabbing URLs (type 2), password/key grabbing URLs:
GET /.git/HEAD HTTP/1.1
GET /app-config.json HTTP/1.1
GET /_image?href=/../../../.env HTTP/1.1
GET /icecoder/lib/terminal-xhr.php HTTP/1.1
GET /_image?href=/proc/self/environ HTTP/1.1
GET /__vite_rsc_findSourceMapURL?filename=file:///root/.aws/credentials&environmentName=rsc HTTP/1.1
show less
Hacking
Web App Attack
Anonymous
2026-09-16 04:15:07
(21 hours ago)
Aggressive web scan
Web App Attack
๐ฉ๐ช
Nightreaver
2026-09-16 04:13:41
(21 hours ago)
35.193.198.178 - - [16/Sep/2026:06:13:41 0200] "GET /static/manifest.json HTTP/1.1" 404 5719 "-" "M ...
show more
35.193.198.178 - - [16/Sep/2026:06:13:41 0200] "GET /static/manifest.json HTTP/1.1" 404 5719 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36 Edg/152.0.0.0"
35.193.198.178 - - [16/Sep/2026:06:13:41 0200] "GET /asset-manifest.json HTTP/1.1" 404 5719 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36 Edg/152.0.0.0"
35.193.198.178 - - [16/Sep/2026:06:13:41 0200] "GET /dist/manifest.json HTTP/1.1" 404 5719 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36 Edg/152.0.0.0"
35.193.198.178 - - [16/Sep/2026:06:13:41 0200] "GET /.github/workflows/deploy.yml HTTP/1.1" 404 5719 "-" "Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; https://kimi.ai/)"
35.193.198.178 - - [16/Sep/2026:06:13:41 0200] "GET /manifest.json HTTP/1.1" 404 5719 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Geck[...]
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 03:32:35
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.193.198.178 (178.198.193.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.193.198.178 (178.198.193.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 23:32:28.126744 2026] [security2:error] [pid 809:tid 809] [client 35.193.198.178:35204] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wilhelminas.biz"] [uri "/.git/config"] [unique_id "aqoNzA_amJpXAJYSTJkQjQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
tecnoacquisti.com
2026-09-16 02:45:08
(22 hours ago)
PrestaShop Security Module: suspicious probe path detected (/.env)
Web App Attack
๐บ๐ธ
CDO
2026-09-16 02:34:51
(23 hours ago)
URL Injection attempt detected. Automated web attack.
Hacking
Bad Web Bot
Web App Attack
๐จ๐ฆ
SoteriaCovenant
2026-09-16 02:28:13
(23 hours ago)
Automated probe: /.env.php.bak on Soteria Global infrastructure. No vulnerable software present.
Web App Attack
๐ต๐ฑ
sefinek.net
2026-09-16 01:56:01
(23 hours ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action: BLOCK | Protocol: HTTP/2 (POST) | Endpoin ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action: BLOCK | Protocol: HTTP/2 (POST) | Endpoint: /icecoder/lib/terminal-xhr.php | UA: Mozilla/5.0 (compatible; Meta-ExternalAgent/1.0; +https://developers.facebook.com/docs/sharing/webmasters/crawler) โข Generated by: github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ฎ๐ฉ
Burayot
2026-09-16 01:48:31
(23 hours ago)
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 35.193.198.178 (US/United States/178 ...
show more
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 35.193.198.178 (US/United States/178.198.193.35.bc.googleusercontent.com): 1 in the last 3600 secs
show less
Web App Attack
๐ฉ๐ช
Hazzard
2026-09-16 01:44:44
(23 hours ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted]): (CF_ENABLE)
Bad Web Bot
๐ฌ๐ง
andypiper
2026-09-16 01:03:00
(1 day ago)
CrowdSec ban for AbuseIPDB Top List
Brute-Force
Web App Attack
๐ณ๐ฑ
Savvii
2026-09-16 00:32:42
(1 day ago)
20 attempts against mh-misbehave-ban on ozone
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 00:17:56
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.193.198.178 (178.198.193.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.193.198.178 (178.198.193.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 20:17:53.342256 2026] [security2:error] [pid 29841:tid 29841] [client 35.193.198.178:52648] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "securityzonepr.com"] [uri "/.git/config"] [unique_id "aqngMZ5dKDwsV2tPOhiOYgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-16 00:09:42
(1 day ago)
Excessive multi-domain requests
Brute-Force