🇳🇱
Site.eu
2026-09-17 02:51:55
(4 days ago)
Excessive multi-domain requests
Brute-Force
🇫🇷
IRISIO
2026-09-16 10:46:19
(4 days ago)
scans/SQL injection/spam posts : 1514 queries
Web App Attack
SQL Injection
🇬🇧
openstrike.co.uk
2026-09-16 05:14:41
(5 days ago)
346 attacks on PHP URLs, env grabbing URLs (type 2), password/key grabbing URLs, VC URLs, directory ...
show more
346 attacks on PHP URLs, env grabbing URLs (type 2), password/key grabbing URLs, VC URLs, directory traversals, config grabbing URLs (type 2), env grabbing URLs:
POST /icecoder/lib/terminal-xhr.php HTTP/1.1
GET /_image?href=/proc/self/environ HTTP/1.1
GET /__vite_rsc_findSourceMapURL?filename=file:///root/.ssh/id_rsa&environmentName=rsc HTTP/1.1
GET /.git/HEAD HTTP/1.1
GET /..%2f.env HTTP/1.1
GET /appsettings.Development.json HTTP/1.1
GET /_image?href=/../../../.env HTTP/1.1
show less
Web App Attack
Hacking
🇧🇪
taivas.nl
2026-09-16 04:34:14
(5 days ago)
Many_bad_calls
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-16 02:54:09
(5 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/grafana-cve-2021-43798
Web App Attack
Hacking
🇳🇱
ConsulHosting
2026-09-16 02:10:30
(5 days ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack
🇫🇷
sthoyer.de
2026-09-16 02:00:41
(5 days ago)
35.196.122.244 - - [16/Sep/2026:04:00:40 +0200] "GET /secure HTTP/2" 302 495 "-" "Mozilla/5.0 (Macin ...
show more
35.196.122.244 - - [16/Sep/2026:04:00:40 +0200] "GET /secure HTTP/2" 302 495 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36 Edg/152.0.0.0"
35.196.122.244 - - [16/Sep/2026:04:00:40 +0200] "GET /img../.env HTTP/2" 302 495 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; [email protected] )"
35.196.122.244 - - [16/Sep/2026:04:00:40 +0200] "GET /@fs/home/ubuntu/.aws/credentials?raw?? HTTP/2" 302 495 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot)"
...
show less
Web App Attack
Anonymous
2026-09-16 01:27:53
(5 days ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
🇺🇸
TPI-Abuse
2026-09-16 01:06:24
(5 days ago)
(mod_security) mod_security (id:210730) triggered by 35.196.122.244 (244.122.196.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.196.122.244 (244.122.196.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 21:06:19.626633 2026] [security2:error] [pid 23924:tid 23924] [client 35.196.122.244:41970] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||sobhrach.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "sobhrach.com"] [uri "/z9x8c7v6b5-debug-trigger-sobhrach.com"] [unique_id "aqnri6a37XnP3T0Zas_3BAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
andypiper
2026-09-16 01:02:53
(5 days ago)
CrowdSec ban for AbuseIPDB Top List
Brute-Force
Web App Attack
🇳🇱
Savvii
2026-09-16 00:37:45
(5 days ago)
20 attempts against mh-misbehave-ban on ozone
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-16 00:37:20
(5 days ago)
(mod_security) mod_security (id:210580) triggered by 35.196.122.244 (244.122.196.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210580) triggered by 35.196.122.244 (244.122.196.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 20:37:15.174959 2026] [security2:error] [pid 13799:tid 13799] [client 35.196.122.244:57620] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "proc/self/environ" at ARGS:filename. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/08_Global_Other.conf"] [line "57"] [id "210580"] [rev "2"] [msg "COMODO WAF: OS File Access Attempt||snowmanchristmascards.net|F|2"] [data "Matched Data: proc/self/environ found within ARGS:filename: file:/proc/self/environ"] [severity "CRITICAL"] [tag "CWAF"] [tag "Other"] [hostname "snowmanchristmascards.net"] [uri "/__vite_rsc_findSourceMapURL"] [unique_id "aqnkux4Jz-5iGh5okpj_VgAAAIM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇵🇱
sefinek.net
2026-09-16 00:20:31
(5 days ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action: BLOCK | Protocol: HTTP/2 (GET) | Endpoint ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action: BLOCK | Protocol: HTTP/2 (GET) | Endpoint: /public/.env | UA: Mozilla/5.0 (compatible; cohere-ai; +https://cohere.com/crawler) • Generated by: github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-16 00:17:45
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 35.196.122.244 (244.122.196.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.196.122.244 (244.122.196.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 20:17:41.400181 2026] [security2:error] [pid 24375:tid 24375] [client 35.196.122.244:53712] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "snickerifabrik.com"] [uri "/@fs/src/.env"] [unique_id "aqngJdqI2tu_PnJESq671wAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
middelkoopcc
2026-09-16 00:10:01
(5 days ago)
2026-09-16 02:08:01 GET /api/uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2f.env [404] && 2026-09-16 02:08:01 GE ...
show more
2026-09-16 02:08:01 GET /api/uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2f.env [404] && 2026-09-16 02:08:01 GET /api/uploads/%2e%2e%2f%2e%2e%2f.env [404] && 2026-09-16 02:08:01 GET /api/attachments/img/avatar/..%2F..%2F..%2F..%2F..%2F.env [404] && 199 more within 20 minutes
show less
Web App Attack