๐ฎ๐ณ
evicky2002
2026-09-17 06:00:05
(2 days ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐ง๐ช
Ivo Vynckier
2026-09-16 14:17:00
(3 days ago)
35.196.194.248 - - [15/Sep/2026:18:07:30 +0200] "GET /.env HTTP/2.0" 403 106 "-" "Mozilla/5.0 (compa ...
show more
35.196.194.248 - - [15/Sep/2026:18:07:30 +0200] "GET /.env HTTP/2.0" 403 106 "-" "Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; +https://kimi.ai/)"
35.196.194.248 - - [15/Sep/2026:18:07:30 +0200] "GET /.env.example HTTP/2.0" 403 106 "-" "Mozilla/5.0 (compatible; KimiBot/1.0; +https://kimi.ai/)"
35.196.194.248 - - [15/Sep/2026:18:07:30 +0200] "GET /.github/workflows/deploy.yml HTTP/2.0" 403 106 "-" "Mozilla/5.0 (compatible; PanguBot/1.0; +https://www.huaweicloud.com/)"
35.196.194.248 - - [15/Sep/2026:18:07:30 +0200] "GET /rclone.conf HTTP/2.0" 404 2310 "-" "CCBot/2.0 (https://commoncrawl.org/faq/)"
show less
Web App Attack
๐ฌ๐ง
openstrike.co.uk
2026-09-16 05:14:47
(3 days ago)
465 attacks on VC URLs, directory traversals, config grabbing URLs (type 2), env grabbing URLs, env ...
show more
465 attacks on VC URLs, directory traversals, config grabbing URLs (type 2), env grabbing URLs, env grabbing URLs (type 2), PHP URLs, password/key grabbing URLs:
GET /.git/HEAD HTTP/1.1
GET /..%2f..%2f.env HTTP/1.1
GET /secrets.json HTTP/1.1
GET /__vite_rsc_findSourceMapURL?filename=file:///app/.env&environmentName=rsc HTTP/1.1
GET /__vite_rsc_findSourceMapURL?filename=file:///proc/self/environ&environmentName=rsc HTTP/1.1
POST /icecoder/lib/terminal-xhr.php HTTP/1.1
GET /.ssh/id_ecdsa HTTP/1.1
show less
Hacking
Web App Attack
๐ฉ๐ช
Marc
2026-09-16 03:29:28
(3 days ago)
35.196.194.248 - - [16/Sep/2026:05:29:28 +0200] "GET /signin HTTP/2.0" 404 291 "-" "Mozilla/5.0 (Mac ...
show more
35.196.194.248 - - [16/Sep/2026:05:29:28 +0200] "GET /signin HTTP/2.0" 404 291 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36" 35.196.194.248 - - [16/Sep/2026:05:29:28 +0200] "GET /auth HTTP/2.0" 404 269 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36" 35.196.194.248 - - [16/Sep/2026:05:29:28 +0200] "GET /auth/login HTTP/2.0" 404 269 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36"
show less
Brute-Force
๐ณ๐ฑ
Alt255
2026-09-16 01:04:08
(4 days ago)
[ti-22al] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail apac ...
show more
[ti-22al] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail apache-404. Example: 35.196.194.248 - - [16/Sep/2026:03:03:50 +0200] "GET /z9x8c7v6b5-debug-trigger-126.mediarotterdam.nl HTTP/2.0" 404 1878 "-" "Mozilla/5.0 (compatible; Bravebot/1.0; +https://brave.com/search/)"
35.196.194.248 - - [16/Sep/2026:03:03:50 +0200] "GET /rclone.conf HTTP/2.0" 404 1855 "-" "CCBot/2.0 (https://commoncrawl.org/faq/)"
35.196.194.248 - - [16/Sep/2026:03:03:50 +0200] "GET /@fs/var/run/secrets/kubernetes.io/serviceaccount/token?raw?? HTTP/2.0" 404 1855 "-" "Mozilla/5.0 (compatible; Bravebot/1.0; +https://brave.com/search/)"
35.196.194.248 - - [16/Sep/2026:03:03:50 +0200] "GET /__vite_rsc_findSourceMapURL?filename=file:///root/.ssh/id_rsa&environmentName=rsc HTTP/2.0" 404 1855 "-" "Mozilla/5.0 (compatible; Goo
...
show less
Bad Web Bot
Web App Attack
๐ฌ๐ง
andypiper
2026-09-16 01:02:19
(4 days ago)
CrowdSec ban for AbuseIPDB Top List
Brute-Force
Web App Attack
๐จ๐ฆ
lakered
2026-09-16 00:11:34
(4 days ago)
Detectors: [NGINX, SURICATA] | Reasons: Suricata: Web Server attack | Automated scan targeting an un ...
show more
Detectors: [NGINX, SURICATA] | Reasons: Suricata: Web Server attack | Automated scan targeting an unauthorized host or default server sinkhole | Evidence: Verified-Bot-JA4-Match (t13d1516h2) | TCP Fingerprint: Modern Linux (Kernel 3.x+) (Link:generic tunnel or VPN, Uptime:0m)
show less
Web App Attack
Hacking
Port Scan
Bad Web Bot
๐ฌ๐ง
noise.agency
2026-09-16 00:03:00
(4 days ago)
35.196.194.248 (US/United States/248.194.196.35.bc.googleusercontent.com), more than 10 Apache 403 h ...
show more
35.196.194.248 (US/United States/248.194.196.35.bc.googleusercontent.com), more than 10 Apache 403 hits
show less
Hacking
๐ธ๐ฌ
khairilgunawan
2026-09-16 00:01:11
(4 days ago)
ZonaKuota Sentinel: Malicious automated scanner/exploit probe trapped. Blocked.
Web App Attack
Bad Web Bot
๐บ๐ธ
antlac1
2026-09-15 23:52:51
(4 days ago)
crowdsecurity/http-probing
Brute-Force
Web App Attack
๐ท๐ด
clauss
2026-09-15 23:39:48
(4 days ago)
35.196.194.248 - - [16/Sep/2026:02:38:23 +0300] "GET /rclone.conf HTTP/2.0" 403 146 "-" "Mozilla/5.0 ...
show more
35.196.194.248 - - [16/Sep/2026:02:38:23 +0300] "GET /rclone.conf HTTP/2.0" 403 146 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; [email protected] )"
35.196.194.248 - - [16/Sep/2026:02:39:46 +0300] "GET /rclone.conf HTTP/2.0" 403 146 "-" "DuckAssistBot/1.1 (https://duckduckgo.com/duckassistbot)"
...
show less
Web App Attack
๐ณ๐ฑ
thedreamer.nl
2026-09-15 23:33:10
(4 days ago)
35.196.194.248 - - [16/Sep/2026:01:31:18 +0200] "GET /static../.env HTTP/2.0" 200 995 "-" "Mozilla/5 ...
show more
35.196.194.248 - - [16/Sep/2026:01:31:18 +0200] "GET /static../.env HTTP/2.0" 200 995 "-" "Mozilla/5.0 (compatible; Meta-ExternalAgent/1.0; +https://developers.facebook.com/docs/sharing/webmasters/crawler)" "US" "North Charleston" "32.86080" "-79.97460"
35.196.194.248 - - [16/Sep/2026:01:31:18 +0200] "GET /media../.env HTTP/2.0" 200 995 "-" "Mozilla/5.0 (compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot)" "US" "North Charleston" "32.86080" "-79.97460"
35.196.194.248 - - [16/Sep/2026:01:31:18 +0200] "GET /_nuxt/../.env HTTP/2.0" 200 995 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ChatGPT-User/1.0; +https://openai.com/bot)" "US" "North Charleston" "32.86080" "-79.97460"
35.196.194.248 - - [16/Sep/2026:01:31:18 +0200] "GET /files../.env HTTP/2.0" 200 995 "-" "Mozilla/5.0 (compatible; MistralAI-User/1.0; +https://mistral.ai/)" "US" "North Charleston" "32.86080" "-79.97460"
...
show less
Hacking
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ท
dominioz
2026-09-15 23:30:35
(4 days ago)
2026-09-15 23:29:50 GET /.env - - 35.196.194.248 HTTP/2 Mozilla/5.0+(compatible;+Baiduspider/2.0;++h ...
show more
2026-09-15 23:29:50 GET /.env - - 35.196.194.248 HTTP/2 Mozilla/5.0+(compatible;+Baiduspider/2.0;++http://www.baidu.com/search/spider.html) - 301 466
2026-09-15 23:29:50 GET /.env.example - - 35.196.194.248 HTTP/2 Mozilla/5.0+(compatible;+Qwenbot/1.0;++https://qwen.alibaba.com/) - 301 466
2026-09-15 23:29:50 GET /.env.local - - 35.196.194.248 HTTP/2 CCBot/2.0+(https://commoncrawl.org/faq/) - 301 466
2026-09-15 23:29:50 GET /.env.backup - - 35.196.194.248 HTTP/2 Mozilla/5.0+AppleWebKit/537.36+(KHTML,+like+Gecko;+compatible;+Claude-User/1.0;[email protected] ) - 301 466
2026-09-15 23:29:50 GET /.env.production - - 35.196.194.248 HTTP/2 Mozilla/5.0+(compatible;+Baiduspider/2.0;++http://www.baidu.com/search/spider.html) - 301 466
2026-09-15 23:29:50 GET /.env.old - - 35.196.194.248 HTTP/2 Mozilla/5.0+(compatible;+Bravebot/1.0;++https://brave.com/search/) - 301 466
2026-09-15 23:29:50 GET /.env.bak - - 35.196.194.248 HTTP/2 DuckAssistBot/1.1+(https://duckduckgo.com/duckassistbot) - 3
...
show less
Web App Attack
๐ฎ๐น
www.tana.it
2026-09-15 23:29:50
(4 days ago)
PHP scan
Web App Attack
๐บ๐ธ
CDO
2026-09-15 23:24:03
(4 days ago)
URL Injection attempt detected. Automated web attack.
Hacking
Bad Web Bot
Web App Attack