๐ฉ๐ช
Vegascosmetics
2026-09-17 06:49:22
(1 hour ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after sensitive config/credentials exposure ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after sensitive config/credentials exposure probe. Evidence: AttackPattern: /\.env (Match: /.env)
show less
Hacking
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-17 06:46:34
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 35.201.174.7 (7.174.201.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.201.174.7 (7.174.201.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 02:46:29.662213 2026] [security2:error] [pid 2501:tid 2501] [client 35.201.174.7:49896] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "voodooshop.com"] [uri "/.env"] [unique_id "aquMxVmOHylJjs5TJpYXsgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Victor Lรณpez
2026-09-17 06:39:05
(1 hour ago)
videoprenatal.com 35.201.174.7 - - [17/Sep/2026:01:39:03 -0500] "GET /.env.live HTTP/2.0" 404 20698 ...
show more
videoprenatal.com 35.201.174.7 - - [17/Sep/2026:01:39:03 -0500] "GET /.env.live HTTP/2.0" 404 20698 "-" "Mozilla/5.0 (compatible; GrokBot/1.0; +https://x.ai/)" -
videoprenatal.com 35.201.174.7 - - [17/Sep/2026:01:39:03 -0500] "GET /.env.save HTTP/2.0" 404 20700 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot)" -
videoprenatal.com 35.201.174.7 - - [17/Sep/2026:01:39:04 -0500] "GET /.env.stage HTTP/2.0" 404 20703 "-" "Mozilla/5.0 (compatible; YiBot/1.0; +https://01.ai/)" -
...
show less
Hacking
Web App Attack
๐ฌ๐ง
Greg Poulson
2026-09-17 06:35:08
(1 hour ago)
Our website was hit by this DDOS at a rate of 121 in 5 minutes.
DDoS Attack
Web Spam
Brute-Force
๐ฉ๐ช
todix
2026-09-17 06:32:15
(1 hour ago)
Web App Attack Exploid from 35.201.174.7
Web App Attack
๐ท๐บ
olegio
2026-09-17 06:05:37
(2 hours ago)
35.201.174.7 - - [17/Sep/2026:06:05:36 +0000] "GET /@fs/src/.env?raw?? HTTP/2.0" 403 146 "-" "Mozill ...
show more
35.201.174.7 - - [17/Sep/2026:06:05:36 +0000] "GET /@fs/src/.env?raw?? HTTP/2.0" 403 146 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
35.201.174.7 - - [17/Sep/2026:06:05:36 +0000] "GET /@fs/app/.env?raw?? HTTP/2.0" 403 146 "-" "Mozilla/5.0 (compatible; Hunyuan/1.0; +https://hunyuan.tencent.com/)"
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-17 06:02:43
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.201.174.7 (7.174.201.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 35.201.174.7 (7.174.201.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 02:02:35.351769 2026] [security2:error] [pid 11324:tid 11324] [client 35.201.174.7:0] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||totalsafe-security.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "totalsafe-security.com"] [uri "/z9x8c7v6b5-debug-trigger-totalsafe-security.com"] [unique_id "aquCezj44CK2z1GAK9GKPAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ณ
evicky2002
2026-09-17 06:00:05
(2 hours ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
Anonymous
2026-09-17 05:59:40
(2 hours ago)
Detected by CrowdSec: crowdsecurity/http-bad-user-agent
Web App Attack
๐ฉ๐ช
gurnip
2026-09-17 05:41:58
(2 hours ago)
Vulnerability probe of page /auth/login, not found on the server.
Brute-Force
Web App Attack
๐ณ๐ฑ
Savvii
2026-09-17 05:29:14
(2 hours ago)
20 attempts against mh-misbehave-ban on ozone
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-17 05:04:37
(3 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 35.201.174.7 (TW/Taiwan/7.174.201.35.bc ...
show more
(mod_security) mod_security triggered on hostname [redacted] 35.201.174.7 (TW/Taiwan/7.174.201.35.bc.googleusercontent.com)
show less
SQL Injection
๐ณ๐ฑ
Savvii
2026-09-17 04:47:08
(3 hours ago)
20 attempts against mh-misbehave-ban on ethyl
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-17 02:56:32
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.201.174.7 (7.174.201.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.201.174.7 (7.174.201.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 22:56:26.386587 2026] [security2:error] [pid 29258:tid 29258] [client 35.201.174.7:59096] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ozkanturker.com"] [uri "/.github/.env"] [unique_id "aqtW2r6ytbfNzrMIWaV3FAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
voormedia
2026-09-17 02:46:37
(5 hours ago)
Accessed trap at '/.bashrc'
Web App Attack