๐ง๐ท
dermatovirtual
2026-09-17 13:26:35
(3 hours ago)
Dermato Virtual CSIRT: Malicious web exploit/scanning probes against app.dermatovirtual.com.br (Web ...
show more
Dermato Virtual CSIRT: Malicious web exploit/scanning probes against app.dermatovirtual.com.br (Web Server Ports 80/443). 58 unauthorized requests recorded between 2026-09-17 13:24:23 UTC and 2026-09-17 13:24:35 UTC (rate: ~58 req/min). Edge perimeter firewall drop active.
Log sample:
[2026-09-17 13:24:34 UTC] IP: 35.201.194.70 - W3C IIS (Port 443): GET /api/.env/public/.env -> HTTP 404 [CLIENT: 35.201.194.70]
[2026-09-17 13:24:35 UTC] IP: 35.201.194.70 - W3C IIS (Port 443): GET /images../.env -> HTTP 404 [CLIENT: 35.201.194.70]
[2026-09-17 13:24:35 UTC] IP: 35.201.194.70 - W3C IIS (Port 443): GET /assets../.env -> HTTP 404 [CLIENT: 35.201.194.70]
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
ConsulHosting
2026-09-17 11:43:52
(5 hours ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack
Anonymous
2026-09-17 09:05:11
(7 hours ago)
Aggressive web scan
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-17 09:03:20
(7 hours ago)
[cb-11al] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail apac ...
show more
[cb-11al] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail apache-404. Example: 35.201.194.70 - - [17/Sep/2026:11:03:18 +0200] "GET /.vscode/launch.json HTTP/2.0" 404 1855 "-" "Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; +https://kimi.ai/)"
35.201.194.70 - - [17/Sep/2026:11:03:18 +0200] "GET /z9x8c7v6b5-debug-trigger-account.trustautolease.nl HTTP/2.0" 404 1855 "-" "Mozilla/5.0 (compatible; Google-Extended; +http://www.google.com/bot.html)"
35.201.194.70 - - [17/Sep/2026:11:03:18 +0200] "GET /signin HTTP/2.0" 404 1855 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36 Edg/152.0.0.0"
35.201.194.70 - - [17/Sep/2026:11:03:18 +0200] "GET /login HTTP/2.0" 404 1855 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKi
...
show less
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
zam
2026-09-17 08:34:59
(8 hours ago)
35.201.194.70 - - [17/Sep/2026:08:34:50 +0000] "GET /ssl/localhost.key HTTP/1.1" 404 27380
35.201.19 ...
show more
35.201.194.70 - - [17/Sep/2026:08:34:50 +0000] "GET /ssl/localhost.key HTTP/1.1" 404 27380
35.201.194.70 - - [17/Sep/2026:08:34:50 +0000] "GET /rclone.conf HTTP/1.1" 404 27380
35.201.194.70 - - [17/Sep/2026:08:34:50 +0000] "GET /z9x8c7v6b5-debug-trigger-zamit.id HTTP/1.1" 404 27380
35.201.194.70 - - [17/Sep/2026:08:34:50 +0000] "GET /.vite/manifest.json HTTP/1.1" 404 27380
35.201.194.70 - - [17/Sep/2026:08:34:50 +0000] "GET /build/manifest.json HTTP/1.1" 404 27380
35.201.194.70 - - [17/Sep/2026:08:34:50 +0000] "GET /host.key HTTP/1.1" 404 27380
show less
Web App Attack
๐ฌ๐ง
WebNiraj
2026-09-17 08:27:24
(8 hours ago)
(mod_security) mod_security (id:949110) triggered by 35.201.194.70 (TW/Taiwan/70.194.201.35.bc.googl ...
show more
(mod_security) mod_security (id:949110) triggered by 35.201.194.70 (TW/Taiwan/70.194.201.35.bc.googleusercontent.com): 5 in the last 3600 secs [SIGMA]
show less
Brute-Force
๐ฉ๐ช
Vegascosmetics
2026-09-17 07:49:26
(9 hours ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after matched multi-pattern attack signatur ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after matched multi-pattern attack signature. Evidence: AttackPattern: /server\.key (Match: /server.key)
show less
Hacking
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-17 07:13:37
(9 hours ago)
[ti-tinov] Web exploit scanning: 1 suspicious requests detected by fail2ban jail <name>. Example: 35 ...
show more
[ti-tinov] Web exploit scanning: 1 suspicious requests detected by fail2ban jail <name>. Example: 35.201.194.70 - - \[17/Sep/2026:09:13:33 +0200\] "GET /.env.backup HTTP/1.1" 404 169839 "-" "Mozilla/5.0 \(compatible\; KimiBot/1.0\; +https://kimi.ai/\)"
...
show less
Bad Web Bot
Web App Attack
๐ฌ๐ง
Apache
2026-09-17 07:00:53
(9 hours ago)
(mod_security) mod_security (id:911100) triggered by 35.201.194.70 (TW/Taiwan/70.194.201.35.bc.googl ...
show more
(mod_security) mod_security (id:911100) triggered by 35.201.194.70 (TW/Taiwan/70.194.201.35.bc.googleusercontent.com): 5 in the last 300 secs (CF_ENABLE)
show less
Brute-Force
Web App Attack
๐ฉ๐ช
niedson
2026-09-17 07:00:02
(9 hours ago)
Automated scanning for exposed secrets: repeated requests for multiple distinct credential paths (.e ...
show more
Automated scanning for exposed secrets: repeated requests for multiple distinct credential paths (.env variants, .git metadata, .ssh private keys, .aws/credentials). Unsolicited. Reported automatically.
show less
Web App Attack
๐ฉ๐ช
LRob
2026-09-17 06:35:16
(10 hours ago)
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: ...
show more
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: /build/manifest.json (+9 more) | ua: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-SearchBot/1.0; [email protected] ) (+1 more) | 2026-09-17 06:35 UTC
show less
Hacking
Web App Attack
๐ฎ๐ณ
evicky2002
2026-09-17 06:00:05
(10 hours ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-09-17 05:41:42
(11 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.201.194.70 (70.194.201.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.201.194.70 (70.194.201.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 01:41:35.825882 2026] [security2:error] [pid 27618:tid 27618] [client 35.201.194.70:39714] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||savoiapower.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "savoiapower.com"] [uri "/z9x8c7v6b5-debug-trigger-savoiapower.com"] [unique_id "aqt9jxBcarHU1uAzCEWtlQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FD-IX
2026-09-17 05:03:14
(11 hours ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
๐ฐ๐ท
ZEROVOX
2026-09-17 04:22:32
(12 hours ago)
CrowdSec: crowdsecurity/http-probing detected
Web App Attack