๐ฟ๐ฆ
conure.sh
2026-10-02 04:30:59
(3 days ago)
csagent: score 19.9: secrets grab x1, spoofed crawler UA x1; 1 domain(s) in 10s
Web App Attack
๐บ๐ธ
Mundo Bueno
2026-10-02 03:30:24
(3 days ago)
[ISILIA Protection v2.3] Tentative d'accรจs: /@fs/root/.aws/credentials [RATE LIMITED - 1800s quarant ...
show more
[ISILIA Protection v2.3] Tentative d'accรจs: /@fs/root/.aws/credentials [RATE LIMITED - 1800s quarantine] | Pays: CA | UA: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perplexity-User/1.0; +https://perplex
show less
Hacking
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-10-02 00:19:00
(3 days ago)
Try to access /@fs/proc/self/cwd/.env?raw??
Web App Attack
๐บ๐ธ
agenciahypelab.com.br
2026-10-01 23:54:14
(3 days ago)
WordPress login brute-force detectado e bloqueado pelo CSF/LFD. Trigger: LF_TRIGGER
Brute-Force
SSH
๐ง๐ช
cmbplf
2026-10-01 23:18:40
(3 days ago)
3.187 requests from abuseipdb.com blacklisted IP (7mos2w3d)
Brute-Force
Bad Web Bot
Anonymous
2026-10-01 21:23:45
(3 days ago)
Web App Attack
Anonymous
2026-10-01 21:13:41
(3 days ago)
(mod_security) mod_security triggered on hostname [redacted] 35.203.79.136 (CA/Canada/136.79.203.35. ...
show more
(mod_security) mod_security triggered on hostname [redacted] 35.203.79.136 (CA/Canada/136.79.203.35.bc.googleusercontent.com)
show less
SQL Injection
๐จ๐ฆ
polycoda
2026-10-01 20:58:09
(3 days ago)
AutoBlock: ๐ฏ Vulnerability Scanner (Non Decay-Based) - ๐ก Port Scan (Non Decay-Based) - โ Excessive 4 ...
show more
AutoBlock: ๐ฏ Vulnerability Scanner (Non Decay-Based) - ๐ก Port Scan (Non Decay-Based) - โ Excessive 40X Errors (Decay-Based)
show less
Port Scan
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 18:30:30
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 35.203.79.136 (136.79.203.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.203.79.136 (136.79.203.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 14:30:23.916892 2026] [security2:error] [pid 8749:tid 8774] [client 35.203.79.136:54846] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.trident-environmental.com|F|2"] [data ".trident-environmental.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.trident-environmental.com"] [uri "/z9x8c7v6b5-debug-trigger-www.trident-environmental.com"] [unique_id "ar6mvx_9tYhSxj-5cYdD1wAAAFc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
JonathanYoung2161
2026-10-01 18:10:32
(3 days ago)
trekgalactic.org 35.203.79.136 - - [01/Oct/2026:13:10:31 -0500] "GET /secrets.json HTTP/2.0" 403 333 ...
show more
trekgalactic.org 35.203.79.136 - - [01/Oct/2026:13:10:31 -0500] "GET /secrets.json HTTP/2.0" 403 3330 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36; compatible; OAI-SearchBot/1.4; +https://openai.com/searchbot"
trekgalactic.org 35.203.79.136 - - [01/Oct/2026:13:10:31 -0500] "GET /config/env/aws_credentials.env HTTP/2.0" 404 3360 "-" "Mozilla/5.0 (compatible; Meta-ExternalAgent/1.0; +https://developers.facebook.com/docs/sharing/webmasters/crawler)"
trekgalactic.org 35.203.79.136 - - [01/Oct/2026:13:10:31 -0500] "GET /secrets.yml HTTP/2.0" 403 3330 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; [email protected] )"
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 18:07:54
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.203.79.136 (136.79.203.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.203.79.136 (136.79.203.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 14:07:50.051962 2026] [security2:error] [pid 1344:tid 1344] [client 35.203.79.136:52848] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.tribalvisions.net"] [uri "/images../.env"] [unique_id "ar6hdrrQkAN_Iv6hG3YFEAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-01 17:43:33
(3 days ago)
Sensitive file access attempt
Hacking
๐ฉ๐ช
itsolon
2026-10-01 16:31:17
(3 days ago)
[01/Oct/2026:18:31:10 +0200] 179087227019.331749 35.203.79.136 0 217.154.7.177 443
[01/Oct/2026:18:3 ...
show more
[01/Oct/2026:18:31:10 +0200] 179087227019.331749 35.203.79.136 0 217.154.7.177 443
[01/Oct/2026:18:31:14 +0200] 179087227427.000558 35.203.79.136 0 217.154.7.177 443
[01/Oct/2026:18:31:14 +0200] 179087227414.534348 35.203.79.136 0 217.154.7.177 443
[01/Oct/2026:18:31:15 +0200] 179087227545.018901 35.203.79.136 0 217.154.7.177 443
[01/Oct/2026:18:31:16 +0200] 179087227614.481977 35.203.79.136 0 217.154.7.177 443
...
show less
Port Scan
Hacking
Brute-Force
Web App Attack
๐ฉ๐ช
yitzhaq
2026-10-01 16:18:00
(3 days ago)
35.203.79.136 - - [01/Oct/2026:18:17:58 +0200] "GET /secure HTTP/2.0" 302 407 "-" "Mozilla/5.0 (Linu ...
show more
35.203.79.136 - - [01/Oct/2026:18:17:58 +0200] "GET /secure HTTP/2.0" 302 407 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Mobile Safari/537.36"
35.203.79.136 - - [01/Oct/2026:18:17:58 +0200] "POST /api/graphql HTTP/2.0" 302 407 "https://[site]" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Mobile Safari/537.36"
35.203.79.136 - - [01/Oct/2026:18:17:58 +0200] "GET /appearance/../../proc/self/environ HTTP/2.0" 400 328 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; [email])"
35.203.79.136 - - [01/Oct/2026:18:17:58 +0200] "GET /icons/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/proc/self/environ HTTP/2.0" 400 328 "-" "Mozilla/5.0 (compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot)"
35.203.79.136 - - [01/Oct/2026:18:17:58 +0200] "GET /admin%2F.env HTTP/2.0" 404 298 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perplexity-User/1.
show less
Web App Attack
Hacking
๐ฟ๐ฆ
conure.sh
2026-10-01 15:57:49
(3 days ago)
csagent: score 21.7: 404 noise floor x7, spoofed crawler UA x1, secrets grab x1; 1 domain(s) in 2s
Web App Attack