Anonymous
2026-09-12 21:00:07
(15 hours ago)
CVE-2025-30208 - ViteJS Traversal Exploit - HTTP(Request)
Hacking
🇳🇱
Eric
2026-09-12 20:49:03
(15 hours ago)
[Sat Sep 12 20:48:59.998691 2026] [security2:error] [pid 4062054:tid 4062054] [client 35.237.251.135 ...
show more
[Sat Sep 12 20:48:59.998691 2026] [security2:error] [pid 4062054:tid 4062054] [client 35.237.251.135:56702] [client 35.237.251.135] ModSecurity: Warning. Pattern match "^[\\\\d.:]+$" at REQUEST_HEADERS:Host. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "736"] [id "920350"] [msg "Host header is a numeric IP address"] [data "94.209.38.171:443"] [severity "WARNING"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "94.209.38.171"] [uri "/"] [unique_id "aqW6u5ngiQ8_5wpnDBYayAAAACI"]
[Sat Sep 12 20:49:02.789187 2026] [security2:error] [pid 4126730:tid 4126730] [client 35.237.251.135:56706] [client 35.237.251.135] ModSecurity: Warning. Pattern match "^[\\\\d.:]+$" at REQUEST_HEADERS:Host. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "736"] [id
...
show less
Hacking
Web App Attack
🇺🇸
MPL
2026-09-12 18:50:57
(17 hours ago)
tcp port scan (8 or more attempts)
Port Scan
🇯🇵
VXG-NET
2026-09-12 18:33:21
(18 hours ago)
port=80, indicator_type=info-leak
Hacking
🇫🇷
COMAITE
2026-09-12 17:47:15
(18 hours ago)
Common web attack from 35.237.251.135.
Web App Attack
🇳🇱
globcom
2026-09-12 17:07:34
(19 hours ago)
General hacking/exploits/scanning
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 16:37:48
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.237.251.135 (135.251.237.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.237.251.135 (135.251.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 12:37:41.057829 2026] [security2:error] [pid 25157:tid 25157] [client 35.237.251.135:3586] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.108"] [uri "/static../.env"] [unique_id "aqV_1emV1ZlXj9QW7aK-kwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
dynamix
2026-09-12 12:30:22
(1 day ago)
Multiple WAF Violations
Web App Attack
🇦🇺
Lazarus
2026-09-12 08:22:14
(1 day ago)
HTTP probe.
Web App Attack
🇧🇾
lns.bz
2026-09-11 17:32:40
(1 day ago)
.env scanning [BY]
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 16:52:54
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.237.251.135 (135.251.237.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.237.251.135 (135.251.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 12:52:50.465599 2026] [security2:error] [pid 32341:tid 32341] [client 35.237.251.135:46980] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.151.12"] [uri "/static../.env"] [unique_id "aqQx4jkJFoV-XQfKOa0gegAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
enpepet
2026-09-11 14:18:37
(1 day ago)
GENERAL: parametres: [url:env=] UA:Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like G ...
show more
GENERAL: parametres: [url:env=] UA:Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko; compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot) Chrome/151.0.2659.10 Safari/537.36 URL:/static../.env
show less
Port Scan
Hacking
Brute-Force
Bad Web Bot
🇺🇸
IndigoRidge
2026-09-11 06:55:15
(2 days ago)
35.237.251.135 - - [11/Sep/2026:02:55:08 -0400] "GET /app/.env HTTP/1.1" 404 228154 "-" "Mozilla/5.0 ...
show more
35.237.251.135 - - [11/Sep/2026:02:55:08 -0400] "GET /app/.env HTTP/1.1" 404 228154 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; OAI-SearchBot/1.4; robots.txt; +https://openai.com/searchbot)"
35.237.251.135 - - [11/Sep/2026:02:55:08 -0400] "GET /@fs/root/.aws/credentials?raw?? HTTP/1.1" 404 231049 "-" "Mozilla/5.0 (compatible; Twitterbot/1.0)"
35.237.251.135 - - [11/Sep/2026:02:55:08 -0400] "GET /.env HTTP/1.1" 404 228145 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko; compatible; Google-Extended/1.0; +http://www.google.com/bot.html) Chrome/120.0.6320.109 Safari/537.36"
...
show less
Web App Attack
🇺🇸
knock
2026-09-11 06:49:29
(2 days ago)
Knock-Knock honeypot brute-force: HTTP (643 total hits)
Web App Attack
🇳🇱
Savvii
2026-09-11 05:14:05
(2 days ago)
20 attempts against mh-misbehave-ban on melon
Brute-Force
Bad Web Bot
Web App Attack