๐ง๐ท
Peregrine
2026-09-18 03:15:55
(19 hours ago)
Fail2Ban ct101 Jail: tomcat-honeypot | Evidence: 35.237.28.167 104.22.57.27 - - [15/Sep/2026:13:02:1 ...
show more
Fail2Ban ct101 Jail: tomcat-honeypot | Evidence: 35.237.28.167 104.22.57.27 - - [15/Sep/2026:13:02:13 -0300] "GET /document.php?modulepart=systemtools&file=../conf/conf.php&hashp=shared HTTP/1.1" 404 18149
show less
Bad Web Bot
๐ณ๐ฑ
e.fierstra
2026-09-16 03:34:32
(2 days ago)
excessive HTTP 404 errors
Bad Web Bot
๐ง๐ท
Peregrine
2026-09-16 03:15:33
(2 days ago)
Fail2Ban ct101 Jail: tomcat-honeypot | Evidence: 35.237.28.167 104.22.57.27 - - [15/Sep/2026:13:02:1 ...
show more
Fail2Ban ct101 Jail: tomcat-honeypot | Evidence: 35.237.28.167 104.22.57.27 - - [15/Sep/2026:13:02:13 -0300] "GET /document.php?modulepart=systemtools&file=../conf/conf.php&hashp=shared HTTP/1.1" 404 18149
show less
Bad Web Bot
๐ซ๐ท
Hippoline
2026-09-16 02:35:44
(2 days ago)
[Wed Sep 16 04:35:41.173726 2026] [authz_core:error] [pid 6997] [client 35.237.28.167:42308] AH01630 ...
show more
[Wed Sep 16 04:35:41.173726 2026] [authz_core:error] [pid 6997] [client 35.237.28.167:42308] AH01630: client denied by server configuration: /var/www/beaufort-online.lu/web/app_dev.php
[Wed Sep 16 04:35:41.297360 2026] [authz_core:error] [pid 6997] [client 35.237.28.167:42308] AH01630: client denied by server configuration: /var/www/beaufort-online.lu/web/app_dev.php
[Wed Sep 16 04:35:41.853475 2026] [authz_core:error] [pid 7000] [client 35.237.28.167:42330] AH01630: client denied by server configuration: /var/www/beaufort-online.lu/web/phpinfo.php
[Wed Sep 16 04:35:41.853669 2026] [authz_core:error] [pid 6997] [client 35.237.28.167:42308] AH01630: client denied by server configuration: /var/www/beaufort-online.lu/web/info.php
[Wed Sep 16 04:35:41.886553 2026] [authz_core:error] [pid 6988] [client 35.237.28.167:42288] AH01630: client denied by server configuration: /var/www/beaufort-online.lu/web/pi.php
...
show less
Brute-Force
Web App Attack
๐ฎ๐ณ
evicky2002
2026-09-16 00:02:04
(2 days ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-09-16 00:01:44
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.237.28.167 (167.28.237.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.237.28.167 (167.28.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 20:01:38.452377 2026] [security2:error] [pid 5580:tid 5580] [client 35.237.28.167:39756] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "waggonerfinancial.com"] [uri "/assets../.env"] [unique_id "aqncYshVh0YQRsqu5BtGzgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฒ๐พ
Rizzy
2026-09-15 23:32:21
(2 days ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 23:17:05
(2 days ago)
(mod_security) mod_security (id:210580) triggered by 35.237.28.167 (167.28.237.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210580) triggered by 35.237.28.167 (167.28.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 19:16:58.832435 2026] [security2:error] [pid 7218:tid 7218] [client 35.237.28.167:33472] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "proc/self/environ" at ARGS:filename. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/08_Global_Other.conf"] [line "57"] [id "210580"] [rev "2"] [msg "COMODO WAF: OS File Access Attempt||revelatorium.com|F|2"] [data "Matched Data: proc/self/environ found within ARGS:filename: file:/proc/self/environ"] [severity "CRITICAL"] [tag "CWAF"] [tag "Other"] [hostname "revelatorium.com"] [uri "/__vite_rsc_findSourceMapURL"] [unique_id "aqnR6nlA5WQGk-tR8q8_3gAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
rh24
2026-09-15 23:15:38
(2 days ago)
(badbots) Bad bot user-agent [redacted] from 35.237.28.167 (US/United States/167.28.237.35.bc.google ...
show more
(badbots) Bad bot user-agent [redacted] from 35.237.28.167 (US/United States/167.28.237.35.bc.googleusercontent.com)
show less
Hacking
๐บ๐ธ
WizardsToolkit
2026-09-15 22:15:34
(3 days ago)
trying to hack my site
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-15 22:11:23
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.237.28.167 (167.28.237.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.237.28.167 (167.28.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 18:11:17.800918 2026] [security2:error] [pid 9118:tid 9118] [client 35.237.28.167:58468] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ltscatering.com"] [uri "/.env.local"] [unique_id "aqnChfT1lsVdwKD6gVq80wAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 21:55:15
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.237.28.167 (167.28.237.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.237.28.167 (167.28.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 17:55:11.871176 2026] [security2:error] [pid 1698:tid 1807] [client 35.237.28.167:43106] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "killerrockandroll.com"] [uri "/%2E%2E/%2E%2E/%2E%2E/%2E%2E/.env"] [unique_id "aqm-vz_3JuLCxPhGyRsKCwAAAJA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-09-15 21:07:04
(3 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 1247
Exploited Host
Web App Attack
๐ซ๐ท
Octopuce
2026-09-15 20:16:48
(3 days ago)
Aggressive web search of vulnerable pages: /userfiles?path=../../.env /userfiles?path=../../../.env ...
show more
Aggressive web search of vulnerable pages: /userfiles?path=../../.env /userfiles?path=../../../.env /userfiles?path=../../../../.env /userfiles ...
show less
Web App Attack
๐ฉ๐ช
ger-stg-sifi1
2026-09-15 18:58:26
(3 days ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack