Anonymous
2026-09-23 18:18:51
(21 hours ago)
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: US, Attack patterns: Word ...
show more
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: US, Attack patterns: WordPress scanning, Backup file probing, Cloud secrets probing
show less
Bad Web Bot
Web App Attack
๐ฎ๐ณ
evicky2002
2026-09-23 06:00:01
(1 day ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐ฌ๐ง
openstrike.co.uk
2026-09-23 05:14:46
(1 day ago)
229 attacks on password/key grabbing URLs, VC URLs, env grabbing URLs, config grabbing URLs (type 2) ...
show more
229 attacks on password/key grabbing URLs, VC URLs, env grabbing URLs, config grabbing URLs (type 2), PHP URLs, env grabbing URLs (type 2), directory traversals:
GET /id_ecdsa HTTP/1.1
GET /.git/HEAD HTTP/1.1
GET /.env.staging HTTP/1.1
GET /config/database.yml HTTP/1.1
POST /icecoder/lib/terminal-xhr.php HTTP/1.1
GET /_image?href=/proc/self/environ HTTP/1.1
GET /..%2f..%2f.env HTTP/1.1
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 02:43:00
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 35.237.82.133 (133.82.237.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.237.82.133 (133.82.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 22:42:53.970435 2026] [security2:error] [pid 31639:tid 31639] [client 35.237.82.133:46586] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||kairoslogammakmur.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "kairoslogammakmur.com"] [uri "/z9x8c7v6b5-debug-trigger-kairoslogammakmur.com"] [unique_id "arM8rcbfCfYE6PSO-8pAIwAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 02:24:04
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 35.237.82.133 (133.82.237.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.237.82.133 (133.82.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 22:23:55.951021 2026] [security2:error] [pid 31222:tid 31222] [client 35.237.82.133:35950] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mailperform.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mailperform.com"] [uri "/z9x8c7v6b5-debug-trigger-mailperform.com"] [unique_id "arM4Ow8M6xG1Ado7uV5dgwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Mainpine
2026-09-23 02:03:44
(1 day ago)
probing for vulnerable web apps
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 01:18:10
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 35.237.82.133 (133.82.237.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.237.82.133 (133.82.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 21:18:04.425477 2026] [security2:error] [pid 22338:tid 22338] [client 35.237.82.133:47086] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||makaihe.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "makaihe.com"] [uri "/z9x8c7v6b5-debug-trigger-makaihe.com"] [unique_id "arMozJ0NU9RiehKEFuRjYQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
ecode hosting
2026-09-23 00:46:08
(1 day ago)
Domain : makinekontrol.com
Rule : env
2026-09-23 00:45:13 10.100.1.20 GET /.env - 443 - 35.237.82.13 ...
show more
Domain : makinekontrol.com
Rule : env
2026-09-23 00:45:13 10.100.1.20 GET /.env - 443 - 35.237.82.133 HTTP/2 CCBot/2.0 (https://commoncrawl.org/faq/) - makinekontrol.com 301 0 0 148 369 542 - -
show less
Hacking
SQL Injection
Anonymous
2026-09-23 00:06:37
(1 day ago)
35.237.82.133 - - [23/Sep/2026:02:06:37 +0200] "GET /dist/manifest.json HTTP/1.1" 404 444 "-" "Mozil ...
show more
35.237.82.133 - - [23/Sep/2026:02:06:37 +0200] "GET /dist/manifest.json HTTP/1.1" 404 444 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36"
35.237.82.133 - - [23/Sep/2026:02:06:37 +0200] "GET /dist/manifest.json HTTP/1.1" 404 249 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36"
35.237.82.133 - - [23/Sep/2026:02:06:37 +0200] "GET /asset-manifest.json HTTP/1.1" 404 444 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36"
35.237.82.133 - - [23/Sep/2026:02:06:37 +0200] "GET /asset-manifest.json HTTP/1.1" 404 249 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36"
35.237.82.133 - - [23/Sep/2026:02:06:37 +0200] "GET /z9x8c7v6b5-debug-trigger-malizganipchavula.com HTTP/1.1" 403 124 "-" "Mozilla/5.0 AppleWe
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-09-23 00:05:13
(1 day ago)
Abuse Detected (10)
Brute-Force
Web App Attack
๐ณ๐ฑ
debestelapp
2026-09-22 23:35:13
(1 day ago)
Web App Attack
๐ธ๐ฌ
crimefireNOC
2026-09-22 23:05:37
(1 day ago)
[waf.rce.eval] waf.rce.eval on https://manakmewa.com/api/v1/validate/code via POST (action: ban+403)
Hacking
Web App Attack
๐บ๐ธ
xmission.com
2026-09-22 22:14:02
(1 day ago)
35.237.82.133 - - [22/Sep/2026:16:14:01 -0600] "-" 400 150 "-" "-"
35.237.82.133 - - [22/Sep/2026:16 ...
show more
35.237.82.133 - - [22/Sep/2026:16:14:01 -0600] "-" 400 150 "-" "-"
35.237.82.133 - - [22/Sep/2026:16:14:01 -0600] "-" 400 150 "-" "-"
35.237.82.133 - - [22/Sep/2026:16:14:01 -0600] "-" 400 150 "-" "-"
35.237.82.133 - - [22/Sep/2026:16:14:01 -0600] "-" 400 150 "-" "-"
35.237.82.133 - - [22/Sep/2026:16:14:01 -0600] "-" 400 150 "-" "-"
...
show less
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-09-22 22:00:55
(1 day ago)
Auto-ban: >3000 req/min op 2026-09-22
Web App Attack
SSH
Hacking
๐ณ๐ฑ
ConsulHosting
2026-09-22 22:00:00
(1 day ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack