๐บ๐ธ
OceanTreasure
2026-09-18 06:01:15
(52 minutes ago)
tcp/8443; Unsolicited SYN to a port that has never been offered on this address (closed, no service ...
show more
tcp/8443; Unsolicited SYN to a port that has never been offered on this address (closed, no service ever) @ 2026-09-18T05:59:27Z
show less
Port Scan
๐ฎ๐ณ
evicky2002
2026-09-18 06:00:02
(53 minutes ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐จ๐ญ
๐จ๐ญ Hosting
2026-09-18 05:10:34
(1 hour ago)
Automated WAF report: 200-300 blocked requests from this IP detected by our WAF.
Bad Web Bot
Web App Attack
๐ฌ๐ง
Marten Mark
2026-09-18 04:26:20
(2 hours ago)
35.239.28.38 - - [18/Sep/2026:04:26:18 +0000] "GET /rclone.conf HTTP/2.0" 404 5334 "-" "Mozilla/5.0 ...
show more
35.239.28.38 - - [18/Sep/2026:04:26:18 +0000] "GET /rclone.conf HTTP/2.0" 404 5334 "-" "Mozilla/5.0 (compatible; Google-Extended; +http://www.google.com/bot.html)"
35.239.28.38 - - [18/Sep/2026:04:26:18 +0000] "GET /server.key HTTP/2.0" 404 5334 "-" "Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; +https://kimi.ai/)"
35.239.28.38 - - [18/Sep/2026:04:26:18 +0000] "GET /key.pem HTTP/2.0" 404 5334 "-" "DuckAssistBot/1.1 (https://duckduckgo.com/duckassistbot)"
35.239.28.38 - - [18/Sep/2026:04:26:18 +0000] "GET /.vite/manifest.json HTTP/2.0" 404 5334 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Mobile Safari/537.36"
35.239.28.38 - - [18/Sep/2026:04:26:18 +0000] "GET /z9x8c7v6b5-debug-trigger-blog.cfi.co HTTP/2.0" 404 5334 "-" "Mozilla/5.0 (compatible; Meta-ExternalAgent/1.0; +https://developers.facebook.com/docs/sharing/webmasters/crawler)"
35.239.28.38 - - [18/Sep/2026:04:26:18 +0000] "GET /dist/manifest.json HTTP/2.0" 404 5334 "-" "Mozilla/5
...
show less
Port Scan
Web App Attack
๐ฎ๐น
VHosting
2026-09-18 03:45:03
(3 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐ฌ๐ง
andypiper
2026-09-18 01:02:59
(5 hours ago)
CrowdSec ban for AbuseIPDB Top List
Brute-Force
Web App Attack
๐ฌ๐ง
Apache
2026-09-18 00:08:57
(6 hours ago)
(mod_security) mod_security (id:930130) triggered by 35.239.28.38 (US/United States/38.28.239.35.bc. ...
show more
(mod_security) mod_security (id:930130) triggered by 35.239.28.38 (US/United States/38.28.239.35.bc.googleusercontent.com): 5 in the last 300 secs (CF_ENABLE)
show less
Brute-Force
Web App Attack
๐ง๐ท
dermatovirtual
2026-09-17 22:40:34
(8 hours ago)
Dermato Virtual CSIRT: Malicious web exploit/scanning probes against app.dermatovirtual.com.br (Web ...
show more
Dermato Virtual CSIRT: Malicious web exploit/scanning probes against app.dermatovirtual.com.br (Web Server Ports 80/443). 87 unauthorized requests recorded between 2026-09-17 22:38:55 UTC and 2026-09-17 22:39:08 UTC (rate: ~87 req/min). Edge perimeter firewall drop active.
Log sample:
[2026-09-17 22:39:08 UTC] IP: 35.239.28.38 - W3C IIS (Port 443): GET /build/.env -> HTTP 404 [CLIENT: 35.239.28.38]
[2026-09-17 22:39:08 UTC] IP: 35.239.28.38 - W3C IIS (Port 443): GET /.env.save -> HTTP 404 [CLIENT: 35.239.28.38]
[2026-09-17 22:39:08 UTC] IP: 35.239.28.38 - W3C IIS (Port 443): GET /.env.stage -> HTTP 404 [CLIENT: 35.239.28.38]
show less
Bad Web Bot
Web App Attack
๐ซ๐ท
SpaceHost-Server
2026-09-17 22:22:44
(8 hours ago)
Brute-Force
Web App Attack
๐ฉ๐ช
Bedios GmbH
2026-09-17 19:50:11
(11 hours ago)
Login credentials theft attempt
Hacking
๐ฉ๐ช
ใใใจใใใใ
2026-09-17 18:03:38
(12 hours ago)
Automated exploit-path probing and webshell write attempts against a self-hosted nginx web service. ...
show more
Automated exploit-path probing and webshell write attempts against a self-hosted nginx web service. Observed: path traversal probes to sensitive files (16 requests). No site identifiers included.
show less
Port Scan
Web App Attack
Anonymous
2026-09-17 13:33:57
(17 hours ago)
Web Servers Directory Traversal.
Web App Attack
Anonymous
2026-09-17 13:06:35
(17 hours ago)
[ssd5.kdns.gr] httpd-config-scan: sites=www.tsokastzakia.gr; logs=/var/log/httpd/domains/tsokastzaki ...
show more
[ssd5.kdns.gr] httpd-config-scan: sites=www.tsokastzakia.gr; logs=/var/log/httpd/domains/tsokastzakia.gr.log; samples=/service-account.json | /.docker/config.json | /.svn/entries
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-17 12:44:23
(18 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.239.28.38 (38.28.239.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 35.239.28.38 (38.28.239.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 08:44:19.428333 2026] [security2:error] [pid 7011:tid 7026] [client 35.239.28.38:36740] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||tomithai.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "tomithai.com"] [uri "/z9x8c7v6b5-debug-trigger-tomithai.com"] [unique_id "aqvgox2jOmUzPtjHUZs-IwAAAM0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-17 12:25:54
(18 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.239.28.38 (38.28.239.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 35.239.28.38 (38.28.239.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 08:25:52.165993 2026] [security2:error] [pid 23545:tid 23545] [client 35.239.28.38:54124] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||thevenicecafe.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "thevenicecafe.com"] [uri "/z9x8c7v6b5-debug-trigger-thevenicecafe.com"] [unique_id "aqvcUOF_YmBUBRV2MtQabQAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack