๐จ๐ฆ
polycoda
2026-10-11 11:50:52
(1 hour ago)
๐ฅ VERY AGGRESSIVE SCANNER probed over 300 inexistent files and PHP scripts in less than an hour.
Hacking
Web App Attack
๐ช๐ธ
masterguru
2026-10-11 10:21:27
(2 hours ago)
BAD BOT - Detected and Blocked.. Matched phrase "OAI-SearchBot" at REQUEST_HEADERS:User-Agent. (1100 ...
show more
BAD BOT - Detected and Blocked.. Matched phrase "OAI-SearchBot" at REQUEST_HEADERS:User-Agent. (1100000-122)
show less
Bad Web Bot
๐ซ๐ท
Catalin Negru
2026-10-11 10:02:17
(3 hours ago)
Recidive ban by fail2ban on server.blackbit.ro
Brute-Force
๐ฟ๐ฆ
conure.sh
2026-10-11 09:52:17
(3 hours ago)
csagent: score 20.0: secrets grab x2; 1 domain(s) in 2s
Web App Attack
Anonymous
2026-10-11 06:22:03
(6 hours ago)
Bot / scanning and/or hacking attempts: GET /ai/.env HTTP/2.0, GET /.env_sample HTTP/2.0
Hacking
Web App Attack
๐ง๐ท
dermatovirtual
2026-10-11 03:13:11
(9 hours ago)
Dermato Virtual CSIRT: Malicious web exploit/scanning probes against app.dermatovirtual.com.br (Web ...
show more
Dermato Virtual CSIRT: Malicious web exploit/scanning probes against app.dermatovirtual.com.br (Web Server Ports 80/443). 136 unauthorized requests recorded between 2026-10-11 03:09:24 UTC and 2026-10-11 03:09:30 UTC (rate: ~136 req/min). Edge perimeter firewall drop active.
Log sample:
[2026-10-11 03:09:30 UTC] IP: 35.240.208.104 - W3C IIS (Port 443): GET /static../.env -> HTTP 404 [CLIENT: 35.240.208.104]
[2026-10-11 03:09:30 UTC] IP: 35.240.208.104 - W3C IIS (Port 443): GET /app/.env -> HTTP 404 [CLIENT: 35.240.208.104]
[2026-10-11 03:09:30 UTC] IP: 35.240.208.104 - W3C IIS (Port 443): GET /.git/config -> HTTP 404 [CLIENT: 35.240.208.104]
show less
Bad Web Bot
Web App Attack
๐น๐ท
ScchutzZ
2026-10-11 02:05:05
(11 hours ago)
Fail2Ban banฤฑ. Jail: plesk-modsecurity.
Brute-Force
๐ฉ๐ช
EGP Abuse Dept
2026-10-11 01:27:25
(11 hours ago)
Scanning for web/db/file exploits on www.donkerbrillen.nl
SQL Injection
Bad Web Bot
Web App Attack
๐ง๐พ
lns.bz
2026-10-11 01:04:27
(12 hours ago)
Too many 404 requests [BY]
Web App Attack
๐ง๐ท
Peregrine
2026-10-11 00:28:35
(12 hours ago)
Fail2Ban ct101 Jail: tomcat-404 | Evidence: 35.240.208.104 172.71.124.200 - - [10/Oct/2026:21:28:31 ...
show more
Fail2Ban ct101 Jail: tomcat-404 | Evidence: 35.240.208.104 172.71.124.200 - - [10/Oct/2026:21:28:31 -0300] "GET /.vite/manifest.json HTTP/1.1" 404 18149
35.240.208.104 172.71.124.201 - - [10/Oct/2026:21:28:32 -0300] "GET /dist/.vite/manifest.json HTTP/1.1" 404 18149
35.240.208.104 172.71.124.186 - - [10/Oct/2026:21:28:32 -0300] "GET /yg32yxc9hokjq6qkd6bz HTTP/1.1" 404 18149
35.240.208.104 172.71.124.200 - - [10/Oct/2026:21:28:32 -0300] "GET /3jsjrj5n4m6uvnd8f1jq HTTP/1.1" 404 18149
35.240.208.104 172.71.124.200 - - [10/Oct/2026:21:28:32 -0300] "POST /graphql HTTP/1.1" 404 18149
show less
Bad Web Bot
Web App Attack
Anonymous
2026-10-11 00:20:07
(12 hours ago)
| [Dangerous/Singapore] Aggressive IP 35.240.208.104 (~30 hits). Type: DoS Defender- Web server 400 ...
show more
| [Dangerous/Singapore] Aggressive IP 35.240.208.104 (~30 hits). Type: DoS Defender- Web server 400 error code
show less
Web App Attack
Hacking
SQL Injection
๐ณ๐ฑ
Alt255
2026-10-11 00:17:24
(12 hours ago)
[cb-06al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[cb-06al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 35.240.208.104 - - [11/Oct/2026:02:17:01 +0200] "GET /@fs/var/task/.env?raw?? HTTP/2.0" 404 1338 "-" "DuckAssistBot/1.1 (https://duckduckgo.com/duckassistbot)"
...
show less
Bad Web Bot
Web App Attack
๐จ๐ฆ
SSH-Admin
2026-10-10 23:51:02
(13 hours ago)
Probing for Exploits on ns74
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-10 23:45:23
(13 hours ago)
(mod_security) mod_security (id:949110) triggered by 35.240.208.104 (104.208.240.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:949110) triggered by 35.240.208.104 (104.208.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 19:45:17.452471 2026] [security2:error] [pid 20980:tid 20980] [client 35.240.208.104:46560] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "cpectec.com"] [uri "/z9x8c7v6b5-debug-trigger-cpectec.com"] [unique_id "asrODWeHI8oZMNNnvlpMNQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
polycoda
2026-10-10 22:57:37
(14 hours ago)
AutoBlock: ๐ฏ Vulnerability Scanner (Non Decay-Based) - ๐ก Port Scan (Non Decay-Based) - โ Excessive 4 ...
show more
AutoBlock: ๐ฏ Vulnerability Scanner (Non Decay-Based) - ๐ก Port Scan (Non Decay-Based) - โ Excessive 40X Errors (Decay-Based)
show less
Port Scan
Hacking
Bad Web Bot
Web App Attack