๐ฎ๐ณ
evicky2002
2026-07-26 06:00:00
(13 hours ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐ฉ๐ช
Trueforce Threat Report
2026-07-26 05:31:02
(13 hours ago)
Automated report, trolling for resource vulnerabilities
Bad Web Bot
Web App Attack
๐บ๐ธ
helios.live
2026-07-26 02:02:37
(17 hours ago)
2026/07/26 02:02:36 [error] 1996879#1996879: *2775012 access forbidden by rule, client: 35.246.166.1 ...
show more
2026/07/26 02:02:36 [error] 1996879#1996879: *2775012 access forbidden by rule, client: 35.246.166.16, server: kocerroxy.com, request: "GET /.gitconfig HTTP/1.1", host: "app.kocerroxy.com"
2026/07/26 02:02:36 [error] 1996879#1996879: *2775000 access forbidden by rule, client: 35.246.166.16, server: kocerroxy.com, request: "GET /.gitlab-ci.yml HTTP/1.1", host: "app.kocerroxy.com"
2026/07/26 02:02:36 [error] 1996879#1996879: *2775012 access forbidden by rule, client: 35.246.166.16, server: kocerroxy.com, request: "GET /.aws/config HTTP/1.1", host: "app.kocerroxy.com"
2026/07/26 02:02:36 [error] 1996879#1996879: *2775000 access forbidden by rule, client: 35.246.166.16, server: kocerroxy.com, request: "GET /.git-credentials HTTP/1.1", host: "app.kocerroxy.com"
2026/07/26 02:02:36 [error] 1996879#1996879: *2775012 access forbidden by rule, client: 35.246.166.16, server: kocerroxy.com, request: "GET /.aws/credentials HTTP/1.1", host: "app.kocerroxy.com"
...
show less
Web App Attack
๐ฉ๐ช
LRob
2026-07-26 01:35:54
(17 hours ago)
CrowdSec: crowdsecurity/http-sensitive-files | req: /.git/HEAD | 5 distinct paths | UA: Mozilla/5.0 ...
show more
CrowdSec: crowdsecurity/http-sensitive-files | req: /.git/HEAD | 5 distinct paths | UA: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; OAI-SearchBot/1.0; +https://openai.com/searchbot
show less
Hacking
๐ง๐ท
mateus.vicente
2026-07-26 01:04:04
(18 hours ago)
[2026-07-26T01:04:04Z] Excessive 5xx requests from single IP detected and blocked. (db-srv)
DDoS Attack
Web Spam
Web App Attack
๐ซ๐ฎ
cleverest.eu
2026-07-26 00:06:25
(19 hours ago)
MimirWAF has 104 incidents from 1 distinct domain => {"bad_request_uri / script_kiddie_detection","b ...
show more
MimirWAF has 104 incidents from 1 distinct domain => {"bad_request_uri / script_kiddie_detection","bad_request_uri / vcs_probe","blacklisted_access / definite_repeat_offender"}
show less
Brute-Force
Web App Attack
๐ฎ๐ช
Coolnagour
2026-07-25 22:44:07
(20 hours ago)
http-probing: /z9x8c7v6b5-debug-trigger-console.icabbicanada.com
Web App Attack
๐ณ๐ฑ
GabrielJST
2026-07-25 22:42:22
(20 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 35.246.166.16 (DE/Germany/16.166.246.35 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 35.246.166.16 (DE/Germany/16.166.246.35.bc.googleusercontent.com): (CF_ENABLE)
show less
SQL Injection
๐ซ๐ท
largo-it.net
2026-07-25 21:41:30
(21 hours ago)
Jul 25 23:41:28 vps-9f3cdc33 haproxy[2641243]: 35.246.166.16:51774 [25/Jul/2026:23:41:28.643] www_fr ...
show more
Jul 25 23:41:28 vps-9f3cdc33 haproxy[2641243]: 35.246.166.16:51774 [25/Jul/2026:23:41:28.643] www_frontend~ sso1_cluster/sso1_https 0/0/1/11/12 404 1250 - - ---- 72/24/0/0/0 0/0 "GET https://sso.largo.fr/z9x8c7v6b5-debug-trigger-sso.largo.fr HTTP/2.0"
Jul 25 23:41:28 vps-9f3cdc33 haproxy[2641243]: 35.246.166.16:51774 [25/Jul/2026:23:41:28.671] www_frontend~ sso1_cluster/sso1_https 0/0/0/9/9 404 1250 - - ---- 72/24/0/0/0 0/0 "GET https://sso.largo.fr/rclone.conf HTTP/2.0"
Jul 25 23:41:28 vps-9f3cdc33 haproxy[2641243]: 35.246.166.16:51774 [25/Jul/2026:23:41:28.757] www_frontend~ sso1_cluster/sso1_https 0/0/1/11/12 404 1250 - - ---- 73/25/3/3/0 0/0 "GET https://sso.largo.fr/.aws/credentials HTTP/2.0"
Jul 25 23:41:28 vps-9f3cdc33 haproxy[2641243]: 35.246.166.16:51774 [25/Jul/2026:23:41:28.759] www_frontend~ sso1_cluster/sso1_https 0/0/0/16/16 404 1250 - - ---- 73/25/2/2/0 0/0 "GET https://sso.largo.fr/webpack-stats.json HTTP/2.0"
Jul 25 23:41:28 vps-9f3cdc33 haproxy[2641243]: 35.246.166.16
...
show less
Hacking
Bad Web Bot
Web App Attack
๐จ๐ฟ
ptlab
2026-07-25 20:45:30
(22 hours ago)
Detected wp_login attack from WP-host.
Hacking
Web App Attack
๐ฌ๐ง
consul.to
2026-07-25 19:12:02
(1 day ago)
Web attack/malicious scanning detected
Web App Attack
๐ท๐ด
INTEQ
2026-07-25 17:58:40
(1 day ago)
Web attack from 35.246.166.16
Web App Attack
Anonymous
2026-07-25 17:02:55
(1 day ago)
35.246.166.16 - - [25/Jul/2026:19:02:48 +0200] "GET /webpack-stats.json HTTP/1.1" 404 29859
35.246.1 ...
show more
35.246.166.16 - - [25/Jul/2026:19:02:48 +0200] "GET /webpack-stats.json HTTP/1.1" 404 29859
35.246.166.16 - - [25/Jul/2026:19:02:48 +0200] "GET /manifest.json HTTP/1.1" 404 29859
35.246.166.16 - - [25/Jul/2026:19:02:48 +0200] "GET /build-manifest.json HTTP/1.1" 404 29859
35.246.166.16 - - [25/Jul/2026:19:02:48 +0200] "GET /_next/build-manifest.json HTTP/1.1" 404 29859
35.246.166.16 - - [25/Jul/2026:19:02:48 +0200] "GET /asset-manifest.json HTTP/1.1" 404 29859
35.246.166.16 - - [25/Jul/2026:19:02:48 +0200] "GET /_next/static/buildManifest.js HTTP/1.1" 404 29859
35.246.166.16 - - [25/Jul/2026:19:02:48 +0200] "GET /z9x8c7v6b5-debug-trigger-crypcool.com HTTP/1.1" 404 29859
35.246.166.16 - - [25/Jul/2026:19:02:51 +0200] "GET /credentials.json HTTP/1.1" 404 28319
35.246.166.16 - - [25/Jul/2026:19:02:51 +0200] "GET /secrets.yml HTTP/1.1" 404 29859
35.246.166.16 - - [25/Jul/2026:19:02:51 +0200] "GET /serviceAccountKey.json HTTP/1.1" 404 28319
...
show less
Web Spam
Web App Attack
๐ณ๐ฑ
Savvii
2026-07-25 15:30:49
(1 day ago)
20 attempts against mh-misbehave-ban on burne
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-25 14:23:02
(1 day ago)
Bot / scanning and/or hacking attempts: GET /.mcp.json HTTP/2.0, GET /.zshrc HTTP/2.0, GET /wp-confi ...
show more
Bot / scanning and/or hacking attempts: GET /.mcp.json HTTP/2.0, GET /.zshrc HTTP/2.0, GET /wp-config.php.bak HTTP/2.0, GET /wp-config.php.old HTTP/2.0, GET /.profile HTTP/2.0, GET /rclone.conf HTTP/2.0
show less
Hacking
Web App Attack