๐ฎ๐ฑ
spd.co.il
2026-09-18 20:02:35
(1 hour ago)
Web application attack detected
Hacking
Web App Attack
๐ช๐ธ
el-brujo
2026-09-18 14:38:00
(7 hours ago)
HTTP DDoS Attack Layer 7
DDoS Attack
๐ซ๐ท
SpaceHost-Server
2026-09-17 22:23:20
(23 hours ago)
Brute-Force
Web App Attack
๐ซ๐ท
IRISIO
2026-09-17 08:29:50
(1 day ago)
scans/SQL injection/spam posts : 113 queries
Web App Attack
SQL Injection
๐ฎ๐ณ
evicky2002
2026-09-17 06:00:05
(1 day ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-09-17 02:58:20
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 44.244.92.155 (ec2-44-244-92-155.us-west-2.comp ...
show more
(mod_security) mod_security (id:210730) triggered by 44.244.92.155 (ec2-44-244-92-155.us-west-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 22:58:15.217462 2026] [security2:error] [pid 20769:tid 20769] [client 44.244.92.155:50478] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||learningbyshipping.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "learningbyshipping.com"] [uri "/rclone.conf"] [unique_id "aqtXR1Z5HPMTXUcRZfjwsgAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
brechtr
2026-09-17 02:50:15
(1 day ago)
[Press84-BanHammer] 404 flood โ 30 hits in 60s โ Sourced from: www.langsvlaamsewegen.be โ Request: G ...
show more
[Press84-BanHammer] 404 flood โ 30 hits in 60s โ Sourced from: www.langsvlaamsewegen.be โ Request: GET /panel
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Savvii
2026-09-17 02:26:07
(1 day ago)
20 attempts against mh-misbehave-ban on grape
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-17 01:44:27
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 44.244.92.155 (ec2-44-244-92-155.us-west-2.comp ...
show more
(mod_security) mod_security (id:210730) triggered by 44.244.92.155 (ec2-44-244-92-155.us-west-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 21:44:23.006188 2026] [security2:error] [pid 32534:tid 32534] [client 44.244.92.155:51498] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||jambmaster.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "jambmaster.com"] [uri "/z9x8c7v6b5-debug-trigger-jambmaster.com"] [unique_id "aqtF9x1h5at9z6PEVhb2BwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
ingroscart.it
2026-09-17 01:24:08
(1 day ago)
(mod_security) mod_security triggered on hostname [redacted])
SQL Injection
๐จ๐ฆ
Mediashaker
2026-09-17 01:09:08
(1 day ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 44.244.92.155 (US/Un ...
show more
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 44.244.92.155 (US/United States/ec2-44-244-92-155.us-west-2.compute.amazonaws.com)
show less
Bad Web Bot
Anonymous
2026-09-17 00:58:02
(1 day ago)
Bot / scanning and/or hacking attempts: GET /winkelwagen HTTP/2.0, GET /.env.www HTTP/2.0, GET /ai/. ...
show more
Bot / scanning and/or hacking attempts: GET /winkelwagen HTTP/2.0, GET /.env.www HTTP/2.0, GET /ai/.env HTTP/2.0, GET /portaal HTTP/2.0, [5/5] read: stream 0, , GET /api/graphql HTTP/2.0, [1/0] done: stream 1, GET /, [39/39] read: stream 0, , POST /api/v1/validate/code HTTP/2.0, GET /agents/.env HTTP/2.0, GET /data/.env HTTP/2.0, POST /api/graphql HTTP/2.0, GET /api/config HTTP/2.0, GET /model/.env HTTP/2.0
show less
Hacking
Web App Attack
๐ช๐ธ
robotstxt
2026-09-17 00:56:25
(1 day ago)
44.244.92.155 - - [17/Sep/2026:00:55:29 +0000] "GET /z9x8c7v6b5-debug-trigger-hotelmasiabellver.es H ...
show more
44.244.92.155 - - [17/Sep/2026:00:55:29 +0000] "GET /z9x8c7v6b5-debug-trigger-hotelmasiabellver.es HTTP/2.0" 403 12474 "-" "Mozilla/5.0 (compatible; MistralAI-User/1.0; +https://mistral.ai/)" "-" edge="44.244.92.155"
44.244.92.155 - - [17/Sep/2026:00:55:29 +0000] "GET /.env_sample HTTP/2.0" 403 12461 "-" "Mozilla/5.0 (compatible; MoonshotBot/1.0; +https://kimi.ai/)" "-" edge="44.244.92.155"
44.244.92.155 - - [17/Sep/2026:00:55:29 +0000] "GET /agents/.env HTTP/2.0" 403 12478 "-" "Mozilla/5.0 (compatible; xAI-Grok/1.0; +https://x.ai/)" "-" edge="44.244.92.155"
44.244.92.155 - - [17/Sep/2026:00:55:29 +0000] "GET /agent/.env HTTP/2.0" 403 12461 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" "-" edge="44.244.92.155"
44.244.92.155 - - [17/Sep/2026:00:55:29 +0000] "GET /build/manifest.json HTTP/2.0" 403 11978 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Mobile Safari/537.36" "-" edge="44.244.92.155"
...
show less
Web App Attack
Anonymous
2026-09-17 00:08:52
(1 day ago)
Blocked: Reason='Suspicious traffic score=100 (review-based detection)'; Requests=249
Hacking
Anonymous
2026-09-16 23:54:07
(1 day ago)
[ns3.backorder.gr] httpd-config-scan: sites=www.gosolar.gr; logs=/var/log/httpd/domains/gosolar.gr.l ...
show more
[ns3.backorder.gr] httpd-config-scan: sites=www.gosolar.gr; logs=/var/log/httpd/domains/gosolar.gr.log; samples=/infra/.env | /.next/.env | /public/.env
show less
Hacking
Web App Attack