๐ซ๐ท
Lunix
2026-08-29 01:15:34
(6 minutes ago)
Brute-Force
Web App Attack
๐บ๐ธ
Hazael
2026-08-29 00:38:13
(44 minutes ago)
SNOOPING - intended to probe for or exploit website vulnerabilities. From: Dublin, รtats-Unis - Amaz ...
show more
SNOOPING - intended to probe for or exploit website vulnerabilities. From: Dublin, รtats-Unis - Amazon.com, Inc. (AS16509 Amazon.com, Inc.) - Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36
show less
Web App Attack
๐บ๐ธ
mw
2026-08-29 00:25:01
(57 minutes ago)
GET /.env.production HTTP/1.1
Web App Attack
๐ฎ๐ณ
evicky2002
2026-08-29 00:00:42
(1 hour ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐ณ๐ฑ
MyGlobalFlowers
2026-08-28 19:50:18
(5 hours ago)
Multiple WAF Violations
Web App Attack
๐ต๐ฑ
nakordoni.eu
2026-08-28 18:30:03
(6 hours ago)
Blocked by nakordoni.eu automated security: vulnerability scanner / probe attack. Jail: nakordoni-se ...
show more
Blocked by nakordoni.eu automated security: vulnerability scanner / probe attack. Jail: nakordoni-security-probe, 3 matches. ISP: Amazon Technologies Inc. (US), Usage: Data Center/Web Hosting/Transit. Prior AbuseIPDB score at ban time: 100/100.
show less
Bad Web Bot
Web App Attack
๐ง๐ช
voormedia
2026-08-28 16:44:47
(8 hours ago)
Accessed trap at '/.aws/credentials'
Web App Attack
๐ต๐ฑ
nfsec.pl
2026-08-28 14:42:34
(10 hours ago)
52.14.95.26 - - [28/Aug/2026:14:42:20 +0000] "GET /.git/config HTTP/1.1" 403 357 "-" "Mozilla/5.0 (c ...
show more
52.14.95.26 - - [28/Aug/2026:14:42:20 +0000] "GET /.git/config HTTP/1.1" 403 357 "-" "Mozilla/5.0 (compatible; Amzn-SearchBot/1.0; +https://developer.amazon.com/support/amazonbot)"
52.14.95.26 - - [28/Aug/2026:14:42:29 +0000] "GET /.git/HEAD HTTP/1.1" 403 357 "-" "Mozilla/5.0 (compatible; Amzn-SearchBot/1.0; +https://developer.amazon.com/support/amazonbot)"
52.14.95.26 - - [28/Aug/2026:14:42:33 +0000] "GET /signin HTTP/2.0" 404 24999 "http://www.nfsec.pl/signin" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Mobile Safari/537.36"
52.14.95.26 - - [28/Aug/2026:14:42:33 +0000] "POST /graphql HTTP/1.1" 403 357 "http://www.nfsec.pl" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Mobile Safari/537.36"
52.14.95.26 - - [28/Aug/2026:14:42:33 +0000] "GET /sign-in HTTP/2.0" 404 0 "http://www.nfsec.pl/sign-in" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Mobile S
...
show less
Web App Attack
Exploited Host
๐ง๐ช
voormedia
2026-08-28 14:28:00
(10 hours ago)
Accessed trap at '/.aws/config'
Web App Attack
๐บ๐ธ
Lee Daniel
2026-08-28 13:31:53
(11 hours ago)
52.14.95.26 - - [28/Aug/2026:09:31:53 -0400] "GET /.aws/credentials HTTP/1.1" 403 6297 "-" "Mozilla/ ...
show more
52.14.95.26 - - [28/Aug/2026:09:31:53 -0400] "GET /.aws/credentials HTTP/1.1" 403 6297 "-" "Mozilla/5.0 (compatible; DeepSeekBot/1.0; +https://www.deepseek.com/bot)"
...
show less
DDoS Attack
Web Spam
Email Spam
Port Scan
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
voormedia
2026-08-28 12:31:32
(12 hours ago)
Accessed trap at '/config/secrets.yml'
Web App Attack
Anonymous
2026-08-28 12:22:01
(13 hours ago)
Portscan: TCP/8443 (9x), TCP/8080 (8x)
Port Scan
๐บ๐ธ
TPI-Abuse
2026-08-28 11:24:08
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 52.14.95.26 (ec2-52-14-95-26.us-east-2.compute. ...
show more
(mod_security) mod_security (id:210492) triggered by 52.14.95.26 (ec2-52-14-95-26.us-east-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 07:24:02.403410 2026] [security2:error] [pid 15440:tid 15573] [client 52.14.95.26:42486] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "americanacademyofprojectmanagement.com"] [uri "/media../.env"] [unique_id "apFv0jlh4F3a0yTSGbZm6gAAAE0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-28 10:17:19
(15 hours ago)
(config_exploit_scan) Configuratie Scanner / Nep GPTBot 52.14.95.26 (US/United States/ec2-52-14-95-2 ...
show more
(config_exploit_scan) Configuratie Scanner / Nep GPTBot 52.14.95.26 (US/United States/ec2-52-14-95-26.us-east-2.compute.amazonaws.com): 3 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 52.14.95.26 - - [28/Aug/2026:12:17:14 +0200] "GET /web/.env HTTP/1.1" 406 441 "-" "meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)"
52.14.95.26 - - [28/Aug/2026:12:17:18 +0200] "GET /storage/.env HTTP/1.1" 406 441 "-" "meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)"
52.14.95.26 - - [28/Aug/2026:12:17:18 +0200] "GET /public/.env HTTP/1.1" 406 441 "-" "meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)"
show less
Port Scan
๐ฉ๐ช
Bedios GmbH
2026-08-28 09:35:15
(15 hours ago)
Login credentials theft attempt
Hacking