๐ฎ๐ฑ
spd.co.il
2026-09-19 01:02:24
(6 hours ago)
Web application attack detected
Hacking
Web App Attack
๐ฎ๐ณ
evicky2002
2026-09-17 06:00:05
(2 days ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-09-17 02:43:55
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 52.201.236.52 (ec2-52-201-236-52.compute-1.amaz ...
show more
(mod_security) mod_security (id:210730) triggered by 52.201.236.52 (ec2-52-201-236-52.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 22:43:49.900379 2026] [security2:error] [pid 6165:tid 6165] [client 52.201.236.52:49496] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||marxistphilosophy.org|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "marxistphilosophy.org"] [uri "/rclone.conf"] [unique_id "aqtT5WmBY39dAlQWijPWAAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
netclix.gr
2026-09-17 02:09:47
(2 days ago)
(bot_kill_mega) Aggressive Bot Blocked: tencent 52.201.236.52 (US/United States/ec2-52-201-236-52.co ...
show more
(bot_kill_mega) Aggressive Bot Blocked: tencent 52.201.236.52 (US/United States/ec2-52-201-236-52.compute-1.amazonaws.com): 1 in the last 4600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 52.201.236.52 - - [17/Sep/2026:05:09:02 +0300] "POST /icecoder/lib/terminal-xhr.php HTTP/2.0" 404 808 "-" "Mozilla/5.0 (compatible; Hunyuan/1.0; +https://hunyuan.tencent.com/)"
show less
Port Scan
๐ฎ๐ช
RoboSOC
2026-09-17 01:12:57
(2 days ago)
Langflow Unauthenticated Remote Code Execution Vulnerability, PTR: ec2-52-201-236-52.compute-1.amazo ...
show more
Langflow Unauthenticated Remote Code Execution Vulnerability, PTR: ec2-52-201-236-52.compute-1.amazonaws.com.
show less
Hacking
๐ฌ๐ง
andypiper
2026-09-17 01:02:32
(2 days ago)
CrowdSec ban for AbuseIPDB Top List
Brute-Force
Web App Attack
๐ณ๐ฑ
Savvii
2026-09-17 00:31:34
(2 days ago)
20 attempts against mh-misbehave-ban on ozone
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-17 00:12:00
(2 days ago)
[cb-15al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[cb-15al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 52.201.236.52 - - [17/Sep/2026:02:11:52 +0200] "GET /@fs/app/.env?raw?? HTTP/2.0" 301 365 "-" "Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; +https://kimi.ai/)"
...
show less
Bad Web Bot
Web App Attack
๐จ๐ฆ
Mediashaker
2026-09-16 23:55:14
(2 days ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 52.201.236.52 (US/Un ...
show more
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 52.201.236.52 (US/United States/ec2-52-201-236-52.compute-1.amazonaws.com)
show less
Bad Web Bot
๐บ๐ธ
H24
2026-09-16 23:41:51
(2 days ago)
/app/.env /packages/.env /web/.env /api/.env /services/.env /backend/.env
Web App Attack
๐ฉ๐ช
BlueWire Hosting
2026-09-16 23:28:55
(2 days ago)
High-confidence malicious configuration/VCS probe
Web App Attack
๐ณ๐ฑ
Savvii
2026-09-16 23:16:50
(2 days ago)
20 attempts against mh-misbehave-ban on frost
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Baking333
2026-09-16 23:02:31
(2 days ago)
[redacted] 52.201.236.52 - - [16/Sep/2026:22:04:36 +0100] "GET /dist/.vite/[redacted] HTTP/1.1" 302 ...
show more
[redacted] 52.201.236.52 - - [16/Sep/2026:22:04:36 +0100] "GET /dist/.vite/[redacted] HTTP/1.1" 302 1534 0/42859 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36 Edg/152.0.0.0" 443 [redacted] 52.201.236.52 - - [16/Sep/2026:22:04:36 +0100] "GET /.vite/[redacted] HTTP/1.1" 302 1534 0/57891 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36 Edg/152.0.0.0" 443
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-16 22:39:44
(2 days ago)
[cb-02al] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail ngin ...
show more
[cb-02al] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail nginx-404. Example: 52.201.236.52 - - [17/Sep/2026:00:39:34 +0200] "POST /graphql HTTP/1.1" 404 14356 "https://gekvanfietsen.nl" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Mobile Safari/537.36"
52.201.236.52 - - [17/Sep/2026:00:39:35 +0200] "GET /secrets.env HTTP/1.1" 404 14405 "https://gekvanfietsen.nl/secrets.env" "Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; +https://kimi.ai/)"
52.201.236.52 - - [17/Sep/2026:00:39:35 +0200] "GET /static/manifest.json HTTP/1.1" 404 14406 "https://gekvanfietsen.nl/static/manifest.json" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Mobile Safari/537.36"
52.201.236.52 - - [17/Sep/2026:00:39:35 +0200] "GET /docker-compose.yaml HTTP/1.1" 404 14406 "https://gekvanfietsen.nl/docker-compo
...
show less
Bad Web Bot
Web App Attack
Anonymous
2026-09-16 22:38:25
(2 days ago)
Automatically blocked after 8 security events. Observed repeated login or credential attacks. Source ...
show more
Automatically blocked after 8 security events. Observed repeated login or credential attacks. Source: Cloudflare security controls.
show less
Hacking
Brute-Force
Bad Web Bot
Web App Attack