๐ฎ๐ฑ
spd.co.il
2026-09-18 17:02:47
(1 day ago)
Web application attack detected
Hacking
Web App Attack
๐ซ๐ท
SpaceHost-Server
2026-09-17 22:24:04
(1 day ago)
Brute-Force
Web App Attack
๐ฎ๐ณ
evicky2002
2026-09-17 06:00:05
(2 days ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐ณ๐ฑ
Savvii
2026-09-17 02:32:21
(2 days ago)
20 attempts against mh-misbehave-ban on ozone
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
helios.live
2026-09-17 02:29:34
(2 days ago)
2026/09/17 02:29:33 [error] 1106817#1106817: *3464921 access forbidden by rule, client: 54.175.94.97 ...
show more
2026/09/17 02:29:33 [error] 1106817#1106817: *3464921 access forbidden by rule, client: 54.175.94.97, server: kocerroxy.com, request: "GET /.git-credentials HTTP/1.1", host: "kocerroxy.com"
2026/09/17 02:29:33 [error] 1106817#1106817: *3465343 access forbidden by rule, client: 54.175.94.97, server: kocerroxy.com, request: "GET /.gitlab-ci.yml HTTP/1.1", host: "kocerroxy.com"
2026/09/17 02:29:33 [error] 1106817#1106817: *3465343 access forbidden by rule, client: 54.175.94.97, server: kocerroxy.com, request: "GET /.gitconfig HTTP/1.1", host: "kocerroxy.com"
2026/09/17 02:29:33 [error] 1106817#1106817: *3464921 access forbidden by rule, client: 54.175.94.97, server: kocerroxy.com, request: "GET /.env.backup HTTP/1.1", host: "kocerroxy.com"
2026/09/17 02:29:33 [error] 1106817#1106817: *3464921 access forbidden by rule, client: 54.175.94.97, server: kocerroxy.com, request: "GET /.env.local HTTP/1.1", host: "kocerroxy.com"
...
show less
Web App Attack
๐ซ๐ท
pm33
2026-09-17 02:26:02
(2 days ago)
Unauthorized connections HTTP 403
Web App Attack
๐ณ๐ฑ
BlueWire Hosting
2026-09-17 02:12:46
(2 days ago)
High-confidence malicious configuration/VCS probe
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-17 01:49:03
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 54.175.94.97 (ec2-54-175-94-97.compute-1.amazon ...
show more
(mod_security) mod_security (id:210492) triggered by 54.175.94.97 (ec2-54-175-94-97.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 21:48:59.285816 2026] [security2:error] [pid 483:tid 483] [client 54.175.94.97:52306] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jbaydeliveries.com"] [uri "/%2e%2e/%2e%2e/%2e%2e/%2e%2e/.env"] [unique_id "aqtHC4OxrtVNH3PdrcVK5wAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
findlab
2026-09-17 01:30:04
(2 days ago)
Backdrop CMS module - malicious activity detected
Bad Web Bot
Web App Attack
๐ฌ๐ง
andypiper
2026-09-17 01:02:38
(2 days ago)
CrowdSec ban for AbuseIPDB Top List
Brute-Force
Web App Attack
๐ช๐ธ
robotstxt
2026-09-17 00:58:06
(2 days ago)
54.175.94.97 - - [17/Sep/2026:00:57:13 +0000] "GET /wp-includes/js/dist/script-modules/interactivity ...
show more
54.175.94.97 - - [17/Sep/2026:00:57:13 +0000] "GET /wp-includes/js/dist/script-modules/interactivity/index.min.js?ver=efaa5193bbad9c60ffd1 HTTP/2.0" 403 15075 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36" "-" edge="54.175.94.97"
54.175.94.97 - - [17/Sep/2026:00:57:13 +0000] "GET /wp-includes/js/jquery/jquery.min.js?ver=3.7.1 HTTP/2.0" 403 15075 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36" "-" edge="54.175.94.97"
54.175.94.97 - - [17/Sep/2026:00:57:13 +0000] "GET /wp-includes/js/dist/script-modules/block-library/navigation/view.min.js?ver=1bf28ded04f9f188bdcb HTTP/2.0" 403 15002 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36" "-" edge="54.175.94.97"
54.175.94.97 - - [17/Sep/2026:00:57:13 +0000] "GET /wp-includes/js/jquery/jquery-migrate.min.js?ver=3.4.1 HTTP/2.0" 403 15075 "-
...
show less
Web App Attack
๐ฉ๐ช
netclix.gr
2026-09-17 00:55:45
(2 days ago)
(mod_security) mod_security triggered on hostname [redacted] 54.175.94.97 (US/United States/ec2-54-1 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 54.175.94.97 (US/United States/ec2-54-175-94-97.compute-1.amazonaws.com): (CF_ENABLE)
show less
SQL Injection
๐ณ๐ฑ
Savvii
2026-09-17 00:29:42
(2 days ago)
20 attempts against mh-misbehave-ban on frost
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
โจ
2026-09-17 00:24:18
(2 days ago)
Domain : gwha.org.uk
Rule : hack
2026-09-17 00:22:05 ***hidden-privacy*** GET /.htpasswd - 443 - 54. ...
show more
Domain : gwha.org.uk
Rule : hack
2026-09-17 00:22:05 ***hidden-privacy*** GET /.htpasswd - 443 - 54.175.94.97 HTTP/2 Mozilla/5.0 (compatible; MistralAI-User/1.0; https://mistral.ai/) - gwha.org.uk 404 0 2 5224 440 125 - -
show less
Hacking
SQL Injection
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-17 00:11:47
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 54.175.94.97 (ec2-54-175-94-97.compute-1.amazon ...
show more
(mod_security) mod_security (id:210492) triggered by 54.175.94.97 (ec2-54-175-94-97.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 20:11:42.938102 2026] [security2:error] [pid 9030:tid 9030] [client 54.175.94.97:52952] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "grasslakepizzatime.com"] [uri "/.github/.env"] [unique_id "aqswPpIfWv08nN91OyHxuAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack