๐ณ๐ฑ
Site.eu
2026-08-30 06:13:39
(1 day ago)
Excessive multi-domain requests
Brute-Force
๐ฎ๐ณ
evicky2002
2026-08-29 00:00:42
(2 days ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐จ๐ฆ
polycoda
2026-08-27 22:59:11
(3 days ago)
โจ๏ธ Probes for /.env everywhere
Hacking
Web App Attack
Anonymous
2026-08-27 22:53:03
(3 days ago)
Bot / scanning and/or hacking attempts: GET /wp-config.php.old HTTP/2.0, GET /auth/login HTTP/2.0, G ...
show more
Bot / scanning and/or hacking attempts: GET /wp-config.php.old HTTP/2.0, GET /auth/login HTTP/2.0, GET /public/plugins/alertlist/../../../../../../../../proc/self, GET /wp-config.php.bak HTTP/2.0, GET /login HTTP/2.0, GET /panel HTTP/2.0, GET /@fs/proc/self/cwd/.env?raw?? HTTP/2.0, POST /v1/graphql HTTP/2.0, GET /backoffice HTTP/2.0, GET /app HTTP/2.0, GET /.env.php.bak HTTP/2.0, POST /api/graphql HTTP/2.0
show less
Hacking
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-08-27 17:21:09
(3 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐ช๐ธ
alferez
2026-08-27 17:17:50
(3 days ago)
Searching .(env|sql|zip|tar|rar) files
Hacking
Exploited Host
Web App Attack
๐ช๐ธ
pipeline.es
2026-08-27 14:45:58
(3 days ago)
Web scanning / probing for vulnerable paths | URL: /.env.example | Evidence: geaweb.pt 54.235.21.199 ...
show more
Web scanning / probing for vulnerable paths | URL: /.env.example | Evidence: geaweb.pt 54.235.21.199 - - [27/Aug/2026:16:44:09 +0200] \"GET /.env.example HTTP/2.0\" 404 20610 \"-\" \"Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; GPTBot/1.0; +https://openai.com/gptbot)\" GEOIP_COUNTRY_CODE=US | ASN: AMAZON-AES | Country: US
show less
Port Scan
Web App Attack
๐ฉ๐ช
findlab
2026-08-27 14:40:04
(3 days ago)
Backdrop CMS module - malicious activity detected
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 14:26:40
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 54.235.21.199 (ec2-54-235-21-199.compute-1.amaz ...
show more
(mod_security) mod_security (id:210730) triggered by 54.235.21.199 (ec2-54-235-21-199.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 10:26:34.820390 2026] [security2:error] [pid 30180:tid 30180] [client 54.235.21.199:42590] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.scoutinsignia.com|F|2"] [data ".key"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.scoutinsignia.com"] [uri "/privatekey.key"] [unique_id "apBJGroHuM5WwBX_dNtCjgAAADY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
danskefilm.dk
2026-08-27 13:30:01
(3 days ago)
wordpress login attempts
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 13:23:51
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 54.235.21.199 (ec2-54-235-21-199.compute-1.amaz ...
show more
(mod_security) mod_security (id:210730) triggered by 54.235.21.199 (ec2-54-235-21-199.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 09:23:43.603848 2026] [security2:error] [pid 1462:tid 1462] [client 54.235.21.199:47090] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||adrienberthaud.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "adrienberthaud.com"] [uri "/z9x8c7v6b5-debug-trigger-adrienberthaud.com"] [unique_id "apA6XxQqNznKqVx80e9BTgAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
polycoda
2026-08-27 13:10:16
(3 days ago)
AutoBlock: ๐ฏ Vulnerability Scanner (Non Decay-Based) - โ Excessive 40X Errors (Decay-Based) - โช๏ธ Exc ...
show more
AutoBlock: ๐ฏ Vulnerability Scanner (Non Decay-Based) - โ Excessive 40X Errors (Decay-Based) - โช๏ธ Excessive 30X Errors (Decay-Based)
show less
Hacking
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-08-27 13:08:17
(3 days ago)
Excessive multi-domain requests
Brute-Force
Anonymous
2026-08-27 12:16:28
(3 days ago)
54.235.21.199 - - [27/Aug/2026:14:16:19 +0200] "GET / HTTP/1.1" 403 12583 "-" "Mozilla/5.0 (Linux; A ...
show more
54.235.21.199 - - [27/Aug/2026:14:16:19 +0200] "GET / HTTP/1.1" 403 12583 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Mobile Safari/537.36"
54.235.21.199 - - [27/Aug/2026:14:16:25 +0200] "GET /..%2f..%2f.env HTTP/1.1" 400 157 "-" "-"
54.235.21.199 - - [27/Aug/2026:14:16:25 +0200] "GET /users/login HTTP/1.1" 403 12583 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Mobile Safari/537.36"
54.235.21.199 - - [27/Aug/2026:14:16:25 +0200] "GET /assets/manifest.json HTTP/1.1" 403 12583 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Mobile Safari/537.36"
54.235.21.199 - - [27/Aug/2026:14:16:25 +0200] "GET /auth HTTP/1.1" 403 12583 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Mobile Safari/537.36"
54.235.21.199 - - [27/Aug/2026:14:16:25 +0200] "GET /rclone.conf HTTP/1.1" 403 12583 "-" "Mozilla/5.0 (
...
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-08-27 11:50:10
(3 days ago)
Try to access /.hermes/.env
Web App Attack