๐ฎ๐ณ
evicky2002
2026-05-04 06:00:00
(1 month ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐ฉ๐ช
paissangroup
2026-05-04 02:30:41
(1 month ago)
Multiple WAF Violations
Web App Attack
๐ฉ๐ช
McClay
2026-05-04 02:07:38
(1 month ago)
HTTP-404 spam:34.26.46.253 - - [04/May/2026:04:07:37 +0200] "GET /.env.staging HTTP/1.1" 404 3618 "- ...
show more
HTTP-404 spam:34.26.46.253 - - [04/May/2026:04:07:37 +0200] "GET /.env.staging HTTP/1.1" 404 3618 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_6_8) AppleWebKit/535.2 (KHTML, like Gecko) Chrome/15.0.874.54 Safari/535.2"
34.26.46.253 - - [04/May/2026:04:07:37 +0200] "GET /.env.testing HTTP/1.1" 404 3618 "-" "wii libnup/1.0"
34.26.46.253 - - [04/May/2026:04:07:37 +0200] "GET /.env.local HTTP/1.1" 404 3618 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_14_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36"
34.26.46.253 - - [04/May/2026:04:07:37 +0200] "GET /.env.prod.local HTTP/1.1" 404 3617 "-" "Mozilla/5.0 (Linux; Android 9; LG-H930) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/76.0.3809.111 Mobile Safari/537.36"
34.26.46.253 - - [04/May/2026:04:07:37 +0200] "GET /.env HTTP/1.1" 404 3618 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 11_4_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Mobile/15G77 MicroMessenger/7.0.3(0x17000321) NetType/WIFI Language/zh_CN"
34.26.46.2
...
show less
Web App Attack
๐ฎ๐น
Inartis
2026-05-04 02:04:46
(1 month ago)
34.26.46.253 - - [04/May/2026:04:04:45 +0200] "GET /.env.test HTTP/1.1" 403 3917 "-" "msnbot/1.0 ( h ...
show more
34.26.46.253 - - [04/May/2026:04:04:45 +0200] "GET /.env.test HTTP/1.1" 403 3917 "-" "msnbot/1.0 ( http://search.msn.com/msnbot.htm)"
34.26.46.253 - - [04/May/2026:04:04:45 +0200] "GET /.env~ HTTP/1.1" 403 3917 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.157 Safari/537.36"
34.26.46.253 - - [04/May/2026:04:04:45 +0200] "GET /admin/.env HTTP/1.1" 403 3917 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3770.142 Safari/537.36"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
ingroscart.it
2026-05-04 01:36:51
(1 month ago)
(mod_security) mod_security triggered on hostname [redacted] 34.26.46.253 (US/United States/253.46.2 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.26.46.253 (US/United States/253.46.26.34.bc.googleusercontent.com)
show less
SQL Injection
๐ง๐ช
cmbplf
2026-05-03 22:38:34
(1 month ago)
482 requests with url.path *.env
Brute-Force
Bad Web Bot
Anonymous
2026-05-03 22:03:08
(1 month ago)
"GET /.git/config HTTP/1.1"
Hacking
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-05-03 22:00:57
(1 month ago)
Auto-ban: >3000 req/min op 2026-05-03
Web App Attack
SSH
Hacking
๐ฎ๐น
Progetto1
2026-05-03 19:35:02
(1 month ago)
Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐ณ๐ฑ
Savvii
2026-05-03 19:30:45
(1 month ago)
20 attempts against mh-misbehave-ban on ozone
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-05-03 15:31:54
(1 month ago)
Web attack/malicious scanning detected
Web App Attack
๐ฟ๐ฆ
Tokolosh Hunters
2026-05-03 10:17:41
(1 month ago)
AutoBlockWindow-Known bad useragent query-2026-05-03 10:17:40
Bad Web Bot
๐ฉ๐ช
Blexyel
2026-05-03 09:11:41
(1 month ago)
34.26.46.253 - - [03/May/2026:11:11:40 +0200] "GET /.git/config HTTP/1.1" 404 555 "-" "Mozilla/5.0 ( ...
show more
34.26.46.253 - - [03/May/2026:11:11:40 +0200] "GET /.git/config HTTP/1.1" 404 555 "-" "Mozilla/5.0 (Linux; Android 9; ANE-LX3) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/76.0.3809.111 Mobile Safari/537.36" "stream.pingusmc.org"
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-03 08:49:10
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 34.26.46.253 (253.46.26.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.26.46.253 (253.46.26.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 03 04:49:03.954191 2026] [security2:error] [pid 7240:tid 7240] [client 34.26.46.253:40684] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nivotrol.innovacionesnimba.com"] [uri "/.git/config"] [unique_id "afcL_xIJXyVlEfF9gfzFEwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
4server
2026-05-03 08:21:57
(1 month ago)
[SunMay0310:21:50.0814362026][security2:error][pid3748790:tid3749220][client34.26.46.253:0]ModSecuri ...
show more
[SunMay0310:21:50.0814362026][security2:error][pid3748790:tid3749220][client34.26.46.253:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".git\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"364\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"carolin-mizio.ch\"][uri\"/.git/config\"][unique_id\"afcFnlrIHO9GAGZ0-DCW9wAAAIk\"]
show less
Hacking
Web App Attack