Anonymous
2026-07-29 07:00:00
(4 weeks ago)
Apache probe; attempts=892; exact paths: /.env | /.env.backup | /.env.bak | /.env.dev | /.env.develo ...
show more
Apache probe; attempts=892; exact paths: /.env | /.env.backup | /.env.bak | /.env.dev | /.env.development | /.env.example | /.env.local | /.env.old | /.env.php.bak | /.env.prod.bak | /.env.production | /.env.production.bak | /.env.staging | /.env.swp | /.env.test | /.git-credentials | /.git/HEAD | /.git/config | /.hermes/.env | /.openclaw/.env | /@fs/.env?raw?? | /@fs/root/.env?raw?? | /actuator | /actuator/configprops | /actuator/env | /actuator/mappings | /admin/.env | /api/.env | /api/.env/ | /app/.env | /backend/.env | /config.env | /config/.env | /config/.env.php | /core/.env | /dev/.env | /docker/.env | /frontend/.env | /laravel/.env | /production/.env | /public/.env | /sendgrid.env | /server/.env | /src/.env | /staging/.env | /web/.env
show less
Web App Attack
๐ณ๐ฑ
Site.eu
2026-07-28 12:12:29
(1 month ago)
Excessive multi-domain requests
Brute-Force
๐ซ๐ท
IRISIO
2026-07-27 16:22:01
(1 month ago)
scans/SQL injection/spam posts : 3273 queries
Web App Attack
SQL Injection
๐ณ๐ฑ
Site.eu
2026-07-27 09:19:22
(1 month ago)
Excessive multi-domain requests
Brute-Force
๐ฎ๐น
CoreTech srl
2026-07-27 05:37:17
(1 month ago)
[DC: IP:151.1.252.27] ntopng alert: blacklisted_client_contact
Hacking
๐ซ๐ท
IRISIO
2026-07-26 20:17:06
(1 month ago)
scans/SQL injection/spam posts : 1675 queries
Web App Attack
SQL Injection
๐ฎ๐ณ
evicky2002
2026-07-26 06:00:00
(1 month ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐ฉ๐ช
Trueforce Threat Report
2026-07-26 05:31:02
(1 month ago)
Automated report, trolling for resource vulnerabilities
Bad Web Bot
Web App Attack
๐บ๐ธ
helios.live
2026-07-26 02:02:37
(1 month ago)
2026/07/26 02:02:36 [error] 1996879#1996879: *2775012 access forbidden by rule, client: 35.246.166.1 ...
show more
2026/07/26 02:02:36 [error] 1996879#1996879: *2775012 access forbidden by rule, client: 35.246.166.16, server: kocerroxy.com, request: "GET /.gitconfig HTTP/1.1", host: "app.kocerroxy.com"
2026/07/26 02:02:36 [error] 1996879#1996879: *2775000 access forbidden by rule, client: 35.246.166.16, server: kocerroxy.com, request: "GET /.gitlab-ci.yml HTTP/1.1", host: "app.kocerroxy.com"
2026/07/26 02:02:36 [error] 1996879#1996879: *2775012 access forbidden by rule, client: 35.246.166.16, server: kocerroxy.com, request: "GET /.aws/config HTTP/1.1", host: "app.kocerroxy.com"
2026/07/26 02:02:36 [error] 1996879#1996879: *2775000 access forbidden by rule, client: 35.246.166.16, server: kocerroxy.com, request: "GET /.git-credentials HTTP/1.1", host: "app.kocerroxy.com"
2026/07/26 02:02:36 [error] 1996879#1996879: *2775012 access forbidden by rule, client: 35.246.166.16, server: kocerroxy.com, request: "GET /.aws/credentials HTTP/1.1", host: "app.kocerroxy.com"
...
show less
Web App Attack
๐ฉ๐ช
LRob
2026-07-26 01:35:54
(1 month ago)
CrowdSec: crowdsecurity/http-sensitive-files | req: /.git/HEAD | 5 distinct paths | UA: Mozilla/5.0 ...
show more
CrowdSec: crowdsecurity/http-sensitive-files | req: /.git/HEAD | 5 distinct paths | UA: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; OAI-SearchBot/1.0; +https://openai.com/searchbot
show less
Hacking
๐ง๐ท
mateus.vicente
2026-07-26 01:04:04
(1 month ago)
[2026-07-26T01:04:04Z] Excessive 5xx requests from single IP detected and blocked. (db-srv)
DDoS Attack
Web Spam
Web App Attack
๐ซ๐ฎ
cleverest.eu
2026-07-26 00:06:25
(1 month ago)
MimirWAF has 104 incidents from 1 distinct domain => {"bad_request_uri / script_kiddie_detection","b ...
show more
MimirWAF has 104 incidents from 1 distinct domain => {"bad_request_uri / script_kiddie_detection","bad_request_uri / vcs_probe","blacklisted_access / definite_repeat_offender"}
show less
Brute-Force
Web App Attack
๐ฎ๐ช
Coolnagour
2026-07-25 22:44:07
(1 month ago)
http-probing: /z9x8c7v6b5-debug-trigger-console.icabbicanada.com
Web App Attack
๐ณ๐ฑ
GabrielJST
2026-07-25 22:42:22
(1 month ago)
(mod_security) mod_security triggered on hostname [redacted] 35.246.166.16 (DE/Germany/16.166.246.35 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 35.246.166.16 (DE/Germany/16.166.246.35.bc.googleusercontent.com): (CF_ENABLE)
show less
SQL Injection
๐ซ๐ท
largo-it.net
2026-07-25 21:41:30
(1 month ago)
Jul 25 23:41:28 vps-9f3cdc33 haproxy[2641243]: 35.246.166.16:51774 [25/Jul/2026:23:41:28.643] www_fr ...
show more
Jul 25 23:41:28 vps-9f3cdc33 haproxy[2641243]: 35.246.166.16:51774 [25/Jul/2026:23:41:28.643] www_frontend~ sso1_cluster/sso1_https 0/0/1/11/12 404 1250 - - ---- 72/24/0/0/0 0/0 "GET https://sso.largo.fr/z9x8c7v6b5-debug-trigger-sso.largo.fr HTTP/2.0"
Jul 25 23:41:28 vps-9f3cdc33 haproxy[2641243]: 35.246.166.16:51774 [25/Jul/2026:23:41:28.671] www_frontend~ sso1_cluster/sso1_https 0/0/0/9/9 404 1250 - - ---- 72/24/0/0/0 0/0 "GET https://sso.largo.fr/rclone.conf HTTP/2.0"
Jul 25 23:41:28 vps-9f3cdc33 haproxy[2641243]: 35.246.166.16:51774 [25/Jul/2026:23:41:28.757] www_frontend~ sso1_cluster/sso1_https 0/0/1/11/12 404 1250 - - ---- 73/25/3/3/0 0/0 "GET https://sso.largo.fr/.aws/credentials HTTP/2.0"
Jul 25 23:41:28 vps-9f3cdc33 haproxy[2641243]: 35.246.166.16:51774 [25/Jul/2026:23:41:28.759] www_frontend~ sso1_cluster/sso1_https 0/0/0/16/16 404 1250 - - ---- 73/25/2/2/0 0/0 "GET https://sso.largo.fr/webpack-stats.json HTTP/2.0"
Jul 25 23:41:28 vps-9f3cdc33 haproxy[2641243]: 35.246.166.16
...
show less
Hacking
Bad Web Bot
Web App Attack