🇩🇪
MBombeck
2026-08-29 20:56:32
(22 minutes ago)
Fail2Ban/traefik-botsearch on apps-01: banned after 5 failures
Web App Attack
🇺🇸
RamSet
2026-08-29 19:55:21
(1 hour ago)
[pit,ycr] HTTP-Probe on port 443 (via domain). 121 distinct paths probed in 39s. Sustained 131 req/m ...
show more
[pit,ycr] HTTP-Probe on port 443 (via domain). 121 distinct paths probed in 39s. Sustained 131 req/min, 118 nonexistent paths (404). Paths: /@fs/app/.env?raw??, /@fs/home/node/.aws/credentials?raw??, /@fs/home/www-data/.aws/credentials?raw??, /@fs/root/.aws/credentials.backup?raw??, /@fs/root/.aws/credentials?raw??, /@fs/.env.staging?raw??, /@fs/.env?raw??, /@fs/..%252f..%252f..%252f..%252f..%252froot/.env?raw??, /@fs/src/.env?raw??, /@fs/root/.env?raw??, /@fs/etc/passwd?raw??, /@fs/.env.development?raw??, /.env?raw??, /@fs/var/www/.aws/credentials?raw??, /@fs/home/ubuntu/.aws/config?raw??, /@fs/.env.production?raw??, /@fs/home/ec2-user/.aws/credentials?raw??, /@fs/var/www/html/.aws/credentials?raw??, /@fs/root/.aws/config?raw??, /@fs/root/.aws/credentials.bak?raw??, /@fs/app/.aws/credentials?raw??, /@fs/home/admin/.aws/credentials?raw??, /@fs/..%252f..%252f..%252f..%252f..%252fapp/.env?raw??, /@fs/home/node/.aws/config?raw??, /@fs/home/ubuntu/.aws/credentials?raw??, …
show less
Bad Web Bot
Web App Attack
🇬🇧
thetomtaylor.co.uk
2026-08-29 16:08:01
(5 hours ago)
Fail2Ban - [WAF]ModSecurity OWASP CRS rule violation on nginx-modsecurity ... [ice01,ice02,wa01,wa02 ...
show more
Fail2Ban - [WAF]ModSecurity OWASP CRS rule violation on nginx-modsecurity ... [ice01,ice02,wa01,wa02]
show less
Hacking
SQL Injection
Web App Attack
🇫🇮
mnazibo
2026-08-29 14:30:28
(6 hours ago)
Date: Aug 29 17:01:32 2026 EAT | Reported IP: 104.199.157.159 mod_security | id: 920440 930100 93011 ...
show more
Date: Aug 29 17:01:32 2026 EAT | Reported IP: 104.199.157.159 mod_security | id: 920440 930100 930110 930130 949110 930140 920500 | TW/usernameab.my_domain/- | Connections: 1 | Blocked: Permanent Block: [LF_MODSEC] | Logs: ; URL file extension is restricted by policy; URL file extension is restricted by policy; Path Traversal Attack (/../) or (/.../); Path Traversal Attack (/../) or (/.../); Path Traversal Attack (/../) or (/.../); Path Traversal Attack (/../) or (/.../); Path Traversal Attack (/../) or (/.../); Restricted File Access Attempt; Restricted File Access Attempt; Restricted File Access Attempt; Restricted File Access Attempt; Restricted File Access Attempt; Restricted File Access Attempt; Restricted File Access Attempt; Restricted File Access Attempt; Restricted File Access Attempt; Restricted File Access Attempt; Restricted File Access Attempt; Restricted File Access Attempt; Restricted File Access Attempt; Restricted File
show less
SQL Injection
Brute-Force
Bad Web Bot
🇦🇺
neilwal
2026-08-29 13:09:50
(8 hours ago)
Web Probe (443): teamhummingbird.neilwallace.au:443 104.199.157.159 - - [29/Aug/2026:23:09:50 +1000] ...
show more
Web Probe (443): teamhummingbird.neilwallace.au:443 104.199.157.159 - - [29/Aug/2026:23:09:50 +1000] "GET /@fs/..%252f..%252f..%252f..%252f..%252froot/.env?raw?? HTTP/1.1" 401 1062 "-" "Mozilla/5.0 (Linux; Android 14; Pixel 8) AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-SearchBot/1.0; +https://www.anthropic.com/claude-searchbot) Chrome/109.0.7969.239 Mobile Safari/537.36"
teamhummingbird.neilwallace.au:443 104.199.157.159 - - [29/Aug/2026:23:09:50 +1000] "GET /@fs/src/.env?raw?? HTTP/1.1" 401 1062 "-" "Mozilla/5.0 (compatible; GrokBot/1.0; +https://x.ai/grokbot)"
teamhummingbird.neilwallace.au:443 104.199.157.159 - - [29/Aug/2026:23:09:50 +1000] "GET /@fs/.env?raw?? HTTP/1.1" 401 1062 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14_6_1) AppleWebKit/605.1.15 (KHTML, like Gecko; compatible; Amzn-SearchBot/1.0; +https://developer.amazon.com/support/amazonbot) Version/18.1 Safari/605.1.15"
show less
Web App Attack
Anonymous
2026-08-29 13:05:05
(8 hours ago)
Web scanner: GET /@fs/../.env?raw??
Web App Attack
Hacking
Anonymous
2026-08-29 12:42:06
(8 hours ago)
Vulnerability scan
Web App Attack
Anonymous
2026-08-29 12:29:41
(8 hours ago)
104.199.157.159 - - [29/Aug/2026:12:28:11 +0000] "GET /.git/config HTTP/2.0" 404 13278 "-" "Mozilla/ ...
show more
104.199.157.159 - - [29/Aug/2026:12:28:11 +0000] "GET /.git/config HTTP/2.0" 404 13278 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Google-Extended/1.0; +http://www.google.com/bot.html)"
104.199.157.159 - - [29/Aug/2026:12:28:11 +0000] "GET /.git/HEAD HTTP/2.0" 404 13274 "-" "Mozilla/5.0 (compatible; Discordbot/2.0; +https://discordapp.com)"
104.199.157.159 - - [29/Aug/2026:12:29:10 +0000] "GET /.env?raw?? HTTP/2.0" 404 13279 "https://www.jinda-massage.nl/@fs/../.env?raw??" "Mozilla/5.0 (compatible; facebookexternalhit/1.1; +http://www.facebook.com/externalhit_uatext.php)"
104.199.157.159 - - [29/Aug/2026:12:29:38 +0000] "GET /.env HTTP/2.0" 301 0 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; WhatsApp/10.0.2.1)"
104.199.157.159 - - [29/Aug/2026:12:29:39 +0000] "GET /.env HTTP/2.0" 404 13267 "https://www.jinda-massage.nl/.env" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; WhatsApp/10.0.2.1)"
...
show less
Brute-Force
Web App Attack
🇩🇪
Skyrider
2026-08-29 11:01:45
(10 hours ago)
crowdsecurity/http-path-traversal-probing
Web App Attack
🇨🇦
polycoda
2026-08-29 10:50:13
(10 hours ago)
AutoBlock: 🎯 Vulnerability Scanner (Non Decay-Based) - ❌ Excessive 40X Errors (Decay-Based)
Hacking
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-29 09:56:39
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.199.157.159 (159.157.199.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 104.199.157.159 (159.157.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 05:56:31.132425 2026] [security2:error] [pid 20034:tid 20034] [client 104.199.157.159:46752] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.rjhills.com"] [uri "/@fs/app/.env"] [unique_id "apKsz3yqBJsVz5sadcsiiAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-29 09:54:19
(11 hours ago)
12 hits, proto=tcp, ports=443,80
Port Scan
Hacking
🇺🇸
TPI-Abuse
2026-08-29 09:29:14
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.199.157.159 (159.157.199.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 104.199.157.159 (159.157.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 05:29:10.461384 2026] [security2:error] [pid 26968:tid 26968] [client 104.199.157.159:38058] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.nunsunveiled.com"] [uri "/@fs/root/.env"] [unique_id "apKmZmJi8zq9DJrV8GxZZAAAADc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-29 08:28:12
(12 hours ago)
Bot / seems abusive / Apache connections: 52
DDoS Attack
Web Spam
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-29 08:25:31
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.199.157.159 (159.157.199.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 104.199.157.159 (159.157.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 04:25:24.688040 2026] [security2:error] [pid 8441:tid 8441] [client 104.199.157.159:58930] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.ktnote.com"] [uri "/@fs/src/.env"] [unique_id "apKXdF8VVch0Oy8WakAIaQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack