๐ซ๐ฎ
Rauno Asp
2026-09-18 03:26:59
(2 days ago)
Automated .env credentials scanning attempt detected by honeypot on elbasanapartments.al
Web App Attack
๐ณ๐ฑ
cybertailor
2026-09-13 13:23:35
(6 days ago)
104.199.166.128 - - [13/Sep/2026:18:23:25 +0500] "GET /api/uploads/%2e%2e%2f%2e%2e%2f.env HTTP/1.1" ...
show more
104.199.166.128 - - [13/Sep/2026:18:23:25 +0500] "GET /api/uploads/%2e%2e%2f%2e%2e%2f.env HTTP/1.1" 404 146 "-" "Mozilla/5.0 (compatible; Google-Extended; +http://www.google.com/bot.html)"
104.199.166.128 - - [13/Sep/2026:18:23:27 +0500] "GET /.env?raw HTTP/1.1" 404 146 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; OAI-SearchBot/1.0; +https://openai.com/searchbot)"
104.199.166.128 - - [13/Sep/2026:18:23:27 +0500] "GET /.env?import&raw HTTP/1.1" 404 146 "-" "Mozilla/5.0 (compatible; cohere-ai; +https://cohere.com/crawler)"
104.199.166.128 - - [13/Sep/2026:18:23:28 +0500] "GET /.env.production?import&raw HTTP/1.1" 404 146 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-SearchBot/1.0; [email protected] )"
104.199.166.128 - - [13/Sep/2026:18:23:28 +0500] "GET /.env.development?raw HTTP/1.1" 404 146 "-" "Mozilla/5.0 (compatible; KimiBot/1.0; +https://kimi.ai/)"
...
show less
Web App Attack
๐ซ๐ท
Stara
2026-09-13 13:20:24
(6 days ago)
ModSecurity detected web attack - .env/config probing or SQLi/Code injection (Rule 949110)
Brute-Force
Hacking
Web App Attack
๐ฉ๐ช
creoline GmbH
2026-09-13 09:33:56
(6 days ago)
[WAF] Multiple suspicious HTTP requests has been blocked
Bad Web Bot
Web App Attack
๐ซ๐ท
david.houstin
2026-09-13 09:19:14
(6 days ago)
104.199.166.128 - - [13/Sep/2026:11:19:06 +0200] "POST /api/graphql HTTP/2.0" 404 32567 "https://chi ...
show more
104.199.166.128 - - [13/Sep/2026:11:19:06 +0200] "POST /api/graphql HTTP/2.0" 404 32567 "https://chine.in" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36" 52897 -
104.199.166.128 - - [13/Sep/2026:11:19:06 +0200] "GET /config/env/aws_credentials.env HTTP/2.0" 404 32329 "-" "CCBot/2.0 (https://commoncrawl.org/faq/)" 44060 -
104.199.166.128 - - [13/Sep/2026:11:19:06 +0200] "GET /id_rsa HTTP/2.0" 404 34874 "-" "Mozilla/5.0 (compatible; PanguBot/1.0; +https://www.huaweicloud.com/)" 65390 -
104.199.166.128 - - [13/Sep/2026:11:19:11 +0200] "GET /..%2f..%2f.env HTTP/2.0" 404 265 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ChatGPT-User/1.0; +https://openai.com/bot)" 952 -
104.199.166.128 - - [13/Sep/2026:11:19:12 +0200] "GET /uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f.env HTTP/2.0" 404 265 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ChatGPT-User/1.0; +https://openai.com/bot)" 474
...
show less
Web App Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-13 09:16:17
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 104.199.166.128 (128.166.199.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 104.199.166.128 (128.166.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 05:16:13.561102 2026] [security2:error] [pid 15216:tid 15216] [client 104.199.166.128:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "chaitanyaconsult.in"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252froot/.env"] [unique_id "aqZp3TNBDWKXctGUHYHeZwAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-09-13 07:59:01
(6 days ago)
Web attack/malicious scanning detected
Web App Attack
Anonymous
2026-09-12 17:31:27
(1 week ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
Anonymous
2026-09-12 17:08:45
(1 week ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-12 00:21:18
(1 week ago)
Excessive multi-domain requests
Brute-Force
๐ฉ๐ช
ghostwarriors
2026-09-11 21:50:05
(1 week ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
๐ฎ๐น
VHosting
2026-09-11 21:25:03
(1 week ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐ฉ๐ช
yitzhaq
2026-09-11 21:25:00
(1 week ago)
104.199.166.128 - - [11/Sep/2026:23:24:56 +0200] "GET /api/account HTTP/2.0" 404 288 "-" "Mozilla/5. ...
show more
104.199.166.128 - - [11/Sep/2026:23:24:56 +0200] "GET /api/account HTTP/2.0" 404 288 "-" "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)"
104.199.166.128 - - [11/Sep/2026:23:24:56 +0200] "GET /swagger.json HTTP/2.0" 404 288 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-SearchBot/1.0; [email])"
104.199.166.128 - - [11/Sep/2026:23:24:56 +0200] "GET /api/v1/models HTTP/2.0" 404 288 "-" "Mozilla/5.0 (compatible; DeepSeekBot/1.0; +https://www.deepseek.com/)"
104.199.166.128 - - [11/Sep/2026:23:24:56 +0200] "GET /config/.env HTTP/2.0" 404 288 "-" "Mozilla/5.0 (compatible; Meta-ExternalAgent/1.0; +https://developers.facebook.com/docs/sharing/webmasters/crawler)"
104.199.166.128 - - [11/Sep/2026:23:24:56 +0200] "GET /ngsw.json HTTP/2.0" 404 288 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-SearchBot/1.0; [email])"
104.199.166.128 - - [11/Sep/2026:23:24:56 +0200] "GET /.env.backup HTTP/2.0" 404 288 "-
show less
Bad Web Bot
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-11 19:31:00
(1 week ago)
This IP was detected by CrowdSec triggering crowdsecurity/grafana-cve-2021-43798
Web App Attack
Hacking
๐จ๐ฟ
antihack.anarchista.xyz
2026-09-11 19:26:09
(1 week ago)
404 burst: 22 hits in 5 min, URI /_astro/pages/index.astro.mjs.map, Ref , UA Mozilla/5.0 AppleWebKit ...
show more
404 burst: 22 hits in 5 min, URI /_astro/pages/index.astro.mjs.map, Ref , UA Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-SearchBot/1.0; [email protected] )
show less
Brute-Force
Web App Attack
Bad Web Bot