Anonymous
2026-06-09 06:19:10
(2 days ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
Anonymous
2026-06-03 21:29:16
(1 week ago)
Web App Attack
Brute-Force
Web App Attack
๐ฉ๐ช
ValtonTahiri
2026-05-20 18:56:01
(3 weeks ago)
UFW blocked a suspicious connection attempt to a closed or denied port. This activity is commonly as ...
show more
UFW blocked a suspicious connection attempt to a closed or denied port. This activity is commonly associated with port scanning, service discovery, or automated internet probing. Technical: source_ip=104.23.225.165; proto=TCP; source_port=13412; target_port=8443; flags=SYN
show less
Port Scan
๐บ๐ธ
mawan
2026-05-09 12:54:55
(1 month ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐บ๐ธ
mawan
2026-05-03 13:22:31
(1 month ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐บ๐ธ
mawan
2026-04-19 17:56:30
(1 month ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐ฉ๐ช
Sรฉfora Srl
2026-04-17 05:01:55
(1 month ago)
Bad user agents ignoring web crawling rules. Draing bandwidth - detected by Fail2Ban in plesk-apache ...
show more
Bad user agents ignoring web crawling rules. Draing bandwidth - detected by Fail2Ban in plesk-apache-badbot jail
show less
Bad Web Bot
๐ซ๐ฎ
Shaik Sai Meera
2026-04-09 10:55:17
(2 months ago)
IM360 WAF: Request indicates a Headless browser
Brute-Force
Web App Attack
๐บ๐ธ
mawan
2026-03-31 02:26:28
(2 months ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐ต๐ฑ
SwiftServer
2026-03-26 02:15:34
(2 months ago)
104.23.225.165 - - [26/Mar/2026:04:13:50 +0200] "GET /.env.prod HTTP/1.1" 403 195 "-" "Mozilla/5.0 ( ...
show more
104.23.225.165 - - [26/Mar/2026:04:13:50 +0200] "GET /.env.prod HTTP/1.1" 403 195 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36, Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
104.23.225.165 - - [26/Mar/2026:04:13:51 +0200] "GET /.env.dev HTTP/1.1" 403 195 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36, Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
104.23.225.165 - - [26/Mar/2026:04:15:32 +0200] "GET /.env HTTP/1.1" 403 195 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36, Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
104.23.225.165 - - [26/Mar/2026:04:15:32 +0200] "GET /src/.env HTTP/1.1" 403 195 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36, Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, lik
...
show less
Brute-Force
Web App Attack
๐ต๐ฑ
SwiftServer
2026-03-24 18:08:48
(2 months ago)
104.23.225.165 - - [24/Mar/2026:20:08:48 +0200] "GET /var/www/.env HTTP/1.1" 403 134 "-" "curl/8.7.1 ...
show more
104.23.225.165 - - [24/Mar/2026:20:08:48 +0200] "GET /var/www/.env HTTP/1.1" 403 134 "-" "curl/8.7.1"
104.23.225.165 - - [24/Mar/2026:20:08:48 +0200] "GET /var/www/html/.env HTTP/1.1" 403 134 "-" "curl/8.7.1"
104.23.225.165 - - [24/Mar/2026:20:08:48 +0200] "GET /opt/.env HTTP/1.1" 403 134 "-" "curl/8.7.1"
104.23.225.165 - - [24/Mar/2026:20:08:48 +0200] "GET /srv/.env HTTP/1.1" 403 134 "-" "curl/8.7.1"
104.23.225.165 - - [24/Mar/2026:20:08:48 +0200] "GET /.env.example HTTP/1.1" 403 134 "-" "curl/8.7.1"
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
mawan
2026-03-23 20:03:35
(2 months ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐ต๐ฑ
SwiftServer
2026-03-23 09:33:21
(2 months ago)
104.23.225.165 - - [23/Mar/2026:11:33:16 +0200] "GET /laravel/.env HTTP/1.1" 403 195 "-" "Mozilla/5. ...
show more
104.23.225.165 - - [23/Mar/2026:11:33:16 +0200] "GET /laravel/.env HTTP/1.1" 403 195 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36, Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
104.23.225.165 - - [23/Mar/2026:11:33:17 +0200] "GET /.env.aws HTTP/1.1" 403 195 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36, Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
104.23.225.165 - - [23/Mar/2026:11:33:19 +0200] "GET /website/.env HTTP/1.1" 403 195 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36, Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
104.23.225.165 - - [23/Mar/2026:11:33:19 +0200] "GET /dev/.env HTTP/1.1" 403 195 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36, Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36
...
show less
Brute-Force
Web App Attack
๐ต๐ฑ
SwiftServer
2026-03-21 23:52:15
(2 months ago)
104.23.225.165 - - [22/Mar/2026:01:52:14 +0200] "GET /conf/.env HTTP/1.1" 403 195 "-" "Mozilla/5.0 ( ...
show more
104.23.225.165 - - [22/Mar/2026:01:52:14 +0200] "GET /conf/.env HTTP/1.1" 403 195 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36, Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
104.23.225.165 - - [22/Mar/2026:01:52:14 +0200] "GET /site/.env HTTP/1.1" 403 195 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36, Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
104.23.225.165 - - [22/Mar/2026:01:52:14 +0200] "GET /development/.env HTTP/1.1" 403 195 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36, Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
104.23.225.165 - - [22/Mar/2026:01:52:14 +0200] "GET /tests/.env HTTP/1.1" 403 195 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36, Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
mawan
2026-03-06 19:32:22
(3 months ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack