🇺🇸
Shouddy Tarano
2026-09-12 22:46:44
(1 hour ago)
[Sat Sep 12 16:46:39.902398 2026] [authz_core:error] [pid 2865482:tid 139792285083392] [client 13.22 ...
show more
[Sat Sep 12 16:46:39.902398 2026] [authz_core:error] [pid 2865482:tid 139792285083392] [client 13.220.90.211:14396] AH01630: client denied by server configuration: /var/www/erpcampestremty/public/
[Sat Sep 12 16:46:39.911107 2026] [authz_core:error] [pid 2865482:tid 139792285083392] [client 13.220.90.211:14396] AH01630: client denied by server configuration: /usr/share/httpd/noindex/index.html
[Sat Sep 12 16:46:41.285988 2026] [authz_core:error] [pid 2964910:tid 139792352225024] [client 13.220.90.211:21003] AH01630: client denied by server configuration: /var/www/erpcampestremty/public/actuator
[Sat Sep 12 16:46:42.374258 2026] [authz_core:error] [pid 2865482:tid 139792318654208] [client 13.220.90.211:24260] AH01630: client denied by server configuration: /var/www/erpcampestremty/public/index.php\n
[Sat Sep 12 16:46:43.146998 2026] [authz_core:error] [pid 2965053:tid 139792402581248] [client 13.220.90.211:28108] AH01630: client denied by server configuration: /var/www/erpcampestremty/p
...
show less
DDoS Attack
Web Spam
Brute-Force
Web App Attack
🇫🇷
agroman93
2026-09-12 22:41:33
(1 hour ago)
SSH honeypot: automated brute-force login attempts against a decoy server. Source seen attacking a p ...
show more
SSH honeypot: automated brute-force login attempts against a decoy server. Source seen attacking a public sensor.
show less
Brute-Force
SSH
🇺🇸
zwebvigil
2026-09-12 21:05:54
(3 hours ago)
13.220.90.211 [12/Sep/2026:14:05:44 -0700] "GET /actuator/gateway/routes HTTP/1.1" 404 2726 "-" por ...
show more
13.220.90.211 [12/Sep/2026:14:05:44 -0700] "GET /actuator/gateway/routes HTTP/1.1" 404 2726 "-" port=11701 "Mozilla/5.0" "-" "-" "<ipaddr>:443" 1079
13.220.90.211 [12/Sep/2026:14:05:45 -0700] "GET /index.php%0a HTTP/1.1" 404 2704 "-" port=15423 "Mozilla/5.0" "-" "-" "<ipaddr>:443" 1000
13.220.90.211 [12/Sep/2026:14:05:46 -0700] "GET /index.php%0aX-Probe:%20test HTTP/1.1" 404 2734 "-" port=19229 "Mozilla/5.0" "-" "-" "<ipaddr>:443" 1168
13.220.90.211 [12/Sep/2026:14:05:52 -0700] "GET /s4s.jsp HTTP/1.1" 404 2694 "-" port=41850 "Mozilla/5.0" "-" "-" "<ipaddr>:443" 1042
13.220.90.211 [12/Sep/2026:14:05:53 -0700] "POST /index.action HTTP/1.1" 404 2704 "-" port=45536 "Mozilla/5.0" "-" "-" "<ipaddr>:443" 709
13.220.90.211 [12/Sep/2026:14:05:54 -0700] "POST /login.action HTTP/1.1" 404 2704 "-" port=49117 "Mozilla/5.0" "-" "-" "<
show less
Web App Attack
🇧🇪
voormedia
2026-09-12 20:30:22
(4 hours ago)
Accessed trap at '/actuator/gateway/routes'
Web App Attack
🇳🇱
wlt-blocker
2026-09-12 20:02:32
(4 hours ago)
Unauthorized access to webpage admin
Web App Attack
🇺🇸
superflea2828
2026-09-12 19:16:30
(5 hours ago)
13.220.90.211 - - [12/Sep/2026:19:16:30 +0000] "GET /.env HTTP/1.1" 404 4444 "-" "Mozilla/5.0"
...
Web App Attack
🇩🇪
burlacu.org
2026-09-12 18:15:05
(6 hours ago)
Nginx multi-log analysis detected: wordpress_scan. Evidence: WordPress config access with 2 attempts ...
show more
Nginx multi-log analysis detected: wordpress_scan. Evidence: WordPress config access with 2 attempts. Blocked automatically.
show less
Web App Attack
Bad Web Bot
🇮🇪
AutosOnShow
2026-09-12 18:00:08
(6 hours ago)
blocked for webapp attack | path requested: /login.action | seen at 2026-09-12 17:59:49.555 |
Web App Attack
🇺🇸
ruusvuu
2026-09-12 15:47:34
(8 hours ago)
Automated abuse report: 31 attack/probe requests from Amazon.com, Inc. / US.
Targeted paths: /index. ...
show more
Automated abuse report: 31 attack/probe requests from Amazon.com, Inc. / US.
Targeted paths: /index.php%0a, /_ignition/health-check, /tmui/login.jsp/..%3B/tmui/locallb/workspace/fileRead.jsp, /.git/HEAD, /.env.local.
Sample log lines:
[helpdesk] 9/12/2026 00:39:20 13.220.90.211 GET /credentials 404 150 2.1 ms
[helpdesk] 9/12/2026 00:39:27 13.220.90.211 GET /config/secrets.yml 404 157 1.3 ms
[helpdesk] 9/12/2026 08:47:33 13.220.90.211 GET /actuator/gateway/routes 404 162 4.9 ms
Detected by an automated web-server log monitor.
show less
Web App Attack
Anonymous
2026-09-12 15:36:51
(8 hours ago)
[Sat Sep 12 17:36:46.319971 2026] [authz_core:error] [pid 449507] [client 13.220.90.211:4516] AH0163 ...
show more
[Sat Sep 12 17:36:46.319971 2026] [authz_core:error] [pid 449507] [client 13.220.90.211:4516] AH01630: client denied by server configuration: /var/www/html/default/
[Sat Sep 12 17:36:48.335684 2026] [authz_core:error] [pid 454532] [client 13.220.90.211:15955] AH01630: client denied by server configuration: /var/www/html/default/actuator
[Sat Sep 12 17:36:49.153256 2026] [authz_core:error] [pid 454533] [client 13.220.90.211:21704] AH01630: client denied by server configuration: /var/www/html/default/index.php\n
[Sat Sep 12 17:36:49.991646 2026] [authz_core:error] [pid 449504] [client 13.220.90.211:26834] AH01630: client denied by server configuration: /var/www/html/default/index.php\nX-Probe: test
[Sat Sep 12 17:36:50.910619 2026] [authz_core:error] [pid 449502] [client 13.220.90.211:32273] AH01630: client denied by server configuration: /var/www/html/default/
...
show less
Web App Attack
🇬🇧
SilverZippo
2026-09-12 14:32:36
(10 hours ago)
Web App Attack
Web App Attack
🇸🇬
itachi1706
2026-09-12 13:12:24
(11 hours ago)
13.220.90.211 - - [12/Sep/2026:21:12:23 +0800] "POST / HTTP/1.1" 405 1410 "-" "Mozilla/5.0"
...
Brute-Force
Web App Attack
🇬🇧
kiwi.network
2026-09-12 10:37:20
(13 hours ago)
Incessant port scan:
Port Scan
Hacking
Exploited Host
🇩🇪
sdos.es
2026-09-12 09:27:46
(15 hours ago)
"HTTP Splitting (CR/LF in request filename detected) - Matched Data: found within REQUEST_FILENAME: ...
show more
"HTTP Splitting (CR/LF in request filename detected) - Matched Data: found within REQUEST_FILENAME: /index.php\x0a"
show less
Web App Attack
🇬🇧
Don Felip
2026-09-12 09:21:28
(15 hours ago)
Web Exploiter - Banned by Fail2Ban
Hacking
Web App Attack