๐ซ๐ท
Kejult
2026-09-30 06:24:20
(1 day ago)
Honeypot Finding: repeated TCP service probing on TCP/443 (HTTPS); 26 application-level events acros ...
show more
Honeypot Finding: repeated TCP service probing on TCP/443 (HTTPS); 26 application-level events across 26 source port(s). Sensor(s): H0neytr4p.
show less
Port Scan
๐ซ๐ท
Entalpi.net
2026-09-30 02:15:37
(1 day ago)
Repeated requests against sensitive web endpoints
Web App Attack
๐ฉ๐ช
klaus_ph
2026-09-29 23:54:13
(1 day ago)
2026-09-27 17:25:28,722 fail2ban.actions [594716]: NOTICE [ipblocklist] Ban 13.50.65.206
...
Bad Web Bot
๐บ๐ธ
wteiken
2026-09-29 20:11:24
(2 days ago)
rocinante.teiken.net:443 13.50.65.206:59776 - - [29/Sep/2026:16:11:21 -0400] "GET /.env HTTP/1.1" 40 ...
show more
rocinante.teiken.net:443 13.50.65.206:59776 - - [29/Sep/2026:16:11:21 -0400] "GET /.env HTTP/1.1" 404 3361 "-" "Mozilla/5.0"
rocinante.teiken.net:443 13.50.65.206:59782 - - [29/Sep/2026:16:11:22 -0400] "GET /.env.local HTTP/1.1" 404 3360 "-" "Mozilla/5.0"
rocinante.teiken.net:443 13.50.65.206:59798 - - [29/Sep/2026:16:11:22 -0400] "GET /.env.prod HTTP/1.1" 404 3360 "-" "Mozilla/5.0"
rocinante.teiken.net:443 13.50.65.206:59800 - - [29/Sep/2026:16:11:22 -0400] "GET /.env.production HTTP/1.1" 404 3361 "-" "Mozilla/5.0"
rocinante.teiken.net:443 13.50.65.206:59804 - - [29/Sep/2026:16:11:23 -0400] "GET /.env.staging HTTP/1.1" 404 3362 "-" "Mozilla/5.0"
rocinante.teiken.net:443 13.50.65.206:59818 - - [29/Sep/2026:16:11:23 -0400] "GET /.env.dev HTTP/1.1" 404 3362 "-" "Mozilla/5.0"
rocinante.teiken.net:443 13.50.65.206:55032 - - [29/Sep/2026:16:11:23 -0400] "GET /.env.backup HTTP/1.1" 404 3361 "-" "Mozilla/5.0"
rocinante.teiken.net:443 13.50.65.206:55046 - - [29/Sep/2026:16:11:24 -0400] "GET /.
...
show less
Web App Attack
๐ฉ๐ช
bescared
2026-09-29 06:15:43
(2 days ago)
F2B - Malicious activity detected. URL Probing. -8ff06ede-
Hacking
Bad Web Bot
Web App Attack
๐ฉ๐ช
klaus_ph
2026-09-29 05:36:43
(2 days ago)
2026-09-27 17:04:42,259 fail2ban.actions [8144]: NOTICE [ipblocklist] Ban 13.50.65.206
...
Bad Web Bot
๐ฎ๐ช
AutosOnShow
2026-09-28 22:28:05
(3 days ago)
blocked for webapp attack | path requested: /.env | seen at 2026-09-28 22:27:40.447 |
Web App Attack
๐ฉ๐ช
SCHAPPY
2026-09-28 21:15:43
(3 days ago)
Malicious activity from IP detected: crowdsecurity/http-sensitive-files.
Web App Attack
Hacking
๐ง๐ท
radardatelecom
2026-09-27 22:26:04
(4 days ago)
Blocked by Radar da Telecom firewall โ abuseipdb
Bad Web Bot
Web App Attack
๐ฆ๐บ
electronico
2026-09-27 21:50:25
(4 days ago)
13.50.65.206 - - [28/Sep/2026:08:50:15 +1100] "GET /.env HTTP/1.1" 404 7413 "-" "Mozilla/5.0"
13.50. ...
show more
13.50.65.206 - - [28/Sep/2026:08:50:15 +1100] "GET /.env HTTP/1.1" 404 7413 "-" "Mozilla/5.0"
13.50.65.206 - - [28/Sep/2026:08:50:16 +1100] "GET /.env.local HTTP/1.1" 404 7413 "-" "Mozilla/5.0"
13.50.65.206 - - [28/Sep/2026:08:50:17 +1100] "GET /.env.prod HTTP/1.1" 404 7413 "-" "Mozilla/5.0"
13.50.65.206 - - [28/Sep/2026:08:50:18 +1100] "GET /.env.production HTTP/1.1" 404 7413 "-" "Mozilla/5.0"
13.50.65.206 - - [28/Sep/2026:08:50:19 +1100] "GET /.env.staging HTTP/1.1" 404 7413 "-" "Mozilla/5.0"
13.50.65.206 - - [28/Sep/2026:08:50:20 +1100] "GET /.env.dev HTTP/1.1" 404 7413 "-" "Mozilla/5.0"
13.50.65.206 - - [28/Sep/2026:08:50:21 +1100] "GET /.env.backup HTTP/1.1" 404 7413 "-" "Mozilla/5.0"
13.50.65.206 - - [28/Sep/2026:08:50:22 +1100] "GET /.env.bak HTTP/1.1" 404 7413 "-" "Mozilla/5.0"
13.50.65.206 - - [28/Sep/2026:08:50:23 +1100] "GET /.env.old HTTP/1.1" 404 7413 "-" "Mozilla/5.0"
13.50.65.206 - - [28/Sep/2026:08:50:24 +1100] "GET /.env.save HTTP/1.1" 404 7413 "-" "Mozilla/5.0"
...
show less
Brute-Force
Web App Attack
๐ฉ๐ช
Hugopvigo
2026-09-27 20:38:50
(4 days ago)
"2026-09-27 20:38:50+00:00 13.50.65.206 IP con score alto (100) detectada en el log."
Brute-Force
SSH
๐ฆ๐บ
paulshipley.com.au
2026-09-27 16:12:03
(4 days ago)
[Mon Sep 28 02:12:02.845062 2026] [security2:error] [pid 939341] [client 13.50.65.206:51714] [client ...
show more
[Mon Sep 28 02:12:02.845062 2026] [security2:error] [pid 939341] [client 13.50.65.206:51714] [client 13.50.65.206] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "paulshipley.com.au"] [uri "/.env"] [unique_id "arlAUrhMsnTJ3VGjFlYBKgAAABA"]
...
show less
Web App Attack
๐ฉ๐ช
Dennis
2026-09-27 14:17:15
(4 days ago)
13.50.65.206 has been banned for triggering http-sensitive-files (5 events over 472.219339ms).
Brute-Force
Web App Attack
๐ณ๐ฑ
tpjg
2026-09-27 12:06:56
(4 days ago)
Automated: 15 requests with error status in 120s window from 13.50.65.206.
Evidence: /opt/app/.env:4 ...
show more
Automated: 15 requests with error status in 120s window from 13.50.65.206.
Evidence: /opt/app/.env:404,/app/.env:404,/api/.env:404,/backend/.env:404,/config/.env:404,/.env.save:404,/.env.old:404,/.env.bak:404,/.env.backup:404,/.env.dev:404,/.env.staging:404,/.env.production:404,/.env.prod:404,/.env.local:404,/.env:404
show less
Web App Attack
Anonymous
2026-09-27 10:14:26
(4 days ago)
Unauthorized access (443/tcp/https)
Port Scan
Web App Attack