πΊπΈ
jormaster3k
2026-07-27 05:24:32
(2 hours ago)
Attack against Apache (too many 404s)
Web App Attack
πΊπΈ
antlac1
2026-07-27 02:06:47
(5 hours ago)
crowdsecurity/http-crawl-non_statics
Brute-Force
Web App Attack
π©π°
HostingGroup
2026-07-27 01:26:53
(6 hours ago)
Automated malicious activity (Honeypot Trap) detected and blocked at the CDN edge by NordicCDN Shiel ...
show more
Automated malicious activity (Honeypot Trap) detected and blocked at the CDN edge by NordicCDN Shield. Offenses: 15. First blocked: 2026-07-27.
show less
Bad Web Bot
Web App Attack
πͺπΈ
alferez
2026-07-27 00:21:39
(7 hours ago)
Searching .(env|sql|zip|tar|rar) files
Hacking
Exploited Host
Web App Attack
π«π·
Catalin Negru
2026-07-26 23:50:38
(7 hours ago)
2026-07-27 02:50:12,522 fail2ban.actions [890352]: NOTICE [apache-dirscan] Ban 139.59.225.35 ...
show more
2026-07-27 02:50:12,522 fail2ban.actions [890352]: NOTICE [apache-dirscan] Ban 139.59.225.35
2026-07-27 02:50:12,831 fail2ban.actions [890352]: NOTICE [laravel-env] Ban 139.59.225.35
2026-07-27 02:50:37,886 fail2ban.actions [890352]: NOTICE [apache-security] Ban 139.59.225.35
2026-07-27 02:50:37,920 fail2ban.actions [890352]: NOTICE [laravel-auth] Ban 139.59.225.35
2026-07-27 02:50:38,278 fail2ban.actions [890352]: NOTICE [web-scanner] Ban 139.59.225.35
...
show less
Brute-Force
Web App Attack
πΏπ¦
conure
2026-07-26 22:13:32
(9 hours ago)
csagent: score 20.5: secrets grab x2, 404 noise floor x2; 1 domain(s) in 0s
Web App Attack
π³π±
Eric
2026-07-26 21:34:15
(10 hours ago)
[Sun Jul 26 21:32:28.891440 2026] [security2:error] [pid 2578225:tid 2578225] [client 139.59.225.35: ...
show more
[Sun Jul 26 21:32:28.891440 2026] [security2:error] [pid 2578225:tid 2578225] [client 139.59.225.35:38902] [client 139.59.225.35] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "fambus.nl"] [uri "/portal/.env"] [unique_id "amZ87LLF8PDWLArJDiM6VQAAABQ"], referer: http://94-209-38-171.cable.dynamic.v4.ziggo.nl/portal/.env
[Sun Jul 26 21:32:29.098594 2026] [security2:error] [pid 2578241:tid 2578241] [client 139.59.225.35:60694] [client 139.59.225.35] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [i
...
show less
Hacking
Web App Attack
π§πͺ
sid3windr
2026-07-26 19:33:37
(12 hours ago)
GET /.env (Tarpitted for 1d15h8m26s, wasted 8.06MB)
Web App Attack
πΊπΈ
stechusa
2026-07-26 18:48:50
(12 hours ago)
[Askari] | country=SG | ASN=DigitalOcean, LLC | Behavior: HTTP/1.1 only, Outdated browser, HTTP/1.1 ...
show more
[Askari] | country=SG | ASN=DigitalOcean, LLC | Behavior: HTTP/1.1 only, Outdated browser, HTTP/1.1 over TLS, Bot-like session, Inhuman browsing speed
show less
Bad Web Bot
DDoS Attack
πΊπΈ
stechusa
2026-07-26 18:48:50
(12 hours ago)
country=SG | ASN=DigitalOcean, LLC | 50 requests with only 1 static assets (2%) - likely automated | ...
show more
country=SG | ASN=DigitalOcean, LLC | 50 requests with only 1 static assets (2%) - likely automated | Average 0.00s between page loads (5 pages in 0.0s) | Average 0.00s between page loads (6 pages in 0.0s)
show less
Bad Web Bot
DDoS Attack
π§πͺ
sid3windr
2026-07-26 17:10:41
(14 hours ago)
GET /.env (Tarpitted for 1d15h8m25s, wasted 8.06MB)
Web App Attack
π¬π§
consul.to
2026-07-26 15:52:22
(15 hours ago)
Web attack/malicious scanning detected
Web App Attack
π³πΏ
Antinson
2026-07-26 12:15:25
(19 hours ago)
Scraping with a high error ratio and request rate
Bad Web Bot
π²πΎ
Rizzy
2026-07-26 11:41:43
(20 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack
π³π±
Eric
2026-07-26 11:14:56
(20 hours ago)
[Sun Jul 26 11:14:52.555240 2026] [security2:error] [pid 2168082:tid 2168082] [client 139.59.225.35: ...
show more
[Sun Jul 26 11:14:52.555240 2026] [security2:error] [pid 2168082:tid 2168082] [client 139.59.225.35:41576] [client 139.59.225.35] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "fambus.nl"] [uri "/account/.env"] [unique_id "amXsLF3Jyv-SfsNxXLXUhwAAAA4"], referer: http://94.209.38.171/account/.env
[Sun Jul 26 11:14:56.514012 2026] [security2:error] [pid 2168224:tid 2168224] [client 139.59.225.35:57902] [client 139.59.225.35] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inboun
...
show less
Hacking
Web App Attack