Anonymous
2026-06-05 05:54:35
(43 minutes ago)
(caddyscan) Scanner path probe from 145.79.30.56 (MY/Malaysia/-): 5 in the last 3600 secs; Ports: *; ...
show more
(caddyscan) Scanner path probe from 145.79.30.56 (MY/Malaysia/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 145.79.30.56 - - [05/Jun/2026:05:54:31 +0000] "GET /dev/.env HTTP/1.1"
[REDACTED] 200 2627 145.79.30.56 - - [05/Jun/2026:05:54:31 +0000] "GET /api/.env HTTP/1.1"
[REDACTED] 200 2627 145.79.30.56 - - [05/Jun/2026:05:54:31 +0000] "GET /core/.env HTTP/1.1"
[REDACTED] 200 2627 145.79.30.56 - - [05/Jun/2026:05:54:31 +0000] "GET /backend/.env HTTP/1.1"
[REDACTED] 200 2627 145.79.30.56 - - [05/Jun/2026:05:54:31 +0000] "GET /.env HTTP/1.1"
show less
Port Scan
๐บ๐ธ
Matthew Ping
2026-06-05 03:13:21
(3 hours ago)
ModSecurity rule 949110 triggered on wp1. Web application attack blocked by CSF/LFD.
Web App Attack
Hacking
Anonymous
2026-06-04 23:01:41
(7 hours ago)
(caddyscan) Scanner path probe from 145.79.30.56 (MY/Malaysia/-): 5 in the last 3600 secs; Ports: *; ...
show more
(caddyscan) Scanner path probe from 145.79.30.56 (MY/Malaysia/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 145.79.30.56 - - [04/Jun/2026:23:01:37 +0000] "GET /member/.env HTTP/1.1"
[REDACTED] 200 2627 145.79.30.56 - - [04/Jun/2026:23:01:37 +0000] "GET /app/.env HTTP/1.1"
[REDACTED] 200 2627 145.79.30.56 - - [04/Jun/2026:23:01:37 +0000] "GET /core/.env HTTP/1.1"
[REDACTED] 200 2627 145.79.30.56 - - [04/Jun/2026:23:01:37 +0000] "GET /backend/.env HTTP/1.1"
[REDACTED] 200 2627 145.79.30.56 - - [04/Jun/2026:23:01:37 +0000] "GET /api/.env HTTP/1.1"
show less
Port Scan
๐ซ๐ท
masterguru
2026-06-04 22:46:01
(7 hours ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-195)
Hacking
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-06-04 19:46:09
(10 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-06-04 18:48:34
(11 hours ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-201)
Hacking
Web App Attack
๐ฌ๐ง
consul.to
2026-06-04 16:43:00
(13 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐ซ๐ท
masterguru
2026-06-04 14:43:13
(15 hours ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-193)
Hacking
Web App Attack
๐บ๐ธ
xxkodedxx
2026-06-04 12:40:36
(17 hours ago)
[Zorvexus edge-defense] GET .env / WordPress honeypot probe
Trigger: 1ร honeypot-get in 10m window.
...
show more
[Zorvexus edge-defense] GET .env / WordPress honeypot probe
Trigger: 1ร honeypot-get in 10m window.
Active: 12:40:16โ12:40:17 UTC
Volume: 9 honeypot probe(s)
Bait taken: /api/.env, /backend/.env, /.env, /admin/.env, /dev/.env
UA: "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36"
Auto-banned 30d. zorvexus-banner.
show less
Bad Web Bot
Web App Attack
Anonymous
2026-06-04 09:22:25
(21 hours ago)
(caddyscan) Scanner path probe from 145.79.30.56 (MY/Malaysia/-): 5 in the last 3600 secs; Ports: *; ...
show more
(caddyscan) Scanner path probe from 145.79.30.56 (MY/Malaysia/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 145.79.30.56 - - [04/Jun/2026:09:22:19 +0000] "GET /dev/.env HTTP/1.1"
[REDACTED] 200 2627 145.79.30.56 - - [04/Jun/2026:09:22:19 +0000] "GET /api/.env HTTP/1.1"
[REDACTED] 200 2627 145.79.30.56 - - [04/Jun/2026:09:22:19 +0000] "GET /core/.env HTTP/1.1"
[REDACTED] 200 2627 145.79.30.56 - - [04/Jun/2026:09:22:19 +0000] "GET /.env HTTP/1.1"
[REDACTED] 200 2627 145.79.30.56 - - [04/Jun/2026:09:22:19 +0000] "GET /admin/.env HTTP/1.1"
show less
Port Scan
Anonymous
2026-06-04 08:12:20
(22 hours ago)
PSCSERV WPSCAN 145.79.30.56
Bad Web Bot
Web App Attack
๐ง๐ท
vfAcceloReporter
2026-06-04 06:21:48
(1 day ago)
145.79.30.56 - - [04/Jun/2026:03:21:48 -0300] "GET /dev/.env HTTP/1.1" 301 169 "-" "Mozilla/5.0 (Mac ...
show more
145.79.30.56 - - [04/Jun/2026:03:21:48 -0300] "GET /dev/.env HTTP/1.1" 301 169 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36"
...
show less
Brute-Force
Web App Attack
Exploited Host
๐ซ๐ท
masterguru
2026-06-04 04:31:13
(1 day ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-196)
Hacking
Web App Attack
๐บ๐ธ
billfor
2026-06-04 02:58:46
(1 day ago)
145.79.30.56 - - [03/Jun/2026:22:58:43 -0400] "GET /member/.env HTTP/1.1" 404 0 "-" "Mozilla/5.0 (Ma ...
show more
145.79.30.56 - - [03/Jun/2026:22:58:43 -0400] "GET /member/.env HTTP/1.1" 404 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36"
show less
Web App Attack
๐ง๐ท
P1n4
2026-06-04 01:58:40
(1 day ago)
Heimdal IDS auto-block: sensitive_file (score=1.00)
Web App Attack