๐ฉ๐ช
enjoyably
2026-08-23 15:05:23
(27 minutes ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐ฌ๐ง
Interceptor_HQ
2026-08-23 13:37:09
(1 hour ago)
request_uri: /.env -- automatic report --
Brute-Force
Hacking
๐ซ๐ท
GabrielJST
2026-08-23 12:57:02
(2 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 149.50.220.171 (FR/France/unn-149-50-22 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 149.50.220.171 (FR/France/unn-149-50-220-171.datapacket.com): (CF_ENABLE)
show less
SQL Injection
๐ฉ๐ช
maxpower
2026-08-23 12:42:45
(2 hours ago)
(PERMBLOCK) 149.50.220.171 (FR/France/unn-149-50-220-171.datapacket.com) has had more than 4 temp bl ...
show more
(PERMBLOCK) 149.50.220.171 (FR/France/unn-149-50-220-171.datapacket.com) has had more than 4 temp blocks in the last 86400 secs; Ports: *; Direction: inout; Trigger: LF_PERMBLOCK_COUNT; Logs:
show less
Port Scan
๐ฌ๐ง
Greg Poulson
2026-08-23 12:40:02
(2 hours ago)
Our website was hit by this DDOS at a rate of 40 in 5 minutes.
DDoS Attack
Web Spam
Brute-Force
๐ฉ๐ช
macrob
2026-08-23 11:45:26
(3 hours ago)
2026/08/23 11:45:24 [error] 3635683#3635683: *511391169 access forbidden by rule, client: 149.50.220 ...
show more
2026/08/23 11:45:24 [error] 3635683#3635683: *511391169 access forbidden by rule, client: 149.50.220.171, server: fn.binixo.es, request: "GET /.env HTTP/1.1", host: "li1822-160.members.linode.com"
2026/08/23 11:45:24 [error] 3635683#3635683: *511391169 access forbidden by rule, client: 149.50.220.171, server: fn.binixo.es, request: "GET /.env.production HTTP/1.1", host: "li1822-160.members.linode.com"
2026/08/23 11:45:25 [error] 3635683#3635683: *511391169 access forbidden by rule, client: 149.50.220.171, server: fn.binixo.es, request: "GET /.env.local HTTP/1.1", host: "li1822-160.members.linode.com"
...
show less
Web App Attack
๐ซ๐ท
Vaction
2026-08-23 11:29:25
(4 hours ago)
149.50.220.171 - - [23/Aug/2026:13:29:24 +0200] "GET /.env HTTP/1.1" 404 437 "-" "Mozilla/5.0 (Macin ...
show more
149.50.220.171 - - [23/Aug/2026:13:29:24 +0200] "GET /.env HTTP/1.1" 404 437 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 Chrome/125.0.0.0 Safari/537.36"
show less
Hacking
Bad Web Bot
Web App Attack
๐ฉ๐ช
McClay
2026-08-23 10:47:52
(4 hours ago)
HTTP-404 spam:149.50.220.171 - - [23/Aug/2026:12:47:50 +0200] "GET /.env HTTP/1.1" 404 1051 "-" "Moz ...
show more
HTTP-404 spam:149.50.220.171 - - [23/Aug/2026:12:47:50 +0200] "GET /.env HTTP/1.1" 404 1051 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 Chrome/125.0.0.0 Safari/537.36"
149.50.220.171 - - [23/Aug/2026:12:47:50 +0200] "GET /.env.production HTTP/1.1" 404 1050 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 Chrome/125.0.0.0 Safari/537.36"
149.50.220.171 - - [23/Aug/2026:12:47:50 +0200] "GET /.env.local HTTP/1.1" 404 1050 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 Chrome/125.0.0.0 Safari/537.36"
149.50.220.171 - - [23/Aug/2026:12:47:50 +0200] "GET /.env.backup HTTP/1.1" 404 1050 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 Version/17.4.1 Safari/605.1.15"
149.50.220.171 - - [23/Aug/2026:12:47:50 +0200] "GET /.env.bak HTTP/1.1" 404 1050 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 Chrome/120.0.0.0 Safari/537.36"
149.50.220.171 - - [23/Aug/2026:12:47:50 +0200] "GET /.env.old HTTP/1.1" 404 1050 "-" "Mozilla/5.0 (Wind
...
show less
Web App Attack
๐ฉ๐ช
maxpower
2026-08-23 10:28:59
(5 hours ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 149.50.220.171 (FR/France/unn-149-50-220 ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 149.50.220.171 (FR/France/unn-149-50-220-171.datapacket.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 149.50.220.171 - - [23/Aug/2026:12:28:58 +0200] "GET /.aws/credentials HTTP/1.1" 301 162 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 Chrome/120.0.0.0 Safari/537.36" "-" host=leo.spacehosting.ovh
show less
Port Scan
๐ฉ๐ช
ghostwarriors
2026-08-23 09:50:10
(5 hours ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
๐ซ๐ท
dynamix
2026-08-23 09:48:23
(5 hours ago)
Multiple WAF Violations
Web App Attack
๐ฉ๐ช
yitzhaq
2026-08-23 09:29:21
(6 hours ago)
149.50.220.171 - - [23/Aug/2026:11:29:18 +0200] "GET /.env.development HTTP/1.1" 404 494 "-" "Mozill ...
show more
149.50.220.171 - - [23/Aug/2026:11:29:18 +0200] "GET /.env.development HTTP/1.1" 404 494 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 Chrome/125.0.0.0 Safari/537.36"
149.50.220.171 - - [23/Aug/2026:11:29:18 +0200] "GET /.env.test HTTP/1.1" 404 494 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:126.0) Gecko/20100101 Firefox/126.0"
149.50.220.171 - - [23/Aug/2026:11:29:18 +0200] "GET /.env.prod HTTP/1.1" 404 494 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 Chrome/120.0.0.0 Safari/537.36"
149.50.220.171 - - [23/Aug/2026:11:29:18 +0200] "GET /.env.dist HTTP/1.1" 404 494 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 Version/17.4.1 Safari/605.1.15"
149.50.220.171 - - [23/Aug/2026:11:29:18 +0200] "GET /.env.sample HTTP/1.1" 404 494 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 Chrome/125.0.0.0 Safari/537.36"
149.50.220.171 - - [23/Aug/2026:11:29:18 +0200] "GET /api/.env HTTP/1.1" 404 494 "-" "Mozilla/5.0 (X11; Linu
show less
Web App Attack
Hacking
๐ฉ๐ช
McClay
2026-08-23 08:47:06
(6 hours ago)
HTTP-404 spam:149.50.220.171 - - [23/Aug/2026:10:47:05 +0200] "GET /.env HTTP/1.1" 404 1051 "-" "Moz ...
show more
HTTP-404 spam:149.50.220.171 - - [23/Aug/2026:10:47:05 +0200] "GET /.env HTTP/1.1" 404 1051 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:126.0) Gecko/20100101 Firefox/126.0"
149.50.220.171 - - [23/Aug/2026:10:47:05 +0200] "GET /.env.production HTTP/1.1" 404 1050 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 Chrome/125.0.0.0 Safari/537.36"
149.50.220.171 - - [23/Aug/2026:10:47:05 +0200] "GET /.env.local HTTP/1.1" 404 1050 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 Chrome/120.0.0.0 Safari/537.36"
149.50.220.171 - - [23/Aug/2026:10:47:05 +0200] "GET /.env.backup HTTP/1.1" 404 1050 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 Version/17.4.1 Safari/605.1.15"
149.50.220.171 - - [23/Aug/2026:10:47:06 +0200] "GET /.env.bak HTTP/1.1" 404 1050 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 Chrome/125.0.0.0 Safari/537.36"
149.50.220.171 - - [23/Aug/2026:10:47:06 +0200] "GET /.env.old HTTP/1.1" 404 1050 "-" "Mozilla/5.0
...
show less
Web App Attack
๐ฉ๐ช
maxpower
2026-08-23 08:33:37
(6 hours ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 149.50.220.171 (FR/France/unn-149-50-220 ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 149.50.220.171 (FR/France/unn-149-50-220-171.datapacket.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 149.50.220.171 - - [23/Aug/2026:10:33:34 +0200] "GET /.aws/credentials HTTP/1.1" 301 162 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 Version/17.4.1 Safari/605.1.15" "-" host=fornax.spacehosting.ovh
show less
Port Scan
๐บ๐ธ
ratcarcher-labs
2026-08-23 08:05:20
(7 hours ago)
[Ratcarcher Labs/MutantShield honeypot CTI] actor=human vector=scanner_probe risk=55 attacks=3 depth ...
show more
[Ratcarcher Labs/MutantShield honeypot CTI] actor=human vector=scanner_probe risk=55 attacks=3 depth=0 node=node-eu-west canary=no human_score=35 agentic=15 cc=FR asn=Datacamp Limited | Data provided by Ratcarcher Labs ยท https://ratcarcher-labs.com ยท docs https://api.ratcarcher-labs.com/api/v1/public/docs
show less
Port Scan
Bad Web Bot