πΊπΈ
micropedro
2026-08-20 10:38:12
(2 days ago)
3 incidents: port scanning. First: 2026-08-06 16:00, Last: 2026-08-20 06:38 UTC. Triggers: non-publi ...
show more
3 incidents: port scanning. First: 2026-08-06 16:00, Last: 2026-08-20 06:38 UTC. Triggers: non-public-port,firewall-tcp,unknown.
show less
Port Scan
π³π±
homeshowdomain.nl
2026-08-09 22:00:35
(1 week ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-08-08.
show less
Web App Attack
SSH
Hacking
π©πͺ
EnthecSolutions
2026-08-09 06:02:16
(1 week ago)
Detected by Enthec Solutions. | Attempts: 78 in 24h | Target port: 80
Web App Attack
πΊπΈ
Epimetheus
2026-08-09 03:08:56
(1 week ago)
Zombie network / Bot scanner detected:
[POST] /graphql
[GET] /.well-known/security.txt
[GET] /servi ...
show more
Zombie network / Bot scanner detected:
[POST] /graphql
[GET] /.well-known/security.txt
[GET] /service-account.json
[GET] /.env.prod
[GET] /secrets.json
[GET] /env.js
[GET] /.git/HEAD
[GET] /serviceAccountKey.json
[GET] /web.config
[GET] /laravel/.env
[GET] /application.properties
[GET] /appsettings.json
[GET] /openapi.json
[GET] /sitemap.xml
[GET] /key.json
[GET] /wp/.env
[GET] /api/config
[GET] /settings.json
[GET] /firebase-adminsdk.json
[GET] /.npmrc
[GET] /wp-config.php
[GET] /actuator/configprops
[GET] /.env.local
[GET] /serverless.yml
[GET] /swagger.json
[GET] /netlify.toml
[GET] /api/.env
[GET] /.env.test
[GET] /.git/config
[GET] /awsconfiguration.json
[GET] /app/.env
[GET] /firebase.json
[GET] /terraform.tfstate
[GET] /.gitlab-ci.yml
[GET] /vercel.json
[GET] /actuator/env
[GET] /.env.backup
[GET] /.env.development
[GET] /docker-compose.yml
[GET] /debug/vars
[GET] /token.json
UA: Mozilla/5.0 (compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot)
show less
Bad Web Bot
Exploited Host
Web App Attack
πΊπΈ
alecj.com
2026-08-09 02:33:11
(1 week ago)
This IP was detected by CrowdSec triggering crowdsecurity/appsec-vpatch
Web App Attack
πΊπΈ
Power Ca
2026-08-09 02:32:04
(1 week ago)
159.65.35.52 - - [09/Aug/2026:02:32:00 +0000] "GET /.git/config HTTP/2.0" 404 55 "-" "Mozilla/5.0 (c ...
show more
159.65.35.52 - - [09/Aug/2026:02:32:00 +0000] "GET /.git/config HTTP/2.0" 404 55 "-" "Mozilla/5.0 (compatible; YandexBot/3.0; +http://yandex.com/bots)"
159.65.35.52 - - [09/Aug/2026:02:32:00 +0000] "GET /.git/HEAD HTTP/2.0" 404 53 "-" "Mozilla/5.0 (compatible; ClaudeBot/1.0; [email protected] )"
159.65.35.52 - - [09/Aug/2026:02:32:03 +0000] "GET /.well-known/security.txt HTTP/2.0" 404 68 "-" "Mozilla/5.0 (compatible; YandexBot/3.0; +http://yandex.com/bots)"
159.65.35.52 - - [09/Aug/2026:02:32:03 +0000] "GET /.env HTTP/2.0" 404 48 "-" "Mozilla/5.0 (compatible; OAI-SearchBot/1.3; +https://openai.com/searchbot)"
159.65.35.52 - - [09/Aug/2026:02:32:03 +0000] "GET /.env.backup HTTP/2.0" 404 55 "-" "Mozilla/5.0 (compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm)"
159.65.35.52 - - [09/Aug/2026:02:32:03 +0000] "GET /.env.old HTTP/2.0" 404 52 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ChatGPT-User/1.0; +https://openai.com/bot)"
159.65.35.52 - - [09/Aug/202
...
show less
Bad Web Bot
Web App Attack
πΊπΈ
helios.live
2026-08-09 02:07:06
(1 week ago)
2026/08/09 02:07:05 [error] 3979783#3979783: *1150955 access forbidden by rule, client: 159.65.35.52 ...
show more
2026/08/09 02:07:05 [error] 3979783#3979783: *1150955 access forbidden by rule, client: 159.65.35.52, server: staging.kocerroxy.com, request: "GET /.aws/config HTTP/2.0", host: "staging.kocerroxy.com"
2026/08/09 02:07:05 [error] 3979783#3979783: *1150955 access forbidden by rule, client: 159.65.35.52, server: staging.kocerroxy.com, request: "GET /.netrc HTTP/2.0", host: "staging.kocerroxy.com"
2026/08/09 02:07:05 [error] 3979784#3979784: *1150973 access forbidden by rule, client: 159.65.35.52, server: staging.kocerroxy.com, request: "GET /.gitlab-ci.yml HTTP/2.0", host: "staging.kocerroxy.com"
2026/08/09 02:07:05 [error] 3979783#3979783: *1150984 access forbidden by rule, client: 159.65.35.52, server: staging.kocerroxy.com, request: "GET /.npmrc HTTP/2.0", host: "staging.kocerroxy.com"
2026/08/09 02:07:06 [error] 3979783#3979783: *1150955 access forbidden by rule, client: 159.65.35.52, server: staging.kocerroxy.com, request: "GET /.env.production HTTP/2.0", host: "staging.kocerroxy.com
...
show less
Web App Attack
πΊπΈ
Blue Pumpkin
2026-08-09 02:05:00
(1 week ago)
159.65.35.52 - - [09/Aug/2026:02:04:58 +0000] "GET /serviceAccountKey.json HTTP/1.1" 307 2639 "http: ...
show more
159.65.35.52 - - [09/Aug/2026:02:04:58 +0000] "GET /serviceAccountKey.json HTTP/1.1" 307 2639 "http://staging.hey-ai.com/serviceAccountKey.json" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
...
show less
Brute-Force
π©πͺ
Gwyneth Llewelyn
2026-08-09 00:38:21
(1 week ago)
2026/08/09 01:38:18 [error] 57179#57179: *195373 access forbidden by rule, client: 159.65.35.52, ser ...
show more
2026/08/09 01:38:18 [error] 57179#57179: *195373 access forbidden by rule, client: 159.65.35.52, server: silvana-moreira-portfolio.zonadetestes.com, request: "GET /.env HTTP/2.0", host: "silvana-moreira-portfolio.zonadetestes.com"
159.65.35.52 - - [09/Aug/2026:01:38:18 +0100] "GET /.env HTTP/2.0" 403 1045 "-" "Mozilla/5.0 (compatible; Google-CloudVertexBot; +https://cloud.google.com/vertex-ai-bot)"
2026/08/09 01:38:19 [error] 57178#57178: *195385 access forbidden by rule, client: 159.65.35.52, server: silvana-moreira-portfolio.zonadetestes.com, request: "GET /laravel/.env HTTP/2.0", host: "silvana-moreira-portfolio.zonadetestes.com"
show less
Brute-Force
Web App Attack
πΊπΈ
SX Communications
2026-08-09 00:12:47
(2 weeks ago)
Blocked abusive HTTP application-layer DoS / botnet traffic from 159.65.35.52: traffic from this add ...
show more
Blocked abusive HTTP application-layer DoS / botnet traffic from 159.65.35.52: traffic from this address continues high-cost dynamic page and feed requests at abusive rates via TCP/HTTPS despite edge block responses. Likely compromised end-user host.
show less
DDoS Attack
Bad Web Bot
Exploited Host
πΊπΈ
danaimone
2026-08-08 20:48:31
(2 weeks ago)
nginx-403: suspicious requests
Web App Attack
πΊπΈ
k3rn3l109
2026-08-08 17:34:50
(2 weeks ago)
Sentinel honeypot: cf-waf-auto hit on ota.emby-media.com UA=Mozilla/5.0 (compatible; bingbot/2.0; +h ...
show more
Sentinel honeypot: cf-waf-auto hit on ota.emby-media.com UA=Mozilla/5.0 (compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm)
show less
Hacking
πΊπΈ
jsjdmediallc
2026-08-08 17:20:04
(2 weeks ago)
Auto-blocked: score 37 (threshold 10). Tier: HIGH. Hits: 7. Flags: env-file, backup-file, seo-bot, c ...
show more
Auto-blocked: score 37 (threshold 10). Tier: HIGH. Hits: 7. Flags: env-file, backup-file, seo-bot, credentials, secret-file, sec-probe. Paths: /.env.backup, /api/.env, /app/.env, /.env.bak, /.env.old
show less
Bad Web Bot
Web App Attack
π©πͺ
vvolpl
2026-08-08 16:53:43
(2 weeks ago)
fail2ban: banned by jail apache-honeypot
Web App Attack
πΊπΈ
SLSLLC
2026-08-08 16:17:00
(2 weeks ago)
159.65.35.52 - - [08/Aug/2026:16:16:59 +0000] "GET /.env HTTP/2.0" 404 401 "-" "Mozilla/5.0 (compati ...
show more
159.65.35.52 - - [08/Aug/2026:16:16:59 +0000] "GET /.env HTTP/2.0" 404 401 "-" "Mozilla/5.0 (compatible; DeepSeekBot/1.0; +https://www.deepseek.com/bot)"
...
show less
Brute-Force
Web App Attack