๐ฉ๐ช
FeG Deutschland
2026-05-29 13:39:24
(5 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 127
Exploited Host
Web App Attack
๐ซ๐ท
Martin Lundstrom
2026-05-29 12:16:25
(5 days ago)
https://www.eagleeye-intelligence.com โ WordPress attack. Automatically detected and blocked.
Web App Attack
๐บ๐ธ
Starburst SysOp Team
2026-05-29 09:09:08
(6 days ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-stl2-17)
Hacking
Web App Attack
๐ฉ๐ช
todix
2026-05-29 06:34:08
(6 days ago)
Web App Attack Exploid from 160.250.123.42
Web App Attack
Anonymous
2026-05-29 05:33:16
(6 days ago)
(caddyscan) Scanner path probe from 160.250.123.42 (PK/Pakistan/-): 5 in the last 3600 secs; Ports: ...
show more
(caddyscan) Scanner path probe from 160.250.123.42 (PK/Pakistan/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 160.250.123.42 - - [29/May/2026:05:02:05 +0000] "GET /.env HTTP/1.1"
[REDACTED] 200 2627 160.250.123.42 - - [29/May/2026:05:02:05 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 160.250.123.42 - - [29/May/2026:05:14:45 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 160.250.123.42 - - [29/May/2026:05:14:46 +0000] "GET /.env HTTP/1.1"
[REDACTED] 200 2627 160.250.123.42 - - [29/May/2026:05:33:13 +0000] "GET /.env HTTP/1.1"
show less
Port Scan
๐ณ๐ฟ
Antinson
2026-05-29 02:56:39
(6 days ago)
Requests to unauthorized or suspicious endpoints (.git, .well-known, .php, etc.)
Bad Web Bot
Anonymous
2026-05-28 23:33:24
(6 days ago)
(caddyscan) Scanner path probe from 160.250.123.42 (PK/Pakistan/-): 5 in the last 3600 secs; Ports: ...
show more
(caddyscan) Scanner path probe from 160.250.123.42 (PK/Pakistan/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 160.250.123.42 - - [28/May/2026:23:18:40 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 160.250.123.42 - - [28/May/2026:23:18:40 +0000] "GET /.env HTTP/1.1"
[REDACTED] 200 2627 160.250.123.42 - - [28/May/2026:23:24:22 +0000] "GET /.env HTTP/1.1"
[REDACTED] 200 2627 160.250.123.42 - - [28/May/2026:23:24:23 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 160.250.123.42 - - [28/May/2026:23:33:22 +0000] "GET /.git/config HTTP/1.1"
show less
Port Scan
๐บ๐ธ
xserverx.ru
2026-05-28 22:47:12
(6 days ago)
Honeypot triggered:
IP: 160.250.123.42
Request to: https://xserverx.ru/.git/config
Method: GET
Host: ...
show more
Honeypot triggered:
IP: 160.250.123.42
Request to: https://xserverx.ru/.git/config
Method: GET
Host: xserverx.ru
User-Agent: Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:123.0) Gecko/20100101 Firefox/123.0
Referer: Direct
Country: PK
ASN: Unknown
Triggered rules: (\.git/|\.gitignore|\.git/config), /\.git
Timestamp: 2026-05-28T22:47:11.436Z
show less
Hacking
Bad Web Bot
Web App Attack
Anonymous
2026-05-28 21:09:47
(6 days ago)
(caddyscan) Scanner path probe from 160.250.123.42 (PK/Pakistan/-): 5 in the last 3600 secs; Ports: ...
show more
(caddyscan) Scanner path probe from 160.250.123.42 (PK/Pakistan/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 160.250.123.42 - - [28/May/2026:20:25:03 +0000] "GET /.env HTTP/1.1"
[REDACTED] 200 2627 160.250.123.42 - - [28/May/2026:20:25:03 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 160.250.123.42 - - [28/May/2026:20:52:22 +0000] "GET /.env HTTP/1.1"
[REDACTED] 200 2627 160.250.123.42 - - [28/May/2026:20:52:23 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 160.250.123.42 - - [28/May/2026:21:09:46 +0000] "GET /.env HTTP/1.1"
show less
Port Scan
๐ซ๐ท
dynamix
2026-05-28 18:41:53
(6 days ago)
Multiple WAF Violations
Web App Attack
๐ซ๐ท
vtchost.com
2026-05-28 16:56:41
(6 days ago)
vtchost.com:443 160.250.123.42 - - [28/May/2026:18:56:41 +0200] "GET /.env HTTP/1.1" 418 2792 "-" "M ...
show more
vtchost.com:443 160.250.123.42 - - [28/May/2026:18:56:41 +0200] "GET /.env HTTP/1.1" 418 2792 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:109.0) Gecko/20100101 Firefox/115.0"
...
show less
Bad Web Bot
๐บ๐ธ
Rip
2026-05-28 14:09:28
(6 days ago)
Automated recon attempt targeting restricted and sensitive paths.
Web App Attack
๐จ๐ญ
4server
2026-05-28 12:28:22
(6 days ago)
[ThuMay2814:28:08.1214352026][security2:error][pid132040:tid132400][client160.250.123.42:0]ModSecuri ...
show more
[ThuMay2814:28:08.1214352026][security2:error][pid132040:tid132400][client160.250.123.42:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".env\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"364\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"staging.swiss-sailing-system.ch\"][uri\"/.env\"][unique_id\"ahg02O-cJ8em0ij5hD7XWgAAANc\"]
show less
Hacking
Web App Attack
๐ฆ๐บ
paulshipley.com.au
2026-05-28 11:41:31
(6 days ago)
[Thu May 28 21:41:30.506128 2026] [security2:error] [pid 539674] [client 160.250.123.42:34724] [clie ...
show more
[Thu May 28 21:41:30.506128 2026] [security2:error] [pid 539674] [client 160.250.123.42:34724] [client 160.250.123.42] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "valueaddedpromotions.com.au"] [uri "/.git/config"] [unique_id "ahgp6pI83jX0E3EDqZN7FAAAAAU"]
...
show less
Web App Attack
๐ง๐ช
sid3windr
2026-05-28 07:48:19
(1 week ago)
GET /.git/config (Tarpitted for 1d15h8m28s, wasted 8.06MB)
Web App Attack