π«π·
LRNP
2026-06-29 12:42:23
(1 day ago)
_:8443 163.47.8.108 - - [29/Jun/2026:12:42:22 +0000] "GET /aws-secret.yaml HTTP/1.1" 404 181 "-" "Mo ...
show more
_:8443 163.47.8.108 - - [29/Jun/2026:12:42:22 +0000] "GET /aws-secret.yaml HTTP/1.1" 404 181 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36"
_:8443 163.47.8.108 - - [29/Jun/2026:12:42:23 +0000] "GET /aws_credentials.yml HTTP/1.1" 404 181 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36"
_:8443 163.47.8.108 - - [29/Jun/2026:12:42:23 +0000] "GET /.env.dev HTTP/1.1" 404 181 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36"
_:8443 163.47.8.108 - - [29/Jun/2026:12:42:23 +0000] "GET /.env.config HTTP/1.1" 404 181 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36"
_:8443 163.47.8.108 - - [29/Jun/2026:12:42:23 +0000] "GET /s3_credentials.csv HTTP/1.1" 404 181 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv
...
show less
Bad Web Bot
Web App Attack
π«π·
LRNP
2026-06-29 08:05:04
(1 day ago)
_:8443 163.47.8.108 - - [29/Jun/2026:08:05:01 +0000] "GET /aws-secret.yaml HTTP/1.1" 404 181 "-" "Mo ...
show more
_:8443 163.47.8.108 - - [29/Jun/2026:08:05:01 +0000] "GET /aws-secret.yaml HTTP/1.1" 404 181 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36"
_:8443 163.47.8.108 - - [29/Jun/2026:08:05:03 +0000] "GET /.env HTTP/1.1" 404 181 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36"
_:8443 163.47.8.108 - - [29/Jun/2026:08:05:03 +0000] "GET /aws_credentials.yml HTTP/1.1" 404 181 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36"
_:8443 163.47.8.108 - - [29/Jun/2026:08:05:03 +0000] "GET /aws_secrets.yml HTTP/1.1" 404 181 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36"
_:8443 163.47.8.108 - - [29/Jun/2026:08:05:03 +0000] "GET /aws-ses-service.ts
...
show less
Bad Web Bot
Web App Attack
πΊπΈ
jormaster3k
2026-06-28 17:26:59
(1 day ago)
Attack against Apache (too many 404s)
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-28 16:51:07
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 163.47.8.108 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 163.47.8.108 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 28 12:50:58.966068 2026] [security2:error] [pid 5372:tid 5372] [client 163.47.8.108:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mindmaterial.io"] [uri "/.env.dev.local"] [unique_id "akFQ8ga-E53TNwZN_4MShAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π§π·
dominioz
2026-06-26 14:09:23
(3 days ago)
2026-06-26 14:08:20 GET /secrets.env - - 163.47.8.108 HTTP/1.1 Mozilla/5.0+(Linux;+Android+7.0;+SM-G ...
show more
2026-06-26 14:08:20 GET /secrets.env - - 163.47.8.108 HTTP/1.1 Mozilla/5.0+(Linux;+Android+7.0;+SM-G892A+Build/NRD90M;+wv)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Version/4.0+Chrome/60.0.3112.107+Mobile+Safari/537.36 - 301 457
2026-06-26 14:08:20 GET /.env - - 163.47.8.108 HTTP/1.1 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/91.0.4472.124+Safari/537.36 - 301 443
2026-06-26 14:08:21 GET /secrets.env - - 163.47.8.108 HTTP/1.1 Mozilla/5.0+(Linux;+Android+7.0;+SM-G892A+Build/NRD90M;+wv)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Version/4.0+Chrome/60.0.3112.107+Mobile+Safari/537.36 http://sdbp.com.br/secrets.env 301 550
2026-06-26 14:08:21 GET /.env - - 163.47.8.108 HTTP/1.1 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/91.0.4472.124+Safari/537.36 http://sdbp.com.br/.env 301 536
...
show less
Web App Attack
Anonymous
2026-06-26 11:40:05
(4 days ago)
| Suspicious URL access.
Web App Attack
Hacking
SQL Injection
πͺπΈ
yvoictra
2026-06-25 03:13:20
(5 days ago)
163.47.8.108 - - [25/Jun/2026:05:13:19 +0200] "GET /.env.bak HTTP/1.1" 404 197 "-" "Mozilla/5.0 (Win ...
show more
163.47.8.108 - - [25/Jun/2026:05:13:19 +0200] "GET /.env.bak HTTP/1.1" 404 197 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36"
163.47.8.108 - - [25/Jun/2026:05:13:19 +0200] "GET /s3_keys.json HTTP/1.1" 404 197 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36"
163.47.8.108 - - [25/Jun/2026:05:13:19 +0200] "GET /.env.debug HTTP/1.1" 404 197 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36"
163.47.8.108 - - [25/Jun/2026:05:13:19 +0200] "GET /secrets.env HTTP/1.1" 404 197 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36"
163.47.8.108 - - [25/Jun/2026:05:13:19 +0200] "GET /aws-secret.yaml HTTP/1.1" 404 197 "-" "Mozilla/5.0 (Linux; Android 7.
...
show less
Brute-Force
Web App Attack
π«π·
dynamix
2026-06-24 15:41:49
(5 days ago)
Multiple WAF Violations
Web App Attack
πΊπΈ
stvnrdg.me
2026-06-23 22:20:50
(6 days ago)
163.47.8.108 - - [23/Jun/2026:22:20:49 +0000] "GET /.env.php HTTP/1.1" 404 429 "-" "Mozilla/5.0 (Win ...
show more
163.47.8.108 - - [23/Jun/2026:22:20:49 +0000] "GET /.env.php HTTP/1.1" 404 429 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36"
...
show less
Hacking
πͺπΈ
yvoictra
2026-06-23 22:04:55
(6 days ago)
163.47.8.108 - - [24/Jun/2026:00:04:54 +0200] "GET /aws-secret.yaml HTTP/1.1" 404 197 "-" "Mozilla/5 ...
show more
163.47.8.108 - - [24/Jun/2026:00:04:54 +0200] "GET /aws-secret.yaml HTTP/1.1" 404 197 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36"
163.47.8.108 - - [24/Jun/2026:00:04:54 +0200] "GET /secrets.env HTTP/1.1" 404 197 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36"
163.47.8.108 - - [24/Jun/2026:00:04:54 +0200] "GET /.env.debug HTTP/1.1" 404 197 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36"
163.47.8.108 - - [24/Jun/2026:00:04:54 +0200] "GET /.env.bak HTTP/1.1" 404 197 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36"
163.47.8.108 - - [24/Jun/2026:00:04:54 +0200] "GET /.env.backup HTTP/1.1" 404 197 "-" "Mozilla/5.0 (Windows NT 10.
...
show less
Brute-Force
Web App Attack
π§πͺ
cmbplf
2026-06-22 16:30:34
(1 week ago)
469 requests with url.path *secrets.yml
190 requests with url.path *config.json
114 requests with ...
show more
469 requests with url.path *secrets.yml
190 requests with url.path *config.json
114 requests with url.path *secrets.yaml
show less
Brute-Force
Bad Web Bot