๐ง๐ช
sid3windr
2026-08-28 19:10:23
(6 hours ago)
GET /.env (Tarpitted for 1d15h8m27s, wasted 8.06MB)
Web App Attack
๐ง๐ช
boxed-it
2026-08-28 17:31:51
(8 hours ago)
GET /.git/config (Tarpitted for 1d15h8m27s, wasted 8.06MB)
Web App Attack
๐ง๐ช
boxed-it
2026-08-28 16:28:47
(9 hours ago)
GET /.env (Tarpitted for 1d15h8m28s, wasted 8.06MB)
Web App Attack
Anonymous
2026-08-28 11:58:09
(13 hours ago)
[Fri Aug 28 07:55:18.541175 2026] [authz_core:error] [pid 5685] [client 163.7.14.149:56596] AH01630: ...
show more
[Fri Aug 28 07:55:18.541175 2026] [authz_core:error] [pid 5685] [client 163.7.14.149:56596] AH01630: client denied by server configuration: /home/ageofconsent/public_html/.htaccess
[Fri Aug 28 07:55:19.724799 2026] [authz_core:error] [pid 5816] [client 163.7.14.149:56620] AH01630: client denied by server configuration: /home/ageofconsent/public_html/.htpasswd
[Fri Aug 28 07:55:22.365559 2026] [authz_core:error] [pid 742] [client 163.7.14.149:56740] AH01630: client denied by server configuration: /home/ageofconsent/public_html/.htaccess
[Fri Aug 28 07:55:23.893234 2026] [authz_core:error] [pid 5706] [client 163.7.14.149:57086] AH01630: client denied by server configuration: /home/ageofconsent/public_html/.htaccess
[Fri Aug 28 07:55:25.169904 2026] [authz_core:error] [pid 6005] [client 163.7.14.149:57108] AH01630: client denied by server configuration: /home/ageofconsent/public_html/.htpasswd
...
show less
Brute-Force
๐ฆ๐บ
foff
2026-08-28 07:58:48
(17 hours ago)
Source IP: 163.7.14.149 (ID/Byteplus Pte. Ltd.). Web application attack detected by OWASP CRS (local ...
show more
Source IP: 163.7.14.149 (ID/Byteplus Pte. Ltd.). Web application attack detected by OWASP CRS (local file inclusion). Attack observed 2026-08-28T17:58:48+10:00.
show less
Web App Attack
๐น๐ท
ozyurterdem
2026-08-28 04:00:02
(21 hours ago)
T-Pot Suricata IDS: 7179 alert(s) in 24h. SiberKale Threat Intel (unknown-bad filtered).
Hacking
IoT Targeted
๐ฌ๐ง
seniorlinuxadmin
2026-08-28 02:30:04
(23 hours ago)
163.7.14.149 - - [27/Aug/2026:07:46:23 +0100] "GET / HTTP/1.1" 403 158 "-" "Mozilla/5.0 (Windows NT ...
show more
163.7.14.149 - - [27/Aug/2026:07:46:23 +0100] "GET / HTTP/1.1" 403 158 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:121.0) Gecko/20100101 Firefox/121.0"
show less
Port Scan
Web App Attack
๐ฉ๐ช
Richie
2026-08-28 02:15:10
(23 hours ago)
[HOST1] phpMyAdmin probe: GET /phpmyadmin/ -> HTTP 404; UA: Wget/1.21.1 (linux-gnu)
Bad Web Bot
Web App Attack
๐ฌ๐ง
Mendip_Defender
2026-08-28 01:52:40
(23 hours ago)
[28/Aug/2026:02:52:50.509856 +0100] apDp8gq73TMlKOyV0jk9tAAAAEc 163.7.14.149 39576 188.246.206.60 70 ...
show more
[28/Aug/2026:02:52:50.509856 +0100] apDp8gq73TMlKOyV0jk9tAAAAEc 163.7.14.149 39576 188.246.206.60 7080
[28/Aug/2026:02:52:50.512833 +0100] apDp8gq73TMlKOyV0jk9tgAAAFA 163.7.14.149 39588 188.246.206.60 7080
...
show less
Brute-Force
๐ญ๐บ
whitehoodie
2026-08-28 01:32:51
(1 day ago)
AUTOMATED REPORT: Trying to access PhpMyAdmin
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
gerensat
2026-08-28 01:21:09
(1 day ago)
2026-08-27 22:21:09 | / | [] | Wget/1.21.1 (linux-gnu)
Web App Attack
๐ญ๐บ
whitehoodie
2026-08-28 00:56:42
(1 day ago)
AUTOMATED REPORT: Tried to access .env file
Hacking
Bad Web Bot
Web App Attack
๐ฉ๐ช
ut-addicted.com
2026-08-27 21:53:12
(1 day ago)
\[Thu Aug 27 23:53:11.071625 2026\] \[:error\] \[pid 24040:tid 140352461670144\] \[client 163.7.14.1 ...
show more
\[Thu Aug 27 23:53:11.071625 2026\] \[:error\] \[pid 24040:tid 140352461670144\] \[client 163.7.14.149:56428\] \[client 163.7.14.149\] ModSecurity: Access denied with code 403 \(phase 2\). Operator GE matched 5 at TX:anomaly_score. \[file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-949-BLOCKING-EVALUATION.conf"\] \[line "57"\] \[id "949110"\] \[msg "Inbound Anomaly Score Exceeded \(Total Score: 5\)"\] \[severity "CRITICAL"\] \[tag "application-multi"\] \[tag "language-multi"\] \[tag "platform-multi"\] \[tag "attack-generic"\] \[hostname "www.ut-addicted.com"\] \[uri "/.env.staging"\] \[unique_id "apCxx9aAvDQUvGXJgE9f8QAAAJA"\]
show less
Brute-Force
Web App Attack
๐ซ๐ท
guillaume illien
2026-08-27 21:14:48
(1 day ago)
163.7.14.149 - - [27/Aug/2026:21:14:39 +0000] "GET /assets/js/runtime-main.chunk.js HTTP/1.1" 404 13 ...
show more
163.7.14.149 - - [27/Aug/2026:21:14:39 +0000] "GET /assets/js/runtime-main.chunk.js HTTP/1.1" 404 134 "-" "Googlebot/2.1 (+http://www.google.com/bot.html)"
163.7.14.149 - - [27/Aug/2026:21:14:40 +0000] "GET /assets/js/runtime-main.bundle.js HTTP/1.1" 404 134 "-" "Apache-HttpClient/4.5.13"
163.7.14.149 - - [27/Aug/2026:21:14:40 +0000] "GET /assets/js/runtime-main.js HTTP/1.1" 404 134 "-" "python-requests/2.28.0"
163.7.14.149 - - [27/Aug/2026:21:14:44 +0000] "GET /assets/js/runtime-main.json HTTP/1.1" 404 134 "-" "Apache-HttpClient/4.5.13"
163.7.14.149 - - [27/Aug/2026:21:14:44 +0000] "GET /assets/js/runtime-main.bundle.json HTTP/1.1" 404 197 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 Chrome/120.0.0.0 Safari/537.36"
163.7.14.149 - - [27/Aug/2026:21:14:44 +0000] "GET /assets/js/runtime-main.chunk.json HTTP/1.1" 404 197 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 Chrome/120.0.0.0 Safari/537.36"
163.7.14.149 - - [27/Aug/2026:21:14:48 +0000] "GET /assets/js
...
show less
Hacking
Brute-Force
Web App Attack
SSH
Anonymous
2026-08-27 20:31:33
(1 day ago)
[Thu Aug 27 20:31:32.303091 2026] [security2:error] [pid 513486:tid 513486] [client 163.7.14.149:508 ...
show more
[Thu Aug 27 20:31:32.303091 2026] [security2:error] [pid 513486:tid 513486] [client 163.7.14.149:50840] [client 163.7.14.149] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 8)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "95.211.63.1"] [uri "/.env.php"] [unique_id "apCepNZhXVMFIbSu-0BDzQAAAAQ"]
[Thu Aug 27 20:31:32.368045 2026] [security2:error] [pid 511369:tid 511369] [client 163.7.14.149:50960] [client 163.7.14.149] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 8)"] [severity
...
show less
Web App Attack