๐ฉ๐ช
msavo
2026-10-02 05:30:43
(1 week ago)
CIR Sentinel: env_probe_permanent; 5 requests in 60s; targets=//.env, //.env.backup, //.env.bak, //. ...
show more
CIR Sentinel: env_probe_permanent; 5 requests in 60s; targets=//.env, //.env.backup, //.env.bak, //.env.config, //.env.dev; permanently blocked by the firewall.
show less
Web App Attack
๐ฉ๐ช
Kejult
2026-09-30 16:21:38
(1 week ago)
Honeypot Finding: repeated TCP service probing on TCP/80 (HTTP); 35 application-level events across ...
show more
Honeypot Finding: repeated TCP service probing on TCP/80 (HTTP); 35 application-level events across 35 source port(s). Sensor(s): Tanner, Honeytrap.
show less
Port Scan
๐บ๐ธ
wteiken
2026-09-30 12:30:56
(1 week ago)
rocinante.teiken.net:80 178.128.212.96:47726 - - [30/Sep/2026:08:30:49 -0400] "GET //.env HTTP/1.1" ...
show more
rocinante.teiken.net:80 178.128.212.96:47726 - - [30/Sep/2026:08:30:49 -0400] "GET //.env HTTP/1.1" 301 616 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36"
rocinante.teiken.net:443 178.128.212.96:43082 - - [30/Sep/2026:08:30:51 -0400] "GET /.env HTTP/1.1" 404 3413 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36"
rocinante.teiken.net:80 178.128.212.96:47728 - - [30/Sep/2026:08:30:51 -0400] "GET //.env.backup HTTP/1.1" 301 630 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36"
rocinante.teiken.net:443 178.128.212.96:43086 - - [30/Sep/2026:08:30:52 -0400] "GET /.env.backup HTTP/1.1" 404 3413 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKi
...
show less
Web App Attack
Anonymous
2026-09-30 04:04:41
(1 week ago)
(mod_security) mod_security triggered on hostname [redacted])
SQL Injection
Anonymous
2026-09-29 06:30:43
(1 week ago)
Bot detected scanning for vulnerable pages
Port Scan
๐ฉ๐ช
maxpower
2026-09-28 13:04:30
(1 week ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 178.128.212.96 (SG/Singapore/-): 1 in th ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 178.128.212.96 (SG/Singapore/-): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 178.128.212.96 - - [28/Sep/2026:15:04:25 +0200] "GET //.aws/credentials HTTP/1.1" 200 11994 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" "-" host=smart-app.cloud
show less
Port Scan
๐ซ๐ท
Mickmick21
2026-09-28 10:02:31
(1 week ago)
178.128.212.96 - - [28/Sep/2026:12:02:30 +0200] "GET //.env HTTP/1.1" 418 0 "-" "Mozilla/5.0 (Linux; ...
show more
178.128.212.96 - - [28/Sep/2026:12:02:30 +0200] "GET //.env HTTP/1.1" 418 0 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36"
...
show less
Port Scan
Web App Attack
๐ฉ๐ช
Dennis
2026-09-27 11:15:17
(1 week ago)
178.128.212.96 has been banned for triggering http-sensitive-files (5 events over 3.057986254s).
Brute-Force
Web App Attack
๐ฉ๐ช
Hary74656
2026-09-27 10:31:45
(1 week ago)
Fail2Ban on schani.hostmi.at: jail=apache-instablock, failures=1.
[client 178.128.212.96] [realclien ...
show more
Fail2Ban on schani.hostmi.at: jail=apache-instablock, failures=1.
[client 178.128.212.96] [realclient 178.128.212.96] [27/Sep/2026:12:31:45 +0200] [vhost schani.hostmi.at] 403 "GET /.env HTTP/1.1"
show less
Web App Attack
๐ซ๐ท
chrisj
2026-09-27 09:36:32
(1 week ago)
2026-09-27T09:36:32.147730+00:00 www.diamondaviators.net throttler[772]: Throttle IP 178.128.212.96 ...
show more
2026-09-27T09:36:32.147730+00:00 www.diamondaviators.net throttler[772]: Throttle IP 178.128.212.96 with 25 denials
...
show less
Bad Web Bot
๐ฉ๐ช
Hary74656
2026-09-27 08:57:37
(1 week ago)
Fail2Ban on postler.hostmi.at: jail=apache-instablock, failures=1.
[client 178.128.212.96] [realclie ...
show more
Fail2Ban on postler.hostmi.at: jail=apache-instablock, failures=1.
[client 178.128.212.96] [realclient 178.128.212.96] [27/Sep/2026:10:57:37 +0200] [vhost postler.hostmi.at] 403 "GET //.env HTTP/1.1"
show less
Web App Attack
๐ฆ๐บ
2000cn.com.au
2026-09-27 08:35:15
(1 week ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐ซ๐ฎ
23p02732
2026-09-27 06:00:35
(1 week ago)
Mailserver and mailaccount attacks
Brute-Force
Bad Web Bot
Exploited Host
Web App Attack
๐บ๐ธ
eber965
2026-09-26 18:47:39
(1 week ago)
[Sat Sep 26 15:47:36 2026] [authz_core:error] [pid 105585:tid 139872639637248] [client 178.128.212.9 ...
show more
[Sat Sep 26 15:47:36 2026] [authz_core:error] [pid 105585:tid 139872639637248] [client 178.128.212.96:59774] AH01630: client denied by server configuration: /var/www/html/.env
[Sat Sep 26 15:47:37 2026] [authz_core:error] [pid 105585:tid 139871700113152] [client 178.128.212.96:59780] AH01630: client denied by server configuration: /var/www/html/.env.backup
[Sat Sep 26 15:47:38 2026] [authz_core:error] [pid 105585:tid 139872622851840] [client 178.128.212.96:59792] AH01630: client denied by server configuration: /var/www/html/.env.bak
[Sat Sep 26 15:47:38 2026] [authz_core:error] [pid 105585:tid 139872874501888] [client 178.128.212.96:59800] AH01630: client denied by server configuration: /var/www/html/.env.config
[Sat Sep 26 15:47:39 2026] [authz_core:error] [pid 105585:tid 139872631244544] [client 178.128.212.96:59814] AH01630: client denied by server configuration: /var/www/html/.env.dev
...
show less
Brute-Force
๐ฒ๐พ
Rizzy
2026-09-26 17:06:25
(1 week ago)
Multiple WAF Violations
Brute-Force
Web App Attack