๐จ๐ญ
TheCoon
2026-07-23 22:15:01
(1 day ago)
Automated: Credential theft attempt - JSON bomb served
Web App Attack
Hacking
๐ฆ๐น
Renรฉ Hickersberger
2026-07-23 08:27:25
(2 days ago)
malicious bot detected: violations="hit-honeypot"; user_agent="ureq/2.12.1"
Web App Attack
Anonymous
2026-07-22 07:53:33
(3 days ago)
Suspicious or malicious traffic has been detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-11 19:22:53
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 185.169.252.170 (vmi2863520.contaboserver.net): ...
show more
(mod_security) mod_security (id:210492) triggered by 185.169.252.170 (vmi2863520.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 11 15:22:45.229616 2026] [security2:error] [pid 8715:tid 8715] [client 185.169.252.170:58608] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.k-h-w.com"] [uri "/.env"] [unique_id "alKYBUxO8wmwGaOh_jBEwgAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
4server
2026-07-05 15:46:24
(2 weeks ago)
[SunJul0517:46:21.8181182026][security2:error][pid3513973:tid3514248][client185.169.252.170:0]ModSec ...
show more
[SunJul0517:46:21.8181182026][security2:error][pid3513973:tid3514248][client185.169.252.170:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".env\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"365\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"autodiscover.carolin-mizio.ch\"][uri\"/.env\"][unique_id\"akp8TYdXyxpDOq2YJ-EIYwAAARA\"]
show less
Hacking
Web App Attack
Anonymous
2026-07-05 02:53:00
(2 weeks ago)
Multiple web server 400 error codes from same source ip
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-07-02 01:30:42
(3 weeks ago)
Try to access /.git/config
Web App Attack
Anonymous
2026-07-01 04:40:48
(3 weeks ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
๐ฌ๐ง
sc user
2026-06-22 04:52:13
(1 month ago)
Fail2Ban nginx: repeated suspicious HTTP requests consistent with automated probing, scanning or bad ...
show more
Fail2Ban nginx: repeated suspicious HTTP requests consistent with automated probing, scanning or bad bot behaviour. Technical log details and local server identifiers intentionally omitted for privacy.
show less
Bad Web Bot
Web App Attack
Port Scan
Anonymous
2026-06-21 07:32:46
(1 month ago)
185.169.252.170 - - [21/Jun/2026:07:32:45 +0000] "HEAD /.aws/credentials HTTP/1.1" 404 0 "-" "Mozill ...
show more
185.169.252.170 - - [21/Jun/2026:07:32:45 +0000] "HEAD /.aws/credentials HTTP/1.1" 404 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14_5) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.4 Safari/605.1.15"
185.169.252.170 - - [21/Jun/2026:07:32:45 +0000] "HEAD /.env HTTP/1.1" 404 0 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ChatGPT-User/1.0; +https://openai.com/bot)"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-21 02:39:44
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 185.169.252.170 (vmi2863520.contaboserver.net): ...
show more
(mod_security) mod_security (id:210492) triggered by 185.169.252.170 (vmi2863520.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 20 22:39:40.770176 2026] [security2:error] [pid 22790:tid 22859] [client 185.169.252.170:47754] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.cloud.giere.org"] [uri "/.env.local"] [unique_id "ajdO7Cmsq5NSxKDKXmftyAAAAYk"], referer: https://www.google.com/search?q=www.cloud.giere.org
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-21 01:29:48
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 185.169.252.170 (vmi2863520.contaboserver.net): ...
show more
(mod_security) mod_security (id:210492) triggered by 185.169.252.170 (vmi2863520.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 20 21:29:42.055240 2026] [security2:error] [pid 25551:tid 25602] [client 185.169.252.170:47928] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.cas.bestofthis.com"] [uri "/.env.local"] [unique_id "ajc-ht5zhS1f7TPkUCKyyAAAAVM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฑ๐น
NotACaptcha
2026-06-20 21:40:45
(1 month ago)
webserver:443 [21/Jun/2026] "GET /client_secret.json HTTP/1.1" 404 5716 "https://www.google.com/sea ...
show more
webserver:443 [21/Jun/2026] "GET /client_secret.json HTTP/1.1" 404 5716 "https://www.google.com/search?q=www.ashunledevles.eu.org" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14_5) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.4 Safari/605.1.15"
webserver:443 [21/Jun/2026] "GET /bootstrap/cache/config.php HTTP/1.1" 404 5716 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
webserver:443 [21/Jun/2026] "GET /wp-config.php HTTP/1.1" 404 5716 "-" "Mozilla/5.0 (Linux; Android 14; Pixel 8) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/135.0.6422.113 Mobile Safari/537.36"
webserver:443 [21/Jun/2026] "GET /.vscode/settings.json HTTP/1.1" 404 5716 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/135.0.0.0 Safari/537.36"
webserver:443 [21/Jun/2026] "GET /.pgpass HTTP/1.1" 404 5716 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:137.0) Gecko/20100101 Firefox/137.0"
webserver:443 [21/Jun/2026] "GET /secrets.yaml HTT...
show less
Web App Attack
Anonymous
2026-06-20 14:24:11
(1 month ago)
(caddyscan) Scanner path probe from 185.169.252.170 (GB/United Kingdom/vmi2863520.contaboserver.net) ...
show more
(caddyscan) Scanner path probe from 185.169.252.170 (GB/United Kingdom/vmi2863520.contaboserver.net): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 185.169.252.170 - - [20/Jun/2026:14:24:09 +0000] "GET /.env.old HTTP/1.1"
[REDACTED] 200 2627 185.169.252.170 - - [20/Jun/2026:14:24:09 +0000] "GET /.vscode/settings.json HTTP/1.1"
[REDACTED] 200 2627 185.169.252.170 - - [20/Jun/2026:14:24:09 +0000] "GET /.aws/credentials HTTP/1.1"
[REDACTED] 200 2627 185.169.252.170 - - [20/Jun/2026:14:24:09 +0000] "GET /.env.local HTTP/1.1"
[REDACTED] 200 2627 185.169.252.170 - - [20/Jun/2026:14:24:09 +0000] "GET /.env.dist HTTP/1.1"
show less
Port Scan
๐ซ๐ท
samji10
2026-06-20 01:53:47
(1 month ago)
Sprint Log Parser automatically flagged security threats: Path Scanning. Specific actions detected: ...
show more
Sprint Log Parser automatically flagged security threats: Path Scanning. Specific actions detected: Environment file access attempt at: /.env; Generic PHP config scan at: /wp-config.php; Environment file access attempt at: /.env.backup; Git repository structure scan at: /.git/HEAD; Git repository structure scan at: /.git/config; Environment file access attempt at: /.env.local; Environment file access attempt at: /.env.production; Generic PHP config scan at: /wp-config.php.bak; Generic PHP config scan at: /bootstrap/cache/config.php; AWS credentials scan at: /.aws/credentials; Environment file access attempt at: /.env.old; Environment file access attempt at: /.env.dist.
show less
Bad Web Bot