πΏπ¦
conure
2026-07-23 12:11:12
(2 days ago)
csagent: score 20.5: secrets grab x2, 404 noise floor x2; 1 domain(s) in 0s
Web App Attack
πΊπ¦
URAN Publishing Service
2026-07-23 05:24:01
(2 days ago)
192.159.101.243 - - [23/Jul/2026:08:24:00 +0300] "GET /public/.env HTTP/1.1" 404 4649 "https://www.g ...
show more
192.159.101.243 - - [23/Jul/2026:08:24:00 +0300] "GET /public/.env HTTP/1.1" 404 4649 "https://www.google.com/" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 Chrome/122.0.0.0 Safari/537.36"
192.159.101.243 - - [23/Jul/2026:08:24:00 +0300] "GET /.env HTTP/1.1" 404 723 "https://www.google.com/" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 Chrome/123.0.0.0 Safari/537.36"
...
show less
Web App Attack
π¨π
backslash
2026-07-23 05:21:01
(2 days ago)
block ruleset WAF detection and high score on abuseIPDB 149EB1B42C242111FADBBC2EF8F90219570691E1
Bad Web Bot
Anonymous
2026-07-23 05:05:17
(2 days ago)
Blocked: Reason='Suspicious traffic score=80 (review-based detection)'; Requests=19
Hacking
π«π·
Octopuce
2026-07-23 05:04:58
(2 days ago)
Aggressive web search of vulnerable pages: /.env.local /.env /public/.env /storage/.env /api/.env . ...
show more
Aggressive web search of vulnerable pages: /.env.local /.env /public/.env /storage/.env /api/.env ...
show less
Web App Attack
πΊπΈ
rdpguard.com
2026-07-23 05:02:10
(2 days ago)
RdpGuard detected brute-force attempt on HTTP
Brute-Force
πΊπΈ
Lee Daniel
2026-07-23 05:00:10
(2 days ago)
192.159.101.243 - - [23/Jul/2026:01:00:09 -0400] "GET /keystore.json HTTP/1.1" 404 31604 "https://ww ...
show more
192.159.101.243 - - [23/Jul/2026:01:00:09 -0400] "GET /keystore.json HTTP/1.1" 404 31604 "https://www.google.com/" "curl/8.5.0"
192.159.101.243 - - [23/Jul/2026:01:00:09 -0400] "GET /secrets.json HTTP/1.1" 404 31604 "https://www.google.com/" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 Chrome/122.0.0.0 Safari/537.36"
192.159.101.243 - - [23/Jul/2026:01:00:09 -0400] "GET /private_keys.txt HTTP/1.1" 404 31604 "https://www.google.com/" "curl/8.5.0"
192.159.101.243 - - [23/Jul/2026:01:00:09 -0400] "GET /keys.json HTTP/1.1" 404 31604 "https://www.google.com/" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 Chrome/123.0.0.0 Safari/537.36"
192.159.101.243 - - [23/Jul/2026:01:00:09 -0400] "GET /id.json HTTP/1.1" 404 31604 "https://www.google.com/" "curl/8.5.0"
...
show less
DDoS Attack
Web Spam
Email Spam
Port Scan
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-23 04:54:49
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 192.159.101.243 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 192.159.101.243 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 00:54:46.602102 2026] [security2:error] [pid 2554078:tid 2554078] [client 192.159.101.243:22900] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "primacomm.com"] [uri "/.env.production"] [unique_id "amGelmoZxc9D1kG8l6EtlAAAAAg"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
XICTRON
2026-07-23 04:40:06
(2 days ago)
ModSecurity rule violation detected by Fail2Ban
Web App Attack
π«π·
_tom
2026-07-23 04:34:04
(2 days ago)
Automated report (2026-07-23T06:34:04+02:00). Caught probing for env file.
Hacking
Web App Attack
Anonymous
2026-07-23 04:31:02
(2 days ago)
Bot / scanning and/or hacking attempts: GET /seed.txt HTTP/1.1, GET /.env.production HTTP/1.1, GET / ...
show more
Bot / scanning and/or hacking attempts: GET /seed.txt HTTP/1.1, GET /.env.production HTTP/1.1, GET /.env.backup HTTP/1.1, GET /mnemonic.txt HTTP/1.1, GET /api/.env HTTP/1.1, GET /wallet.json HTTP/1.1
show less
Hacking
Web App Attack
Anonymous
2026-07-23 04:30:02
(2 days ago)
2026/07/23 06:30:01 [error] 118375#118375: *31494 access forbidden by rule, client: 192.159.101.243, ...
show more
2026/07/23 06:30:01 [error] 118375#118375: *31494 access forbidden by rule, client: 192.159.101.243, server: sahpa.co.za, request: "GET /.env.prod HTTP/1.1", host: "sahpa.co.za", referrer: "https://www.google.com/"
2026/07/23 06:30:01 [error] 118375#118375: *31497 access forbidden by rule, client: 192.159.101.243, server: sahpa.co.za, request: "GET /.env.local HTTP/1.1", host: "sahpa.co.za", referrer: "https://www.google.com/"
2026/07/23 06:30:01 [error] 118376#118376: *31495 access forbidden by rule, client: 192.159.101.243, server: sahpa.co.za, request: "GET /.env.backup HTTP/1.1", host: "sahpa.co.za", referrer: "https://www.google.com/"
...
show less
Hacking
Web App Attack
π©πͺ
LRob
2026-07-23 04:29:58
(2 days ago)
CrowdSec: crowdsecurity/http-sensitive-files | req: /.env.local | 5 distinct paths | UA: Mozilla/5.0 ...
show more
CrowdSec: crowdsecurity/http-sensitive-files | req: /.env.local | 5 distinct paths | UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 Chrome/123.0.0.0 Safari/537.36
show less
Hacking
π²πΎ
Rizzy
2026-07-23 04:28:06
(2 days ago)
Multiple WAF Violations
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-23 04:21:05
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 192.159.101.243 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 192.159.101.243 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 00:20:59.500298 2026] [security2:error] [pid 4073783:tid 4073783] [client 192.159.101.243:8842] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cycontechnology.com"] [uri "/.env.production"] [unique_id "amGWq-nl-yuXAi5s81HiGwAAABY"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack