π¨π¦
Sakusen
2026-10-07 05:37:58
(17 hours ago)
Automated web attack: 3 reqs, 1 paths probed; probed: 1 .env
Hacking
Web App Attack
π«π·
arsonist
2026-10-07 05:14:26
(18 hours ago)
[fail2ban]
2026-10-07T05:14:25.277052+00:00 arson caddy[1712]: {"level":"info","ts":1791350065.27700 ...
show more
[fail2ban]
2026-10-07T05:14:25.277052+00:00 arson caddy[1712]: {"level":"info","ts":1791350065.2770002,"logger":"http.log.access.default","msg":"handled request","request":{"remote_ip":"194.33.47.69","remote_port":"54009","client_ip":"194.33.47.69","proto":"HTTP/1.1","method":"GET","host":"mc.possum.city","uri":"/.env","headers":{"Accept-Language":["en-US,en;q=0.9"],"Accept-Encoding":["gzip, deflate, br"],"Cache-Control":["max-age=0"],"Sec-Fetch-Mode":["navigate"],"Sec-Fetch-User":["?1"],"Sec-Ch-Ua":["\"Google Chrome\";v=\"143\", \"Chromium\";v=\"143\", \"Not_A Brand\";v=\"24\""],"Sec-Fetch-Dest":["document"],"Sec-Fetch-Site":["none"],"Sec-Ch-Ua-Mobile":["?0"],"User-Agent":["Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/143.0.0.0 Safari/537.36"],"Sec-Ch-Ua-Platform":["\"Windows\""],"Upgrade-Insecure-Requests":["1"],"Accept":["text/html,application/xhtml+xml
...
show less
Bad Web Bot
π¦πΊ
Bay13
2026-10-07 04:43:08
(18 hours ago)
CrowdSec:custom/http-sensitive-files
Web App Attack
π©πͺ
FeG Deutschland
2026-10-07 04:23:15
(19 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
Anonymous
2026-10-07 04:10:59
(19 hours ago)
194.33.47.69 - - [07/Oct/2026:12:10:59 +0800] "GET /.env HTTP/1.1" 301 241 "-" "Mozilla/5.0 (Windows ...
show more
194.33.47.69 - - [07/Oct/2026:12:10:59 +0800] "GET /.env HTTP/1.1" 301 241 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/143.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
π¨π¦
DRI
2026-10-07 01:00:22
(22 hours ago)
Web attack/Malicious activity detected
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-06 22:12:39
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 194.33.47.69 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 194.33.47.69 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 18:12:33.341710 2026] [security2:error] [pid 22195:tid 22195] [client 194.33.47.69:39121] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.recetabook.com"] [uri "/.env"] [unique_id "asVyUUgic89BFi3roaiObgAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
big-cloud.nl
2026-10-06 21:26:14
(1 day ago)
Try to access /.env
Web App Attack
π―π΅
VXG-NET
2026-10-06 21:07:57
(1 day ago)
port=80, indicator_type=info-leak
Hacking
πͺπΈ
masterguru
2026-10-06 21:05:17
(1 day ago)
Inbound Anomaly Score Exceeded (Total Score: 5). Operator GE matched 5 at TX:anomaly_score. (949110- ...
show more
Inbound Anomaly Score Exceeded (Total Score: 5). Operator GE matched 5 at TX:anomaly_score. (949110-122)
show less
Hacking
π«π·
dynamix
2026-10-06 20:55:05
(1 day ago)
Multiple WAF Violations
Web App Attack
π¦πΊ
2000cn.com.au
2026-10-06 20:35:56
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
π³π±
Alt255
2026-10-06 20:20:08
(1 day ago)
[cb-15al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[cb-15al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 194.33.47.69 - - [06/Oct/2026:22:19:47 +0200] "GET /.env HTTP/1.1" 404 131713 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/143.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-06 20:18:41
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 194.33.47.69 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 194.33.47.69 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 16:18:38.702153 2026] [security2:error] [pid 2742138:tid 2742235] [client 194.33.47.69:65097] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.datuinc.com"] [uri "/.env"] [unique_id "asVXnm2oJd_Ig-7VmPzE5AAAAcs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
masterguru
2026-10-06 18:45:23
(1 day ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-196)
Hacking
Web App Attack