๐ซ๐ท
Catalin Negru
2026-08-21 14:08:26
(2 hours ago)
2026-08-15 17:30:09,083 fail2ban.actions [722]: NOTICE [apache-404] Ban 20.203.144.231
2026- ...
show more
2026-08-15 17:30:09,083 fail2ban.actions [722]: NOTICE [apache-404] Ban 20.203.144.231
2026-08-15 17:30:09,137 fail2ban.actions [722]: NOTICE [laravel-env] Ban 20.203.144.231
2026-08-15 17:30:09,283 fail2ban.actions [722]: NOTICE [apache-scan] Ban 20.203.144.231
2026-08-15 17:30:09,284 fail2ban.actions [722]: NOTICE [laravel-auth] Ban 20.203.144.231
2026-08-15 17:30:09,285 fail2ban.actions [722]: NOTICE [web-scanner] Ban 20.203.144.231
...
show less
Brute-Force
Web App Attack
๐ซ๐ท
hxsain
2026-08-21 11:20:45
(5 hours ago)
Automated report from CrowdSec: probing for exposed configuration and credential files. 5 events obs ...
show more
Automated report from CrowdSec: probing for exposed configuration and credential files. 5 events observed.
show less
Hacking
Web App Attack
๐ฉ๐ช
maxpower
2026-08-21 10:14:12
(6 hours ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 20.203.144.231 (CH/Switzerland/-): 1 in ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 20.203.144.231 (CH/Switzerland/-): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 20.203.144.231 - - [21/Aug/2026:12:14:08 +0200] "GET /home/ec2-user/.aws/credentials/.env HTTP/1.1" 301 162 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36" "-" host=leo.spacehosting.ovh
show less
Port Scan
๐ซ๐ท
Vaction
2026-08-21 09:32:06
(7 hours ago)
20.203.144.231 - - [21/Aug/2026:11:32:06 +0200] "GET /.env HTTP/1.1" 404 400 "-" "Mozilla/5.0 (Macin ...
show more
20.203.144.231 - - [21/Aug/2026:11:32:06 +0200] "GET /.env HTTP/1.1" 404 400 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36"
show less
Hacking
Bad Web Bot
Web App Attack
๐ฉ๐ช
maxpower
2026-08-21 08:56:12
(7 hours ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 20.203.144.231 (CH/Switzerland/-): 1 in ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 20.203.144.231 (CH/Switzerland/-): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 20.203.144.231 - - [21/Aug/2026:10:56:08 +0200] "GET /home/ec2-user/.aws/credentials/.env HTTP/1.1" 301 162 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36" "-" host=51.89.83.26
show less
Port Scan
๐ฉ๐ช
maxpower
2026-08-21 08:27:52
(8 hours ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 20.203.144.231 (CH/Switzerland/-): 1 in ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 20.203.144.231 (CH/Switzerland/-): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 20.203.144.231 - - [21/Aug/2026:10:27:47 +0200] "GET /home/ec2-user/.aws/credentials/.env HTTP/1.1" 301 162 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36" "-" host=indus.spacehosting.ovh
show less
Port Scan
๐ฉ๐ช
maxpower
2026-08-21 07:42:52
(9 hours ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 20.203.144.231 (CH/Switzerland/-): 1 in ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 20.203.144.231 (CH/Switzerland/-): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 20.203.144.231 - - [21/Aug/2026:09:42:51 +0200] "GET /home/ec2-user/.aws/credentials/.env HTTP/1.1" 301 162 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36" "-" host=aries.spacehosting.ovh
show less
Port Scan
๐ซ๐ท
GabrielJST
2026-08-21 07:00:21
(9 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 20.203.144.231 (CH/Switzerland/-): (CF ...
show more
(mod_security) mod_security triggered on hostname [redacted] 20.203.144.231 (CH/Switzerland/-): (CF_ENABLE)
show less
SQL Injection
๐ซ๐ท
Jager
2026-08-21 07:00:07
(9 hours ago)
Blocked by CrowdSec on my OVH VPS for scenario: crowdsecurity/http-sensitive-files
Brute-Force
Port Scan
Web App Attack
๐ซ๐ท
solution.it
2026-08-21 06:58:26
(9 hours ago)
[Fri Aug 21 08:58:25.600411 2026] [php7:error] [pid 3047349:tid 3047349] [client 20.203.144.231:5023 ...
show more
[Fri Aug 21 08:58:25.600411 2026] [php7:error] [pid 3047349:tid 3047349] [client 20.203.144.231:50231] script '/var/www/html/.env.php' not found or unable to stat
show less
Web App Attack
๐ฉ๐ช
maxpower
2026-08-21 06:56:37
(9 hours ago)
(PERMBLOCK) 20.203.144.231 (CH/Switzerland/-) has had more than 4 temp blocks in the last 86400 secs ...
show more
(PERMBLOCK) 20.203.144.231 (CH/Switzerland/-) has had more than 4 temp blocks in the last 86400 secs; Ports: *; Direction: inout; Trigger: LF_PERMBLOCK_COUNT; Logs:
show less
Port Scan
๐ต๐ฑ
Budyn
2026-08-21 06:11:39
(10 hours ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit Block. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: 51.83.237.XX | URI: /.env | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 | BODY: [Empty / GET Request]
show less
Hacking
Web App Attack
๐ฉ๐ช
EnthecSolutions
2026-08-21 06:01:27
(10 hours ago)
Detected by Enthec Solutions. | Attempts: 178 in 24h | Target port: 80
Web App Attack
๐ต๐ฑ
strefapi_com
2026-08-21 04:08:39
(12 hours ago)
Brute-force, web
...
Hacking
Brute-Force
Web App Attack
๐ฉ๐ช
maxpower
2026-08-21 04:08:26
(12 hours ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 20.203.144.231 (CH/Switzerland/-): 1 in ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 20.203.144.231 (CH/Switzerland/-): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 20.203.144.231 - - [21/Aug/2026:06:08:23 +0200] "GET /home/ec2-user/.aws/credentials/.env HTTP/1.1" 301 162 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36" "-" host=musca.spacehosting.ovh
show less
Port Scan