๐จ๐ญ
zynex
2026-06-09 22:07:24
(8 hours ago)
URL Probing: /.env
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-06-09 22:02:10
(8 hours ago)
Auto-ban: >3000 req/min op 2026-06-09
Web App Attack
SSH
Hacking
๐บ๐ธ
eber965
2026-06-09 22:01:42
(8 hours ago)
[Tue Jun 09 18:01:33 2026] [authz_core:error] [pid 3286984:tid 140065493726976] [client 20.236.100.1 ...
show more
[Tue Jun 09 18:01:33 2026] [authz_core:error] [pid 3286984:tid 140065493726976] [client 20.236.100.10:18845] AH01630: client denied by server configuration: /var/www/html/.git
[Tue Jun 09 18:01:37 2026] [authz_core:error] [pid 3683847:tid 140065703413504] [client 20.236.100.10:18839] AH01630: client denied by server configuration: /var/www/html/.env.local
[Tue Jun 09 18:01:38 2026] [authz_core:error] [pid 3375060:tid 140065493726976] [client 20.236.100.10:17861] AH01630: client denied by server configuration: /var/www/html/.env.production
[Tue Jun 09 18:01:39 2026] [authz_core:error] [pid 3375060:tid 140065342723840] [client 20.236.100.10:18870] AH01630: client denied by server configuration: /var/www/html/.env.backup
[Tue Jun 09 18:01:41 2026] [authz_core:error] [pid 3286984:tid 140065476941568] [client 20.236.100.10:18825] AH01630: client denied by server configuration: /var/www/html/.env.save
...
show less
Brute-Force
๐บ๐ธ
helios.live
2026-06-09 21:56:33
(8 hours ago)
2026/06/09 21:56:27 [error] 3898613#3898613: *320957 access forbidden by rule, client: 20.236.100.10 ...
show more
2026/06/09 21:56:27 [error] 3898613#3898613: *320957 access forbidden by rule, client: 20.236.100.10, server: 163.123.204.218, request: "GET /.env HTTP/1.1", host: "163.123.204.218"
2026/06/09 21:56:29 [error] 3898613#3898613: *320960 access forbidden by rule, client: 20.236.100.10, server: 163.123.204.218, request: "GET /.env.local HTTP/1.1", host: "163.123.204.218"
2026/06/09 21:56:30 [error] 3898613#3898613: *320964 access forbidden by rule, client: 20.236.100.10, server: 163.123.204.218, request: "GET /.env.production HTTP/1.1", host: "163.123.204.218"
2026/06/09 21:56:32 [error] 3898613#3898613: *320967 access forbidden by rule, client: 20.236.100.10, server: 163.123.204.218, request: "GET /.env.backup HTTP/1.1", host: "163.123.204.218"
2026/06/09 21:56:33 [error] 3898613#3898613: *320970 access forbidden by rule, client: 20.236.100.10, server: 163.123.204.218, request: "GET /.env.save HTTP/1.1", host: "163.123.204.218"
...
show less
Web App Attack
๐บ๐ธ
jkhorvath.com
2026-06-09 21:05:04
(9 hours ago)
Request for URL /.git/HEAD
Phishing
Brute-Force
Web App Attack
๐บ๐ธ
cwytech
2026-06-09 20:44:22
(10 hours ago)
Fleet-wide ban from the Ghostfleet ๐ป. Triggered by scenario: cwy/tactical-rmm-lockdown-high.
Hacking
๐บ๐ธ
brantknudson.org
2026-06-09 20:15:44
(10 hours ago)
Request path 'GET /.git/HEAD HTTP/1.1'
Web App Attack
Hacking
๐ง๐ท
mateus.vicente
2026-06-09 19:44:37
(11 hours ago)
[2026-06-09T19:44:37Z] Requests to sensitive Apache endpoints and path traversal patterns. (db-srv)
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
theanalogmaker
2026-06-09 19:00:26
(11 hours ago)
CrowdSec: Symphony auto-ban: /___proxy_subdomain_whm/login/?login_only=1 (100.0% confidence) (720h b ...
show more
CrowdSec: Symphony auto-ban: /___proxy_subdomain_whm/login/?login_only=1 (100.0% confidence) (720h ban)
show less
Brute-Force
Web App Attack
Anonymous
2026-06-09 18:47:35
(12 hours ago)
Unauthorized access (tcp/443/https)
Port Scan
Web App Attack
๐บ๐ธ
NXTwoThou
2026-06-09 18:15:04
(12 hours ago)
/___proxy_subdomain_whm/login/%3Flogin_only=1
Web App Attack
๐บ๐ธ
LotPhantom
2026-06-09 18:01:04
(12 hours ago)
2026-06-09T18:01:04.173382+00:00 bridginggaps kernel: [UFW BLOCK] IN=eth0 OUT= MAC=2e:bc:64:1d:2c:e1 ...
show more
2026-06-09T18:01:04.173382+00:00 bridginggaps kernel: [UFW BLOCK] IN=eth0 OUT= MAC=2e:bc:64:1d:2c:e1:fe:00:00:00:01:01:08:00 SRC=20.236.100.10 DST=157.230.217.55 LEN=60 TOS=0x00 PREC=0x00 TTL=48 ID=2517 DF PROTO=TCP SPT=18752 DPT=2083 WINDOW=64240 RES=0x00 SYN URGP=0
2026-06-09T18:01:04.173866+00:00 bridginggaps kernel: [UFW BLOCK] IN=eth0 OUT= MAC=2e:bc:64:1d:2c:e1:fe:00:00:00:01:01:08:00 SRC=20.236.100.10 DST=157.230.217.55 LEN=60 TOS=0x00 PREC=0x00 TTL=48 ID=41685 DF PROTO=TCP SPT=19284 DPT=2087 WINDOW=64240 RES=0x00 SYN URGP=0
...
show less
Port Scan
Hacking
๐บ๐ธ
TPI-Abuse
2026-06-09 17:32:48
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 20.236.100.10 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 20.236.100.10 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 13:32:43.039969 2026] [security2:error] [pid 28175:tid 28175] [client 20.236.100.10:17660] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.204"] [uri "/.git/HEAD"] [unique_id "aihOOy7_m241L3WxD2FMaQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
antlac1
2026-06-09 17:00:59
(13 hours ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
Anonymous
2026-06-09 16:38:41
(14 hours ago)
Unauthorized connection attempt
Port Scan
Hacking
Exploited Host