๐ฉ๐ช
raph
2026-09-01 10:22:36
(7 minutes ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack
๐ง๐ช
Saec
2026-09-01 09:38:01
(51 minutes ago)
Jarvis auto-ban: CF top attacker on saec.me (26 hits, BE)
Port Scan
Web App Attack
๐ซ๐ท
masterguru
2026-09-01 09:27:27
(1 hour ago)
URL file extension is restricted by policy. String match within ".ani/ .asa/ .asax/ .ascx/ .back/ .b ...
show more
URL file extension is restricted by policy. String match within ".ani/ .asa/ .asax/ .ascx/ .back/ .backup/ .bak/ .bck/ .bk/ .bkp/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .cnf/ .com/ .compositefont/ .config/ .conf/ .copy/ .crt/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dist/ .dll/ .dos/ .dpkg-dist/ .drv/ .gadget/ .hta/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .inf/ .ini/ .jks/ .jse/ .key/ .licx/ .lnk/ .log/ .mdb/ .msc/ .ocx/ .old/ .pass/ .pdb/ .pfx/ .pif/ .pem/ .pol/ .prf/ .printer/ .pwd/ .rdb/ .rdp/ .reg/ .resources/ .resx/ .sav/ .save/ .scr/ .sct/ .sh/ .shs/ .sql/ .sqlite/ .sqlite3/ .swap/ .swo/ .swp/ .sys/ .temp/ .tfstate/ .tlb/ .tmp/ .vb/ .vbe/ .vbs/ .vbproj/ .vsdisco/ .vxd/ .webinfo/ .ws/ .wsc/ .wsf/ .wsh/ .xsd/ .xsx/" at TX:extension. (920440-201)
show less
Hacking
๐ซ๐ท
LRNP
2026-09-01 09:18:57
(1 hour ago)
mirror2.urbanterror.info:443 207.175.187.89 - - [01/Sep/2026:09:18:57 +0000] "GET /.env HTTP/1.1" 40 ...
show more
mirror2.urbanterror.info:443 207.175.187.89 - - [01/Sep/2026:09:18:57 +0000] "GET /.env HTTP/1.1" 404 146 "-" "crusader-worker/1.0"
...
show less
Bad Web Bot
Web App Attack
๐ง๐ท
Peregrine
2026-09-01 07:57:12
(2 hours ago)
Fail2Ban Jail s2: tomcat-404 | Evidence: - 207.175.187.89 - - [01/Sep/2026:04:57:05 -0300] "GET /act ...
show more
Fail2Ban Jail s2: tomcat-404 | Evidence: - 207.175.187.89 - - [01/Sep/2026:04:57:05 -0300] "GET /actuator/env HTTP/1.1" 404 414
- 207.175.187.89 - - [01/Sep/2026:04:57:05 -0300] "GET /_ignition/health-check HTTP/1.1" 404 414
- 207.175.187.89 - - [01/Sep/2026:04:57:05 -0300] "GET /actuator/configprops HTTP/1.1" 404 414
- 207.175.187.89 - - [01/Sep/2026:04:57:05 -0300] "GET /storage/logs/laravel.log HTTP/1.1" 404 414
- 207.175.187.89 - - [01/Sep/2026:04:57:05 -0300] "GET /wp-config.php~ HTTP/1.1" 404 414
- 207.175.187.89 - - [01/Sep/2026:04:57:05 -0300] "GET /crusader-404-probe HTTP/1.1" 404 414
- 207.175.187.89 - - [01/Sep/2026:04:57:05 -0300] "GET /wp-config.php.swp HTTP/1.1" 404 414
- 207.175.187.89 - - [01/Sep/2026:04:57:05 -0300] "GET /env HTTP/1.1" 404 414
- 207.175.187.89 - - [01/Sep/2026:04:57:05 -0300] "GET /wp-config.php.bak HTTP/1.1" 404 414
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 07:52:38
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 207.175.187.89 (89.187.175.207.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 207.175.187.89 (89.187.175.207.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 03:52:35.153305 2026] [security2:error] [pid 28146:tid 28146] [client 207.175.187.89:57024] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.mauriciagandara.com"] [uri "/.env.backup"] [unique_id "apaEQ_IS-cvb-vAzuK6a8wAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
polycoda
2026-09-01 07:46:16
(2 hours ago)
AutoBlock: ๐ฏ Vulnerability Scanner (Non Decay-Based) - โ๏ธ Configuration File Access (Non Decay-Based ...
show more
AutoBlock: ๐ฏ Vulnerability Scanner (Non Decay-Based) - โ๏ธ Configuration File Access (Non Decay-Based) - โ Excessive 40X Errors (Decay-Based)
show less
Hacking
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-09-01 07:28:58
(3 hours ago)
URL file extension is restricted by policy. String match within ".ani/ .asa/ .asax/ .ascx/ .back/ .b ...
show more
URL file extension is restricted by policy. String match within ".ani/ .asa/ .asax/ .ascx/ .back/ .backup/ .bak/ .bck/ .bk/ .bkp/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .cnf/ .com/ .compositefont/ .config/ .conf/ .copy/ .crt/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dist/ .dll/ .dos/ .dpkg-dist/ .drv/ .gadget/ .hta/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .inf/ .ini/ .jks/ .jse/ .key/ .licx/ .lnk/ .log/ .mdb/ .msc/ .ocx/ .old/ .pass/ .pdb/ .pfx/ .pif/ .pem/ .pol/ .prf/ .printer/ .pwd/ .rdb/ .rdp/ .reg/ .resources/ .resx/ .sav/ .save/ .scr/ .sct/ .sh/ .shs/ .sql/ .sqlite/ .sqlite3/ .swap/ .swo/ .swp/ .sys/ .temp/ .tfstate/ .tlb/ .tmp/ .vb/ .vbe/ .vbs/ .vbproj/ .vsdisco/ .vxd/ .webinfo/ .ws/ .wsc/ .wsf/ .wsh/ .xsd/ .xsx/" at TX:extension. (920440-193)
show less
Hacking
๐ฉ๐ช
ger-stg-sifi1
2026-09-01 07:19:59
(3 hours ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
๐ต๐ฑ
Budyn
2026-09-01 06:56:45
(3 hours ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: 0bit.budyn.wtf | URI: /.env.save | UA: crusader-worker/1.0 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-09-01 06:32:32
(3 hours ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-196)
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 06:25:56
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 207.175.187.89 (89.187.175.207.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 207.175.187.89 (89.187.175.207.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 02:25:51.883453 2026] [security2:error] [pid 14479:tid 14479] [client 207.175.187.89:36500] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "stringsonfire.guitar-pedals-amp.com"] [uri "/.env.local"] [unique_id "apZv79_hwxfXodFBFx_EWgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 06:03:52
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 207.175.187.89 (89.187.175.207.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 207.175.187.89 (89.187.175.207.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 02:03:44.195833 2026] [security2:error] [pid 21821:tid 21821] [client 207.175.187.89:55288] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.goikopro.com"] [uri "/wp-config.php.swp"] [unique_id "apZqwK4LFbSSCO6ZeF4anwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ท๐บ
DZBOT
2026-09-01 05:24:31
(5 hours ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 05:07:13
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 207.175.187.89 (89.187.175.207.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 207.175.187.89 (89.187.175.207.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 01:07:05.451101 2026] [security2:error] [pid 4970:tid 4970] [client 207.175.187.89:56424] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.baystarpartners.com"] [uri "/.env.production"] [unique_id "apZdeWQl0gbqDGwvees1KgAAADA"]
show less
Brute-Force
Bad Web Bot
Web App Attack