๐ซ๐ท
sthoyer.de
2026-07-30 07:11:06
(2 hours ago)
207.175.30.2 - - [30/Jul/2026:09:11:05 +0200] "GET /assets/manifest.json HTTP/2" 302 495 "-" "Mozill ...
show more
207.175.30.2 - - [30/Jul/2026:09:11:05 +0200] "GET /assets/manifest.json HTTP/2" 302 495 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Safari/537.36"
207.175.30.2 - - [30/Jul/2026:09:11:05 +0200] "GET /dashboard HTTP/2" 302 495 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Safari/537.36"
207.175.30.2 - - [30/Jul/2026:09:11:05 +0200] "GET /static/manifest.json HTTP/2" 302 495 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Safari/537.36"
...
show less
Web App Attack
๐ฆ๐บ
screwlooseit.com.au
2026-07-30 06:06:07
(3 hours ago)
Blocked by CSF 13 firewall - Rule: config-dotfile
US/United States/2.30.175.207.bc.googleusercontent ...
show more
Blocked by CSF 13 firewall - Rule: config-dotfile
US/United States/2.30.175.207.bc.googleusercontent.com
show less
Web App Attack
๐ณ๐ฑ
maxxsense
2026-07-30 05:04:31
(5 hours ago)
207.175.30.2 (BE/Belgium/2.30.175.207.bc.googleusercontent.com), more than 10 Apache 403 hits
Hacking
๐ณ๐ฑ
Site.eu
2026-07-30 03:35:41
(6 hours ago)
Excessive multi-domain requests
Brute-Force
Anonymous
2026-07-30 03:10:04
(6 hours ago)
Bot / scanning and/or hacking attempts: GET /.env.php.bak HTTP/2.0, GET /configuration.php.bak HTTP/ ...
show more
Bot / scanning and/or hacking attempts: GET /.env.php.bak HTTP/2.0, GET /configuration.php.bak HTTP/2.0, GET /config.php.bak HTTP/2.0, GET /public/.env HTTP/2.0, GET /staging/.env HTTP/2.0, GET /.env.production.bak HTTP/2.0, GET /aws-exports.js HTTP/2.0, GET /.env.prod.bak HTTP/2.0, GET /core/.env HTTP/2.0, GET /config/.env.php HTTP/2.0, GET /.env.docker HTTP/2.0, GET /web/.env HTTP/2.0, GET /values.yaml HTTP/2.0, GET /_debugbar/open HTTP/2.0, GET /trace.axd HTTP/2.0, GET /metrics HTTP/2.0, GET /@fs/root/.env?raw?? HTTP/2.0, GET /.env.dev HTTP/2.0, GET /amplifyconfiguration.json HTTP/2.0, GET /server-status HTTP/2.0
show less
Hacking
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-07-30 01:00:51
(9 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐ต๐ฑ
webadmin
2026-07-30 00:15:04
(9 hours ago)
2026-07-30T02:15:03.956304+02:00 tytan mobile-sai-api[4129]: [error] client: 207.175.30.2 server: mo ...
show more
2026-07-30T02:15:03.956304+02:00 tytan mobile-sai-api[4129]: [error] client: 207.175.30.2 server: mobile.sai.pl, request: "GET", url: http://mobile.sai.pl/z9x8c7v6b5-debug-trigger-mobile.sai.pl [404]: Not Found
2026-07-30T02:15:03.956304+02:00 tytan mobile-sai-api[4129]: [error] client: 207.175.30.2 server: mobile.sai.pl, request: "GET", url: http://mobile.sai.pl/config.js [404]: Not Found
2026-07-30T02:15:03.956304+02:00 tytan mobile-sai-api[4129]: [error] client: 207.175.30.2 server: mobile.sai.pl, request: "GET", url: http://mobile.sai.pl/env.js [404]: Not Found
2026-07-30T02:15:03.956304+02:00 tytan mobile-sai-api[4129]: [error] client: 207.175.30.2 server: mobile.sai.pl, request: "GET", url: http://mobile.sai.pl/__/firebase/init.json [404]: Not Found
show less
Web App Attack
๐ณ๐ฑ
ConsulHosting
2026-07-30 00:02:58
(10 hours ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack
๐ช๐ธ
alferez
2026-07-29 23:47:19
(10 hours ago)
Searching .(env|sql|zip|tar|rar) files
Hacking
Exploited Host
Web App Attack
๐ซ๐ท
sthoyer.de
2026-07-29 23:18:01
(10 hours ago)
207.175.30.2 - - [30/Jul/2026:01:17:59 +0200] "GET /.git/config HTTP/2" 302 495 "-" "Mozilla/5.0 App ...
show more
207.175.30.2 - - [30/Jul/2026:01:17:59 +0200] "GET /.git/config HTTP/2" 302 495 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; Claude-User/1.0; +mailto:[email protected] "
207.175.30.2 - - [30/Jul/2026:01:17:59 +0200] "GET /.aws/config HTTP/2" 302 495 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; Claude-User/1.0; +mailto:[email protected] "
207.175.30.2 - - [30/Jul/2026:01:17:59 +0200] "GET /dashboard HTTP/2" 302 495 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Safari/537.36"
...
show less
Web App Attack
๐บ๐ธ
jormaster3k
2026-07-29 23:15:23
(10 hours ago)
Attack against Apache (too many 404s)
Web App Attack
๐ณ๐ด
jad-abuse
2026-07-29 22:52:42
(11 hours ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_expos ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_exposure, aws_creds, env_probe, source_backup, credential_file, dotfile_probe, ssh_keys, ai_secrets. Observed by 1 sensor(s); 242 hits.
show less
Hacking
Web App Attack
๐ซ๐ท
Little Iguana
2026-07-29 22:43:10
(11 hours ago)
Attempt to hack Wordpress Login, XMLRPC or other login
Hacking
๐ซ๐ท
Octopuce
2026-07-29 22:06:37
(11 hours ago)
Aggressive web search of vulnerable pages: /.env.local /.env /api/.env /admin/.env /.github/.env .. ...
show more
Aggressive web search of vulnerable pages: /.env.local /.env /api/.env /admin/.env /.github/.env ...
show less
Web App Attack
๐ฉ๐ช
Guardian
2026-07-29 21:50:43
(12 hours ago)
Multi abuses [2]: Unauthorized connection attempt / Port scanning (x47), Unauthorized attempt to ret ...
show more
Multi abuses [2]: Unauthorized connection attempt / Port scanning (x47), Unauthorized attempt to retrieve configuration file (x12)
207.175.30.2 [29/Jul/2026:23:50:42 +0200] "GET / HTTP/1.1"
207.175.30.2 [29/Jul/2026:23:50:42 +0200] "GET /.git/config HTTP/1.1"
207.175.30.2 [29/Jul/2026:23:50:42 +0200] "GET /.aws/config HTTP/1.1"
207.175.30.2 [29/Jul/2026:23:50:42 +0200] "GET /.git/HEAD HTTP/1.1"
207.175.30.2 [29/Jul/2026:23:50:42 +0200] "GET /.aws/credentials HTTP/1.1"
207.175.30.2 [29/Jul/2026:23:50:42 +0200] "GET /z9x8c7v6b5-debug-trigger-backoffice.******.*** HTTP/1.1"
207.175.30.2 [29/Jul/2026:23:50:42 +0200] "GET /admin HTTP/1.1"
207.175.30.2 [29/Jul/2026:23:50:42 +0200] "GET /login HTTP/1.1"
207.175.30.2 [29/Jul/2026:23:50:42 +0200] "GET /dashboard HTTP/1.1"
207.175.30.2 [29/Jul/2026:23:50:42 +0200] "GET /app HTTP/1.1"
207.175.30.2 [29/Jul/2026:23:50:42 +0200] "GET /console HTTP/1.1"
207.175.30.2 [29/Jul/2026:23:50:42 +0200] "GET /settings HTTP/1.1"
207.175.30.2 [29/Jul/2026:23:50:42 +0200] "GET /rclone
show less
Port Scan
Web App Attack