๐ฉ๐ช
FeG Deutschland
2026-06-01 11:33:45
(2 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 12
Exploited Host
Web App Attack
๐ฉ๐ช
raph
2026-06-01 10:48:10
(2 days ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-06-01 10:29:37
(2 days ago)
207.241.173.205 - - [01/Jun/2026:13:29:36 +0300] "GET /app/.env HTTP/1.1" 404 3275 "-" "Mozilla/5.0 ...
show more
207.241.173.205 - - [01/Jun/2026:13:29:36 +0300] "GET /app/.env HTTP/1.1" 404 3275 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Safari/537.36"
...
show less
Web App Attack
๐ณ๐ด
Bots.go.to.hell
2026-06-01 09:42:30
(2 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐ฌ๐ง
prime_fusion_ld
2026-06-01 09:04:15
(3 days ago)
Blocked by CSF/LFD on vps.primefusion.co.uk. Trigger: 1 Ports: *
Port Scan
๐ซ๐ท
IRISIO
2026-06-01 08:23:20
(3 days ago)
scans/SQL injection/spam posts : 139 queries
Web App Attack
SQL Injection
๐บ๐ฆ
URAN Publishing Service
2026-06-01 08:06:30
(3 days ago)
207.241.173.205 - - [01/Jun/2026:11:06:15 +0300] "GET /src/.env HTTP/1.1" 404 2823 "-" "Mozilla/5.0 ...
show more
207.241.173.205 - - [01/Jun/2026:11:06:15 +0300] "GET /src/.env HTTP/1.1" 404 2823 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Safari/537.36"
207.241.173.205 - - [01/Jun/2026:11:06:15 +0300] "GET /public/.env HTTP/1.1" 404 2823 "-" "Mozilla/5.0 (X11; Linux x86_64; rv:150.0) Gecko/20100101 Firefox/150.0"
...
show less
Web App Attack
Anonymous
2026-06-01 08:01:35
(3 days ago)
Blocked: Reason='Suspicious traffic score=60 (review-based detection)'; Requests=75
Hacking
๐ฌ๐ง
Mendip_Defender
2026-06-01 07:55:27
(3 days ago)
[01/Jun/2026:08:55:25.199887 +0100] ah067cU1v5FdXkZLfgNYrQAAAFM 207.241.173.205 56580 188.246.206.60 ...
show more
[01/Jun/2026:08:55:25.199887 +0100] ah067cU1v5FdXkZLfgNYrQAAAFM 207.241.173.205 56580 188.246.206.60 7080
[01/Jun/2026:08:55:25.343872 +0100] ah067cU1v5FdXkZLfgNYrgAAAE0 207.241.173.205 56588 188.246.206.60 7080
...
show less
Brute-Force
Anonymous
2026-06-01 06:35:07
(3 days ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
๐ฉ๐ช
SwinT
2026-06-01 06:00:08
(3 days ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
๐ซ๐ท
dwmp
2026-06-01 04:44:09
(3 days ago)
[01/Jun/2026:06:44:08.862756 +0200] ah0OGPAZwX8qfXibYQ4OTwAAAEs 207.241.173.205 50934 38.242.227.117 ...
show more
[01/Jun/2026:06:44:08.862756 +0200] ah0OGPAZwX8qfXibYQ4OTwAAAEs 207.241.173.205 50934 38.242.227.117 7080
[01/Jun/2026:06:44:08.882338 +0200] ah0OGPAZwX8qfXibYQ4OWwAAAE0 207.241.173.205 50970 38.242.227.117 7080
[01/Jun/2026:06:44:08.892022 +0200] ah0OGPAZwX8qfXibYQ4OWQAAAFE 207.241.173.205 50968 38.242.227.117 7080
...
show less
Brute-Force
SSH
๐บ๐ธ
lavnet.net
2026-06-01 03:43:03
(3 days ago)
207.241.173.205 - - [01/Jun/2026:03:43:02 +0000] "GET /.env.production HTTP/1.1" 404 2933 "-" "Mozil ...
show more
207.241.173.205 - - [01/Jun/2026:03:43:02 +0000] "GET /.env.production HTTP/1.1" 404 2933 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/146.0.0.0 Safari/537.36"
207.241.173.205 - - [01/Jun/2026:03:43:02 +0000] "GET /.env.local HTTP/1.1" 404 2932 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Safari/537.36"
207.241.173.205 - - [01/Jun/2026:03:43:02 +0000] "GET /gcp-service-account.json/ HTTP/1.1" 404 366 "https://ghost.lavweb.com/gcp-service-account.json" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:149.0) Gecko/20100101 Firefox/149.0"
207.241.173.205 - - [01/Jun/2026:03:43:03 +0000] "GET /app/credentials.json/ HTTP/1.1" 404 366 "https://ghost.lavweb.com/app/credentials.json" "Mozilla/5.0 (X11; Linux x86_64; rv:149.0) Gecko/20100101 Firefox/149.0"
207.241.173.205 - - [01/Jun/2026:03:43:03 +0000] "GET /backend/.env/ HTTP/1.1" 404 932 "https://ghost.lavweb.com/backend/.env" "Mozilla/5.0 (Windows
...
show less
Brute-Force
๐ง๐ช
voormedia
2026-06-01 03:09:07
(3 days ago)
Accessed trap at '/.env'
Web App Attack
Anonymous
2026-06-01 02:20:28
(3 days ago)
207.241.173.205 - - [01/Jun/2026:04:20:25 +0200] "GET /firebase-adminsdk.json HTTP/1.1" 404 437 "-" ...
show more
207.241.173.205 - - [01/Jun/2026:04:20:25 +0200] "GET /firebase-adminsdk.json HTTP/1.1" 404 437 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:150.0) Gecko/20100101 Firefox/150.0"
207.241.173.205 - - [01/Jun/2026:04:20:25 +0200] "GET /firebase-adminsdk.json HTTP/1.1" 404 243 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:150.0) Gecko/20100101 Firefox/150.0"
207.241.173.205 - - [01/Jun/2026:04:20:25 +0200] "GET /firebase.json HTTP/1.1" 404 437 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36"
207.241.173.205 - - [01/Jun/2026:04:20:25 +0200] "GET /firebase.json HTTP/1.1" 404 243 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36"
207.241.173.205 - - [01/Jun/2026:04:20:25 +0200] "GET /config/credentials.json HTTP/1.1" 404 437 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Safari/537.36"
2
...
show less
Bad Web Bot
Web App Attack