๐ฒ๐พ
Rizzy
2026-06-24 17:07:02
(4 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐ณ๐ฑ
debestelapp
2026-06-24 15:55:04
(5 hours ago)
Web App Attack
๐ฎ๐น
Inartis
2026-06-24 15:14:15
(6 hours ago)
208.84.100.136 - - [24/Jun/2026:17:14:12 +0200] "GET /.env HTTP/1.1" 200 51374 "-" "Mozilla/5.0 (Mac ...
show more
208.84.100.136 - - [24/Jun/2026:17:14:12 +0200] "GET /.env HTTP/1.1" 200 51374 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.3 Safari/605.1.15"
208.84.100.136 - - [24/Jun/2026:17:14:15 +0200] "GET /.env.local HTTP/1.1" 200 56498 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Safari/537.36"
208.84.100.136 - - [24/Jun/2026:17:14:15 +0200] "GET /.env.bak HTTP/1.1" 200 56498 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Safari/537.36"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Any Authorised User
2026-06-24 13:51:00
(7 hours ago)
Web App Attack
๐ฑ๐ป
garmtech.com
2026-06-24 08:24:00
(13 hours ago)
Attempted access to sensitive endpoint (/.env.development) detected. Automated scan or unauthorized ...
show more
Attempted access to sensitive endpoint (/.env.development) detected. Automated scan or unauthorized probing.
show less
Web App Attack
Anonymous
2026-06-24 02:06:04
(19 hours ago)
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: US, Attack patterns: Word ...
show more
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: US, Attack patterns: WordPress scanning, Backup file probing, Cloud secrets probing
show less
Bad Web Bot
Web App Attack
๐ธ๐ช
SkyDancer
2026-06-23 18:52:46
(1 day ago)
Multiple intrusion attempts via http/https on known vulnerable url offsets. Attack automatically blo ...
show more
Multiple intrusion attempts via http/https on known vulnerable url offsets. Attack automatically blocked by SkyDancer Ai(web-X).
show less
Hacking
Brute-Force
๐บ๐ฆ
URAN Publishing Service
2026-06-23 18:46:39
(1 day ago)
208.84.100.136 - - [23/Jun/2026:21:46:31 +0300] "GET /wp-content/debug.log HTTP/1.1" 404 708 "-" "Mo ...
show more
208.84.100.136 - - [23/Jun/2026:21:46:31 +0300] "GET /wp-content/debug.log HTTP/1.1" 404 708 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:150.0) Gecko/20100101 Firefox/150.0"
208.84.100.136 - - [23/Jun/2026:21:46:33 +0300] "GET /.env HTTP/1.1" 404 708 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Safari/537.36"
...
show less
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-06-23 17:48:55
(1 day ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 1247
Exploited Host
Web App Attack
๐ฌ๐ง
OptimusGO
2026-06-23 16:58:02
(1 day ago)
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Time ...
show more
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Timestamp: 2026-06-23 17:58:02 UTC
Log evidence:
208.84.100.136 - - [23/Jun/2026:17:58:00 +0100] "GET / HTTP/1.1" 301 162 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Safari/537.36 Edg/147.0.0.0"
06/23/2026-17:58:01.453778 [wDrop] [**] [1:7000500:1] FINSERV CRITICAL: Aggressive Port Scan [**] [Classification: Attempted Information Leak] [Priority: 2] {TCP} 208.84.100.136:59012 -> 185.127.18.66:443
06/23/2026-17:58:01.453778 [**] [1:9000060:2] AUTONOMOUS Long-term Reconnaissance [**] [Classification: (null)] [Priority: 2] {TCP} 208.84.100.136:59012 -> 185.127.18.66:443
show less
Port Scan
Brute-Force
๐บ๐ธ
Matthew Ping
2026-06-23 16:15:01
(1 day ago)
ModSecurity rule 949110 triggered on wp1. Web application attack blocked by CSF/LFD.
Web App Attack
Hacking
๐ฆ๐บ
rubixstudios
2026-06-23 12:06:03
(1 day ago)
Excessive HTTP requests consistent with automated attack behaviour detected by Imunify360
DDoS Attack
Brute-Force
Web App Attack
Anonymous
2026-06-23 11:51:43
(1 day ago)
208.84.100.136 - - [23/Jun/2026:13:51:26 +0200] "GET /api/.env HTTP/1.1" 403 5499 "-" "Mozilla/5.0 ( ...
show more
208.84.100.136 - - [23/Jun/2026:13:51:26 +0200] "GET /api/.env HTTP/1.1" 403 5499 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Safari/537.36 Edg/147.0.0.0"
208.84.100.136 - - [23/Jun/2026:13:51:26 +0200] "GET /.cursor/mcp.json HTTP/1.1" 404 5496 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/146.0.0.0 Safari/537.36"
208.84.100.136 - - [23/Jun/2026:13:51:26 +0200] "GET /service-account.json HTTP/1.1" 404 5496 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Safari/537.36 Edg/147.0.0.0"
208.84.100.136 - - [23/Jun/2026:13:51:26 +0200] "GET /backend/.env HTTP/1.1" 403 5499 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Safari/537.36 Edg/147.0.0.0"
208.84.100.136 - - [23/Jun/2026:13:51:26 +0200] "GET /.openclaw/openclaw.json HTTP/1.1" 404 5496 "-" "Mozilla/5.0 (Macinto
...
show less
DDoS Attack
๐บ๐ธ
TPI-Abuse
2026-06-23 10:48:04
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 208.84.100.136 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 208.84.100.136 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 23 06:47:56.246645 2026] [security2:error] [pid 17169:tid 17169] [client 208.84.100.136:24738] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.zeta-me.com"] [uri "/.env.production.copy"] [unique_id "ajpkXJTaMYWm-_i0UhQcjQAAAEk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-23 09:54:11
(1 day ago)
(caddyscan) Scanner path probe from 208.84.100.136 (US/United States/-): 5 in the last 3600 secs; Po ...
show more
(caddyscan) Scanner path probe from 208.84.100.136 (US/United States/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 208.84.100.136 - - [23/Jun/2026:09:54:07 +0000] "GET /.env.local HTTP/1.1"
[REDACTED] 200 2627 208.84.100.136 - - [23/Jun/2026:09:54:07 +0000] "GET /.env.production HTTP/1.1"
[REDACTED] 200 2627 208.84.100.136 - - [23/Jun/2026:09:54:07 +0000] "GET /.env.development HTTP/1.1"
[REDACTED] 200 2627 208.84.100.136 - - [23/Jun/2026:09:54:07 +0000] "GET /.env.backup HTTP/1.1"
[REDACTED] 200 2627 208.84.100.136 - - [23/Jun/2026:09:54:07 +0000] "GET /.env.bak HTTP/1.1"
show less
Port Scan