🇮🇳
evicky2002
2026-08-18 07:13:36
(4 weeks ago)
Confirmed malicious by STILWaters CTI platform (score=95, sources=1)
Hacking
Brute-Force
SSH
🇺🇸
antlac1
2026-05-31 20:13:12
(3 months ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
🇳🇵
Nanak011
2026-05-31 17:40:10
(3 months ago)
Information Disclosure Attempt: A web client attempted to access the Git repository HEAD file, indic ...
show more
Information Disclosure Attempt: A web client attempted to access the Git repository HEAD file, indicating a search for exposed source code.
show less
Web App Attack
Hacking
🇮🇹
mgarofano80
2026-05-31 16:50:23
(3 months ago)
Brute-Force
Web App Attack
Anonymous
2026-05-31 10:57:07
(3 months ago)
RdpGuard detected brute-force attempt on HTTP
Brute-Force
Anonymous
2026-05-31 06:37:43
(3 months ago)
DNS Compromise
DDoS Attack
🇩🇪
manuelisus
2026-05-31 06:36:52
(3 months ago)
Honeypot HTTP: +10: honeypot_connection, +15: short_automated_session, +50: abuseipdb_score_high, +2 ...
show more
Honeypot HTTP: +10: honeypot_connection, +15: short_automated_session, +50: abuseipdb_score_high, +20: repeat_visitor
show less
Web App Attack
Hacking
🇩🇪
MBombeck
2026-05-31 06:36:45
(3 months ago)
Fail2Ban/traefik-botsearch on apps-01: banned after 5 failures
Web App Attack
🇩🇪
NxtGenIT
2026-05-31 06:36:02
(3 months ago)
Tanner Honeypot hit, Event Type: , HTTP Method: GET, User Agent: , URI: /.env.production
SSH
🇬🇧
Artelis
2026-05-31 06:08:54
(3 months ago)
209.59.154.232 - - [31/May/2026:06:08:53 +0000] "GET /.env HTTP/1.1" 301 162 "-" "Mozilla/5.0 (Macin ...
show more
209.59.154.232 - - [31/May/2026:06:08:53 +0000] "GET /.env HTTP/1.1" 301 162 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36"
...
show less
Web App Attack
🇩🇪
SCHAPPY
2026-05-31 05:18:37
(3 months ago)
Malicious activity from IP detected: crowdsecurity/http-sensitive-files.
Web App Attack
Hacking
🇩🇪
maxpower
2026-05-31 04:10:06
(3 months ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 209.59.154.232 (US/United States/-): 2 i ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 209.59.154.232 (US/United States/-): 2 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 209.59.154.232 - - [31/May/2026:06:09:58 +0200] "GET /wp-config.php.bak HTTP/1.1" 403 548 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/123.0.0.0 Safari/537.36" "-" host=51.77.95.119
209.59.154.232 - - [31/May/2026:06:09:58 +0200] "GET /.aws/credentials HTTP/1.1" 404 10391 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36 Edg/124.0.0.0" "-" host=51.77.95.119
show less
Port Scan
🇺🇸
i553041
2026-05-30 19:53:55
(3 months ago)
209.59.154.232 - - [30/May/2026:19:53:45 +0000] "GET /.git/HEAD HTTP/1.1" 404 118 "-" "Mozilla/5.0 ( ...
show more
209.59.154.232 - - [30/May/2026:19:53:45 +0000] "GET /.git/HEAD HTTP/1.1" 404 118 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:125.0) Gecko/20100101 Firefox/125.0"
209.59.154.232 - - [30/May/2026:19:53:45 +0000] "GET /.git/config HTTP/1.1" 404 181 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36"
209.59.154.232 - - [30/May/2026:19:53:46 +0000] "GET /.env HTTP/1.1" 404 118 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:125.0) Gecko/20100101 Firefox/125.0"
209.59.154.232 - - [30/May/2026:19:53:46 +0000] "GET /.env.local HTTP/1.1" 404 181 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14_4_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36"
209.59.154.232 - - [30/May/2026:19:53:46 +0000] "GET /.env.production HTTP/1.1" 404 118 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
209.59.154.232 - - [30/May/2026:19:53:46 +0000] "GET /.env.backup HTTP/1.1" 404 118 "-
...
show less
Brute-Force
SSH
🇫🇷
masterguru
2026-05-30 17:13:26
(3 months ago)
Host header is a numeric IP address. Pattern match "^ (920350-131)
Hacking
Bad Web Bot
🇦🇺
Terrier
2026-05-30 14:00:00
(3 months ago)
Blocked for HTTP vulnerability scanning (excessive 40x)
Web App Attack