๐ณ๐ฑ
JaRoNL
2026-09-11 15:47:00
(1 hour ago)
209.99.189.119 - - \[09/Sep/2026:00:00:01 +0200\] "GET /.aws/credentials HTTP/1.1" 404 7443 "-" "Moz ...
show more
209.99.189.119 - - \[09/Sep/2026:00:00:01 +0200\] "GET /.aws/credentials HTTP/1.1" 404 7443 "-" "Mozilla/5.0 \(Windows NT 10.0\; Win64\; x64\) AppleWebKit/537.36 \(KHTML, like Gecko\) Chrome/131.0.0.0 Safari/537.36"
209.99.189.119 - - \[09/Sep/2026:00:00:01 +0200\] "GET /.git/config HTTP/1.1" 404 7443 "-" "Mozilla/5.0 \(Windows NT 10.0\; Win64\; x64\) AppleWebKit/537.36 \(KHTML, like Gecko\) Chrome/131.0.0.0 Safari/537.36"
209.99.189.119 - - \[09/Sep/2026:00:00:01 +0200\] "GET /.env HTTP/1.1" 404 7443 "-" "Mozilla/5.0 \(Windows NT 10.0\; Win64\; x64\) AppleWebKit/537.36 \(KHTML, like Gecko\) Chrome/131.0.0.0 Safari/537.36"
209.99.189.119 - - \[09/Sep/2026:00:00:02 +0200\] "GET /.aws/credentials HTTP/1.1" 404 7443 "-" "Mozilla/5.0 \(Windows NT 10.0\; Win64\; x64\) AppleWebKit/537.36 \(KHTML, like Gecko\) Chrome/131.0.0.0 Safari/537.36"
209
...
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
doarg
2026-09-11 14:30:42
(2 hours ago)
[Fri Sep 11 16:30:41.707819 2026] [authz_core:error] [pid 577897] [client 209.99.189.119:47400] AH01 ...
show more
[Fri Sep 11 16:30:41.707819 2026] [authz_core:error] [pid 577897] [client 209.99.189.119:47400] AH01630: client denied by server configuration: /var/www/doarg.com/.git/config
[Fri Sep 11 16:30:41.835433 2026] [authz_core:error] [pid 577627] [client 209.99.189.119:47484] AH01630: client denied by server configuration: /var/www/doarg.com/.env
[Fri Sep 11 16:30:41.846171 2026] [authz_core:error] [pid 577636] [client 209.99.189.119:47414] AH01630: client denied by server configuration: /var/www/doarg.com/config.json
[Fri Sep 11 16:30:41.849735 2026] [authz_core:error] [pid 577629] [client 209.99.189.119:47416] AH01630: client denied by server configuration: /var/www/doarg.com/config.json
[Fri Sep 11 16:30:42.287544 2026] [authz_core:error] [pid 578121] [client 209.99.189.119:47460] AH01630: client denied by server configuration: /var/www/doarg.com/.git/config
...
show less
Brute-Force
๐ฌ๐ง
WebNiraj
2026-09-11 14:28:40
(2 hours ago)
(mod_security) mod_security (id:949110) triggered by 209.99.189.119 (US/United States/-): 5 in the l ...
show more
(mod_security) mod_security (id:949110) triggered by 209.99.189.119 (US/United States/-): 5 in the last 3600 secs [SIGMA]
show less
Brute-Force
Anonymous
2026-09-11 14:27:23
(2 hours ago)
๐จ Repeated automated attempts to access prohibited paths and exploit known web application vulnerabi ...
show more
๐จ Repeated automated attempts to access prohibited paths and exploit known web application vulnerabilities.
show less
Bad Web Bot
Web App Attack
๐ฌ๐ง
Aetherweb Ark
2026-09-11 14:16:18
(3 hours ago)
(mod_security) mod_security (id:949110) triggered by 209.99.189.119 (CH/Switzerland/-): N in the las ...
show more
(mod_security) mod_security (id:949110) triggered by 209.99.189.119 (CH/Switzerland/-): N in the last X secs
show less
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-09-11 13:53:20
(3 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-09-11 13:50:10
(3 hours ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
๐ต๐ฑ
Budyn
2026-09-11 13:25:52
(3 hours ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: auth.astropot.online | URI: /.env.production | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
๐จ๐ฆ
SoteriaCovenant
2026-09-11 13:06:01
(4 hours ago)
Automated probe: /config.json on Soteria Global infrastructure. No vulnerable software present.
Hacking
๐ง๐พ
lns.bz
2026-09-11 12:44:25
(4 hours ago)
.env scanning [BY]
Web App Attack
๐จ๐ญ
YF
2026-09-11 12:37:14
(4 hours ago)
Environment file probe
Web App Attack
๐ฒ๐พ
Rizzy
2026-09-11 12:35:02
(4 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐ฎ๐ฉ
Burayot
2026-09-11 12:17:12
(5 hours ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 209.99.189.119 (CH/Switzerland/-): ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 209.99.189.119 (CH/Switzerland/-): 1 in the last 3600 secs
show less
Web App Attack
๐ซ๐ท
arsonist
2026-09-11 11:41:08
(5 hours ago)
[fail2ban]
2026-09-11T11:41:08.550783+00:00 arson caddy[1890453]: {"level":"info","ts":1789126868.55 ...
show more
[fail2ban]
2026-09-11T11:41:08.550783+00:00 arson caddy[1890453]: {"level":"info","ts":1789126868.5507505,"logger":"http.log.access.default","msg":"handled request","request":{"remote_ip":"209.99.189.119","remote_port":"33538","client_ip":"209.99.189.119","proto":"HTTP/1.1","method":"GET","host":"live.arson.gg","uri":"/.git/config","headers":{"Accept-Encoding":["gzip, deflate"],"User-Agent":["Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"],"Accept":["text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8"],"Accept-Language":["en-US,en;q=0.9"]},"tls":{"resumed":false,"version":772,"cipher_suite":4865,"proto":"http/1.1","server_name":"live.arson.gg","ech":false}},"bytes_read":0,"user_id":"","duration":0.000058631,"size":7,"status":418,"resp_headers":{"Server":["Caddy"],"Alt-Svc":["h3=\":443\"; ma=2592000"],"Content-Type":["tex
...
show less
Bad Web Bot
๐ฌ๐ง
consul.to
2026-09-11 10:56:24
(6 hours ago)
Web attack/malicious scanning detected
Web App Attack