🇺🇸
MPL
2026-09-14 16:57:41
(13 hours ago)
tcp/80
Port Scan
🇵🇱
webadmin
2026-09-14 08:24:41
(21 hours ago)
2026-09-14T10:10:40.284201+02:00 tytan csmpro-api[3056]: [error] client: 23.132.164.2 server: 213.25 ...
show more
2026-09-14T10:10:40.284201+02:00 tytan csmpro-api[3056]: [error] client: 23.132.164.2 server: 213.25.105.153, request: "GET", url: http://213.25.105.153/ [404]: Not Found
2026-09-14T10:10:41.545596+02:00 tytan csmpro-api[3056]: [error] client: 23.132.164.2 server: 213.25.105.153, request: "GET", url: http://213.25.105.153/.env [404]: Not Found
2026-09-14T10:10:44.154934+02:00 tytan csmpro-api[3056]: [error] client: 23.132.164.2 server: 213.25.105.153, request: "POST", url: http://213.25.105.153/ [404]: Not Found
2026-09-14T10:24:40.617414+02:00 tytan csmpro-api[3056]: [error] client: 23.132.164.2 server: 213.25.105.153, request: "GET", url: http://213.25.105.153/.env [404]: Not Found
show less
Web App Attack
🇯🇵
VXG-NET
2026-09-14 07:56:18
(22 hours ago)
port=80, indicator_type=info-leak
Hacking
Anonymous
2026-09-14 04:18:38
(1 day ago)
23.132.164.2 - - [14/Sep/2026:06:18:37 +0200] "GET /.env HTTP/1.1" 404 134 "-" "Mozilla/5.0 (Linux; ...
show more
23.132.164.2 - - [14/Sep/2026:06:18:37 +0200] "GET /.env HTTP/1.1" 404 134 "-" "Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30"
...
show less
Port Scan
Hacking
Brute-Force
Bad Web Bot
Web App Attack
SSH
Anonymous
2026-09-14 04:17:20
(1 day ago)
Sensitive Configuration File Disclosure.
Hacking
🇮🇪
Jim Keir
2026-09-14 04:07:35
(1 day ago)
2026-09-14 03:21:33 23.132.164.2 File scanning, blocking 23.132.164.2 for 5 minutes
2026-09-14 03:21 ...
show more
2026-09-14 03:21:33 23.132.164.2 File scanning, blocking 23.132.164.2 for 5 minutes
2026-09-14 03:21:33 23.132.164.2 File scanning, blocking 23.132.164.2 for 5 minutes
show less
Web App Attack
Anonymous
2026-09-14 03:54:30
(1 day ago)
23.132.164.2 - - [14/Sep/2026:03:54:29 +0000] "GET /.env HTTP/1.1" 404 153 "-" "Mozilla/5.0 (Linux; ...
show more
23.132.164.2 - - [14/Sep/2026:03:54:29 +0000] "GET /.env HTTP/1.1" 404 153 "-" "Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30" "-" "91.98.135.170"
...
show less
Hacking
Bad Web Bot
Web App Attack
🇮🇪
Jim Keir
2026-09-14 03:21:34
(1 day ago)
2026-09-14 03:21:33 23.132.164.2 File scanning, blocking 23.132.164.2 for 5 minutes
Web App Attack
🇦🇺
paulshipley.com.au
2026-09-14 00:38:04
(1 day ago)
[Mon Sep 14 10:38:03.657953 2026] [security2:error] [pid 39700] [client 23.132.164.2:64823] [client ...
show more
[Mon Sep 14 10:38:03.657953 2026] [security2:error] [pid 39700] [client 23.132.164.2:64823] [client 23.132.164.2] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "paulshipley.com.au"] [uri "/.env"] [unique_id "aqdB63cXoWO2IXZcZr6ETQAAAAw"]
...
show less
Web App Attack
🇺🇸
Power Ca
2026-09-13 23:28:41
(1 day ago)
23.132.164.2 - - [13/Sep/2026:23:28:41 +0000] "GET /.env HTTP/1.1" 301 178 "-" "Mozilla/5.0 (Linux; ...
show more
23.132.164.2 - - [13/Sep/2026:23:28:41 +0000] "GET /.env HTTP/1.1" 301 178 "-" "Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30"
...
show less
Web App Attack
Hacking
🇺🇸
cwytech
2026-09-13 23:08:13
(1 day ago)
Fleet-wide ban from the Ghostfleet 👻. Triggered by scenario: cwy/tpot-web-high.
Bad Web Bot
Web App Attack
🇫🇷
dynamix
2026-09-13 22:51:54
(1 day ago)
Multiple WAF Violations
Web App Attack
🇫🇮
6kilowatti
2026-09-13 22:20:51
(1 day ago)
23.132.164.2 - - [14/Sep/2026:01:20:50 +0300] "GET /.env HTTP/1.1" 404 153 "-" "Mozilla/5.0 (Linux; ...
show more
23.132.164.2 - - [14/Sep/2026:01:20:50 +0300] "GET /.env HTTP/1.1" 404 153 "-" "Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30"
...
show less
Web App Attack
🇫🇮
nNordic
2026-06-09 09:15:56
(3 months ago)
Connection attempt blocked by IDS/IPS from 23.132.164.2/32
Hacking
🇩🇪
Lazentis
2026-05-12 21:10:16
(4 months ago)
Unauthorized access attempt to port 5900 (tcp)
Brute-Force
SSH