๐ฉ๐ช
LRob
2025-12-11 03:17:34
(7 months ago)
Repeated attacks detected by Fail2Ban in recidive jail
Hacking
๐ซ๐ท
dynamix
2025-12-11 03:11:30
(7 months ago)
Multiple WAF Violations
Web App Attack
๐ฉ๐ช
paissangroup
2025-12-11 03:04:14
(7 months ago)
Multiple WAF Violations
Web App Attack
๐ฆ๐บ
aranguren.org
2025-12-11 03:03:36
(7 months ago)
3.239.202.201 - - [11/Dec/2025:14:03:33 +1100] "GET /.env HTTP/1.1" 404 985 "-" "Mozilla/5.0 (X11; L ...
show more
3.239.202.201 - - [11/Dec/2025:14:03:33 +1100] "GET /.env HTTP/1.1" 404 985 "-" "Mozilla/5.0 (X11; Linux x86_64)"
3.239.202.201 - - [11/Dec/2025:14:03:34 +1100] "GET /app/.env HTTP/1.1" 404 985 "-" "Mozilla/5.0 (X11; Linux x86_64)"
3.239.202.201 - - [11/Dec/2025:14:03:34 +1100] "GET /config/.env HTTP/1.1" 404 985 "-" "Mozilla/5.0 (X11; Linux x86_64)"
3.239.202.201 - - [11/Dec/2025:14:03:34 +1100] "GET /api/.env HTTP/1.1" 404 985 "-" "Mozilla/5.0 (X11; Linux x86_64)"
3.239.202.201 - - [11/Dec/2025:14:03:35 +1100] "GET /admin/.env HTTP/1.1" 404 985 "-" "Mozilla/5.0 (X11; Linux x86_64)"
3.239.202.201 - - [11/Dec/2025:14:03:35 +1100] "GET /backend/.env HTTP/1.1" 404 985 "-" "Mozilla/5.0 (X11; Linux x86_64)"
...
show less
Bad Web Bot
๐ง๐ช
taivas.nl
2025-12-11 03:02:10
(7 months ago)
Bad_requests
Bad Web Bot
๐ช๐ธ
Francisco Vallejo
2025-12-11 02:57:50
(7 months ago)
[Thu Dec 11 03:57:34.515319 2025] [authz_core:error] [pid 1470271:tid 127275550881472] [client 3.239 ...
show more
[Thu Dec 11 03:57:34.515319 2025] [authz_core:error] [pid 1470271:tid 127275550881472] [client 3.239.202.201:58344] AH01630: client denied by server configuration: proxy:http://127.0.0.1:1780/, referer: http://audio.franvallejo.es
[Thu Dec 11 03:57:34.861205 2025] [authz_core:error] [pid 1470271:tid 127277100680896] [client 3.239.202.201:58344] AH01630: client denied by server configuration: proxy:http://127.0.0.1:1780/.env, referer: http://audio.franvallejo.es/.env
[Thu Dec 11 03:57:35.125507 2025] [authz_core:error] [pid 1470271:tid 127276960167616] [client 3.239.202.201:58344] AH01630: client denied by server configuration: proxy:http://127.0.0.1:1780/app/.env, referer: http://audio.franvallejo.es/app/.env
[Thu Dec 11 03:57:35.411934 2025] [authz_core:error] [pid 1470271:tid 127277083895488] [client 3.239.202.201:58344] AH01630: client denied by server configuration: proxy:http://127.0.0.1:1780/config/.env, referer: http://audio.franvallejo.es/config/.env
[Thu Dec 11 03:57:35.675020
...
show less
Brute-Force
SSH
๐ฌ๐ง
Apache
2025-12-11 02:49:24
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 3.239.202.201 (US/United States/ec2-3-239-202-2 ...
show more
(mod_security) mod_security (id:210492) triggered by 3.239.202.201 (US/United States/ec2-3-239-202-201.compute-1.amazonaws.com): 5 in the last 300 secs
show less
Brute-Force
Web App Attack
๐ฉ๐ช
DocNetzwerk
2025-12-11 02:45:16
(7 months ago)
(mod_security) mod_security triggered on hostname [redacted] 3.239.202.201 (US/United States/ec2-3-2 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 3.239.202.201 (US/United States/ec2-3-239-202-201.compute-1.amazonaws.com)
show less
SQL Injection
๐บ๐ธ
Eric Bellomo
2025-12-11 02:44:29
(7 months ago)
3.239.202.201 - - [11/Dec/2025:02:44:28 +0000] "GET / HTTP/1.1" 403 13
3.239.202.201 - - [11/Dec/202 ...
show more
3.239.202.201 - - [11/Dec/2025:02:44:28 +0000] "GET / HTTP/1.1" 403 13
3.239.202.201 - - [11/Dec/2025:02:44:28 +0000] "GET /.env HTTP/1.1" 403 13
3.239.202.201 - - [11/Dec/2025:02:44:28 +0000] "GET /app/.env HTTP/1.1" 403 13
3.239.202.201 - - [11/Dec/2025:02:44:29 +0000] "GET /config/.env HTTP/1.1" 403 13
...
show less
Port Scan
Bad Web Bot
๐ฆ๐บ
screwlooseit.com.au
2025-12-11 02:43:21
(7 months ago)
Blocked by CSF 13 firewall - Rule: config-dotfile
US/United States/ec2-3-239-202-201.compute-1.amazo ...
show more
Blocked by CSF 13 firewall - Rule: config-dotfile
US/United States/ec2-3-239-202-201.compute-1.amazonaws.com
show less
Web App Attack
๐ฉ๐ช
LRob
2025-12-11 02:32:54
(7 months ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
๐ฉ๐ช
Hary74656
2025-12-11 02:31:11
(7 months ago)
[Thu Dec 11 03:31:01.087921 2025] [security2:error] [pid 420803:tid 420881] [client 3.239.202.201:52 ...
show more
[Thu Dec 11 03:31:01.087921 2025] [security2:error] [pid 420803:tid 420881] [client 3.239.202.201:52146] [client 3.239.202.201] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "125"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "auge.weavernet.at"] [uri "/.env"] [unique_id "aTos5ZFF85PWSnXiDvclwwAAA48"]
[Thu Dec 11 03:31:01.250904 2025] [security2:error] [pid 420803:tid 420883] [client 3.239.202.201:52146] [client 3.239.202.201] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/mods
...
show less
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2025-12-11 02:26:40
(7 months ago)
3.239.202.201 - - [11/Dec/2025:04:26:38 +0200] "GET /.env HTTP/1.1" 404 301 "http://artmind.ndiu.org ...
show more
3.239.202.201 - - [11/Dec/2025:04:26:38 +0200] "GET /.env HTTP/1.1" 404 301 "http://artmind.ndiu.org.ua/.env" "Mozilla/5.0 (X11; Linux x86_64)"
3.239.202.201 - - [11/Dec/2025:04:26:39 +0200] "GET /app/.env HTTP/1.1" 404 2855 "http://artmind.ndiu.org.ua/app/.env" "Mozilla/5.0 (X11; Linux x86_64)"
...
show less
Web App Attack
๐ช๐ธ
masterguru
2025-12-11 02:23:00
(7 months ago)
BAD BOT - Detected and Blocked.. Matched phrase "go-http-client" at REQUEST_HEADERS:User-Agent. (110 ...
show more
BAD BOT - Detected and Blocked.. Matched phrase "go-http-client" at REQUEST_HEADERS:User-Agent. (1100000-123)
show less
Bad Web Bot
๐ฉ๐ช
Bedios GmbH
2025-12-10 03:11:40
(7 months ago)
Login credentials theft attempt
Hacking