Anonymous
2026-07-29 07:00:00
(1 day ago)
Apache probe; attempts=865; exact paths: /.env | /.env.backup | /.env.bak | /.env.dev | /.env.develo ...
show more
Apache probe; attempts=865; exact paths: /.env | /.env.backup | /.env.bak | /.env.dev | /.env.development | /.env.example | /.env.local | /.env.old | /.env.php.bak | /.env.prod.bak | /.env.production | /.env.production.bak | /.env.staging | /.env.swp | /.env.test | /.git-credentials | /.git/HEAD | /.git/config | /.hermes/.env | /.openclaw/.env | /@fs/.env?raw?? | /@fs/root/.env?raw?? | /actuator | /actuator/configprops | /actuator/env | /actuator/mappings | /admin/.env | /api/.env | /app/.env | /backend/.env | /config.env | /config/.env | /config/.env.php | /core/.env | /dev/.env | /docker/.env | /frontend/.env | /laravel/.env | /production/.env | /public/.env | /sendgrid.env | /server/.env | /src/.env | /staging/.env | /web/.env
show less
Web App Attack
๐จ๐ญ
TheCoon
2026-07-27 14:15:01
(2 days ago)
Automated: Credential theft attempt - JSON bomb served
Web App Attack
Hacking
๐ฉ๐ช
macrob
2026-07-27 12:41:48
(2 days ago)
2026/07/27 12:41:47 [error] 4144890#4144890: *417154264 access forbidden by rule, client: 34.107.97. ...
show more
2026/07/27 12:41:47 [error] 4144890#4144890: *417154264 access forbidden by rule, client: 34.107.97.183, server: fn.binixo.es, request: "GET /.aws/credentials HTTP/2.0", host: "customer.fastcredit.net.ua"
2026/07/27 12:41:47 [error] 4144890#4144890: *417154264 access forbidden by rule, client: 34.107.97.183, server: fn.binixo.es, request: "GET /.aws/config HTTP/2.0", host: "customer.fastcredit.net.ua"
2026/07/27 12:41:47 [error] 4144890#4144890: *417154264 access forbidden by rule, client: 34.107.97.183, server: fn.binixo.es, request: "GET /.git/config HTTP/2.0", host: "customer.fastcredit.net.ua"
...
show less
Web App Attack
๐ฉ๐ช
macrob
2026-07-27 10:25:46
(2 days ago)
2026/07/27 10:25:44 [error] 4144892#4144892: *416791522 access forbidden by rule, client: 34.107.97. ...
show more
2026/07/27 10:25:44 [error] 4144892#4144892: *416791522 access forbidden by rule, client: 34.107.97.183, server: fn.binixo.es, request: "GET /.git/config HTTP/2.0", host: "qa.fastcredit.net.ua"
2026/07/27 10:25:44 [error] 4144892#4144892: *416791522 access forbidden by rule, client: 34.107.97.183, server: fn.binixo.es, request: "GET /.aws/credentials HTTP/2.0", host: "qa.fastcredit.net.ua"
2026/07/27 10:25:44 [error] 4144892#4144892: *416791522 access forbidden by rule, client: 34.107.97.183, server: fn.binixo.es, request: "GET /.next/build-manifest.json HTTP/2.0", host: "qa.fastcredit.net.ua"
...
show less
Web App Attack
๐ณ๐ฑ
Site.eu
2026-07-27 10:07:12
(2 days ago)
Excessive multi-domain requests
Brute-Force
๐ซ๐ท
dynamix
2026-07-27 09:12:20
(2 days ago)
Multiple WAF Violations
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-07-27 09:06:11
(2 days ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐ง๐ช
voormedia
2026-07-27 03:18:15
(3 days ago)
Accessed trap at '/.env'
Web App Attack
๐ฉ๐ช
marcelhalls
2026-07-27 03:00:14
(3 days ago)
Repeated attacks detected by Fail2Ban in recidive jail
Hacking
๐ณ๐ฑ
Savvii
2026-07-27 01:58:37
(3 days ago)
15 attempts against mh-modsecurity-ban on byrd
Brute-Force
Web App Attack
๐ณ๐ฑ
Eric
2026-07-27 01:48:06
(3 days ago)
[Mon Jul 27 01:48:06.077797 2026] [security2:error] [pid 2717324:tid 2717324] [client 34.107.97.183: ...
show more
[Mon Jul 27 01:48:06.077797 2026] [security2:error] [pid 2717324:tid 2717324] [client 34.107.97.183:0] [client 34.107.97.183] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "pop-the-slots.com"] [uri "/z9x8c7v6b5-debug-trigger-pop-the-slots.com"] [unique_id "ama41uxvRQ9jaXmw8PHcpgAAAAc"]
[Mon Jul 27 01:48:06.086657 2026] [security2:error] [pid 2748107:tid 2748107] [client 34.107.97.183:0] [client 34.107.97.183] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Scor
...
show less
Hacking
Web App Attack
๐บ๐ธ
legionMCCXV
2026-07-27 01:00:42
(3 days ago)
PHP/WordPress shell scanner on non-PHP site โ repeated requests to .php paths returning 404.
Bad Web Bot
๐ซ๐ท
Lunix
2026-07-26 22:28:23
(3 days ago)
Brute-Force
Web App Attack
๐ง๐ช
voormedia
2026-07-26 16:53:30
(3 days ago)
Accessed trap at '/.git/HEAD'
Web App Attack
๐ณ๐ฑ
Savvii
2026-07-26 14:18:41
(3 days ago)
20 attempts against mh-misbehave-ban on onion
Brute-Force
Bad Web Bot
Web App Attack