๐ณ๐ฑ
e.fierstra
2026-08-31 15:54:21
(3 days ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐ง๐ท
Peregrine
2026-08-31 03:16:01
(3 days ago)
Fail2Ban ct101 Jail: tomcat-honeypot | Evidence: - 34.20.154.163 - - [27/Aug/2026:03:45:36 -0300] "G ...
show more
Fail2Ban ct101 Jail: tomcat-honeypot | Evidence: - 34.20.154.163 - - [27/Aug/2026:03:45:36 -0300] "GET /wp-config.php~ HTTP/1.1" 404 18193
show less
Bad Web Bot
๐ฎ๐ช
AutosOnShow
2026-08-30 03:53:04
(4 days ago)
blocked for webapp attack | path requested: / | seen at 2026-08-30 03:52:42.239 |
Web App Attack
๐บ๐ธ
Axel
2026-08-30 01:58:31
(4 days ago)
Blocked by UFW on LAXHH [9080/tcp] | SPT: 42250 | TTL: 55 | LEN: 60 | TOS: 0x00 โข Reported by: githu ...
show more
Blocked by UFW on LAXHH [9080/tcp] | SPT: 42250 | TTL: 55 | LEN: 60 | TOS: 0x00 โข Reported by: github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
๐ง๐ฌ
Stoyko Stoykov
2026-08-30 01:27:29
(4 days ago)
34.20.154.163 - - [30/Aug/2026:04:27:29 +0300] "GET /.env.production HTTP/1.1" 404 0 "-" "crusader-w ...
show more
34.20.154.163 - - [30/Aug/2026:04:27:29 +0300] "GET /.env.production HTTP/1.1" 404 0 "-" "crusader-worker/1.0"
...
show less
Hacking
Web App Attack
๐ฌ๐ง
Artelis
2026-08-30 00:58:45
(4 days ago)
34.20.154.163 - - [30/Aug/2026:00:58:45 +0000] "GET /wp-config.php.swp HTTP/1.1" 404 146 "-" "crusad ...
show more
34.20.154.163 - - [30/Aug/2026:00:58:45 +0000] "GET /wp-config.php.swp HTTP/1.1" 404 146 "-" "crusader-worker/1.0"
34.20.154.163 - - [30/Aug/2026:00:58:45 +0000] "GET /.env.example HTTP/1.1" 404 146 "-" "crusader-worker/1.0"
34.20.154.163 - - [30/Aug/2026:00:58:45 +0000] "GET /wp-config.php.bak HTTP/1.1" 404 146 "-" "crusader-worker/1.0"
34.20.154.163 - - [30/Aug/2026:00:58:45 +0000] "GET /.env.production HTTP/1.1" 404 146 "-" "crusader-worker/1.0"
34.20.154.163 - - [30/Aug/2026:00:58:45 +0000] "GET /crusader-404-probe HTTP/1.1" 404 146 "-" "crusader-worker/1.0"
34.20.154.163 - - [30/Aug/2026:00:58:45 +0000] "GET /.env HTTP/1.1" 404 146 "-" "crusader-worker/1.0"
34.20.154.163 - - [30/Aug/2026:00:58:45 +0000] "GET /storage/logs/laravel.log HTTP/1.1" 404 146 "-" "crusader-worker/1.0"
34.20.154.163 - - [30/Aug/2026:00:58:45 +0000] "GET /actuator/configprops HTTP/1.1" 404 146 "-" "crusader-worker/1.0"
34.20.154.163 - - [30/Aug/2026:00:58:45 +0000] "GET /.env.bak HTTP/1.1" 404 146 "-" "crus
...
show less
Web App Attack
๐บ๐ธ
NXTwoThou
2026-08-30 00:23:00
(4 days ago)
/.env.example
Web App Attack
Anonymous
2026-08-29 04:05:08
(5 days ago)
WAF repeated trigger detected by Fail2Ban
Web App Attack
๐ฉ๐ช
Skyrider
2026-08-29 03:24:56
(5 days ago)
crowdsecurity/http-sensitive-files
Web App Attack
๐ง๐ท
Peregrine
2026-08-29 03:15:54
(5 days ago)
Fail2Ban ct101 Jail: tomcat-honeypot | Evidence: - 34.20.154.163 - - [27/Aug/2026:03:45:36 -0300] "G ...
show more
Fail2Ban ct101 Jail: tomcat-honeypot | Evidence: - 34.20.154.163 - - [27/Aug/2026:03:45:36 -0300] "GET /wp-config.php~ HTTP/1.1" 404 18193
show less
Bad Web Bot
๐ฉ๐ช
LRob
2026-08-29 03:13:44
(5 days ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.env.production (+12 more) | 2026-08-29 03:13 UTC
show less
Hacking
Web App Attack
Anonymous
2026-08-29 03:05:23
(5 days ago)
CrowdSec blocked IP for crowdsecurity/http-sensitive-files on localhost
Web App Attack
๐ฉ๐ช
4server
2026-08-29 02:02:24
(5 days ago)
[SatAug2904:02:18.4871922026][security2:error][pid3462014:tid3462107][client34.20.154.163:0]ModSecur ...
show more
[SatAug2904:02:18.4871922026][security2:error][pid3462014:tid3462107][client34.20.154.163:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"parrocchiaditesserete.ch.136-243-54-122.cpanel.site\"][uri\"/.env.production\"][unique_id\"apI9qtOtWUH7Vcd561m09gAAAMc\"]
show less
Port Scan
Brute-Force
Web App Attack
๐ฉ๐ช
maxpower
2026-08-29 01:37:09
(5 days ago)
(nginx_hardened) REGOLA 3 - Nginx Hardening Triggered 34.20.154.163 (US/United States/163.154.20.34. ...
show more
(nginx_hardened) REGOLA 3 - Nginx Hardening Triggered 34.20.154.163 (US/United States/163.154.20.34.bc.googleusercontent.com): 3 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 2026/08/29 03:37:08 [error] 1941209#1941209: *882554 access forbidden by rule, client: 34.20.154.163, server: fisacabruzzo.com, request: "GET /wp-config.php.bak HTTP/1.1", host: "51.89.2.98"
2026/08/29 03:37:08 [error] 1941214#1941214: *882557 access forbidden by rule, client: 34.20.154.163, server: fisacabruzzo.com, request: "GET /wp-config.php.swp HTTP/1.1", host: "51.89.2.98"
2026/08/29 03:37:08 [error] 1941213#1941213: *882556 access forbidden by rule, client: 34.20.154.163, server: fisacabruzzo.com, request: "GET /wp-config.php~ HTTP/1.1", host: "51.89.2.98"
show less
Port Scan
๐ฉ๐ช
FD-IX
2026-08-29 01:25:39
(5 days ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack