๐ซ๐ท
phoenix1jl96
2026-09-15 01:43:37
(1 day ago)
2026/09/15 03:43:36 [error] 1444054#1444054: *172370 open() "/home/user-data/www/default/mailer/.env ...
show more
2026/09/15 03:43:36 [error] 1444054#1444054: *172370 open() "/home/user-data/www/default/mailer/.env" failed (2: No such file or directory), client: 34.35.137.43, server: pbs.ledemon.us, request: "GET /mailer/.env HTTP/1.1", host: "pbs.ledemon.us"
2026/09/15 03:43:36 [error] 1444054#1444054: *172370 open() "/usr/local/lib/roundcubemail/.env" failed (2: No such file or directory), client: 34.35.137.43, server: pbs.ledemon.us, request: "GET /mail/.env HTTP/1.1", host: "pbs.ledemon.us"
...
show less
DNS Compromise
DNS Poisoning
DDoS Attack
Ping of Death
Web Spam
Email Spam
Blog Spam
Port Scan
Hacking
Brute-Force
Bad Web Bot
SSH
Web App Attack
๐ฉ๐ช
LRob
2026-09-15 01:26:54
(1 day ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.git/config | 2026-09-15 01:26 UTC
show less
Hacking
Web App Attack
๐ฎ๐น
CoreTech srl
2026-09-15 01:25:07
(1 day ago)
[DC: IP:151.1.252.27] ntopng alert: blacklisted_client_contact,ndpi_tcp_issues,ndpi_probing_attempt
Hacking
๐ณ๐ฑ
Alt255
2026-09-15 00:28:06
(1 day ago)
[ti-14al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail <name>. Example: 34. ...
show more
[ti-14al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail <name>. Example: 34.35.137.43 - - \[15/Sep/2026:02:28:05 +0200\] "GET /.git/config HTTP/1.1" 301 558 "-" "Mozilla/5.0 \(Windows NT 10.0\; Win64\; x64\) AppleWebKit/537.36 \(KHTML, like Gecko\) Chrome/131.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-14 23:37:38
(1 day ago)
Excessive multi-domain requests
Brute-Force
๐ณ๐ฑ
debestelapp
2026-09-14 18:40:11
(1 day ago)
Web App Attack
๐จ๐ญ
Ribeye375
2026-09-14 00:26:10
(2 days ago)
HIPS web-exfiltration - Block tcp/0:65535
Web App Attack
๐จ๐ญ
dalslab ltd
2026-09-14 00:02:28
(2 days ago)
[14/Sep/2026:02:02:26 +0200] - 404 404 - GET https nc.dalslab.com "/.git/config" [Client 34.35.137.4 ...
show more
[14/Sep/2026:02:02:26 +0200] - 404 404 - GET https nc.dalslab.com "/.git/config" [Client 34.35.137.43] [Length 1846] [Gzip -] [Sent-to 10.1.1.253] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-"
[14/Sep/2026:02:02:26 +0200] - 404 404 - GET https nc.dalslab.com "/.env" [Client 34.35.137.43] [Length 1845] [Gzip -] [Sent-to 10.1.1.253] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-"
[14/Sep/2026:02:02:27 +0200] - 404 404 - GET https nc.dalslab.com "/.env.local" [Client 34.35.137.43] [Length 1843] [Gzip -] [Sent-to 10.1.1.253] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-"
[14/Sep/2026:02:02:27 +0200] - 404 404 - GET https nc.dalslab.com "/.env.production" [Client 34.35.137.43] [Length 1845] [Gzip -] [Sent-to 10.1.1.253] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_1
...
show less
Web Spam
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
mrcrassi
2026-09-13 23:59:47
(2 days ago)
Triggered Cloudflare WAF (firewallManaged) from ZA.
Action taken: BLOCK
Protocol: HTTP/1.1 (POST met ...
show more
Triggered Cloudflare WAF (firewallManaged) from ZA.
Action taken: BLOCK
Protocol: HTTP/1.1 (POST method)
Endpoint: /login
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ณ๐ฑ
oisecnet
2026-09-13 21:02:38
(2 days ago)
Automated report: Unauthorized vulnerability scanning detected on 2026-09-13. 842 requests from this ...
show more
Automated report: Unauthorized vulnerability scanning detected on 2026-09-13. 842 requests from this IP.
show less
Port Scan
Hacking
Web App Attack
๐บ๐ธ
Starburst SysOp Team
2026-09-13 13:43:42
(3 days ago)
Malware host detected by rbl.malware.expert. RBL lookup of 43.137.35.34.rbl.malware.expert succeeded ...
show more
Malware host detected by rbl.malware.expert. RBL lookup of 43.137.35.34.rbl.malware.expert succeeded at REMOTE_ADDR. (400010-stl2-14)
show less
Hacking
๐ณ๐ฑ
Site.eu
2026-09-13 09:29:45
(3 days ago)
Excessive multi-domain requests
Brute-Force
๐ฉ๐ช
neckaralb-admin.de
2026-09-13 08:09:58
(3 days ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
๐บ๐ธ
Lee Daniel
2026-09-12 06:56:01
(4 days ago)
34.35.137.43 - - [12/Sep/2026:02:56:00 -0400] "GET /.env HTTP/1.1" 403 6285 "-" "Mozilla/5.0 (Macint ...
show more
34.35.137.43 - - [12/Sep/2026:02:56:00 -0400] "GET /.env HTTP/1.1" 403 6285 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
DDoS Attack
Web Spam
Email Spam
Port Scan
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐น
penguin-solutions.at
2026-09-12 06:55:24
(4 days ago)
Excessive 403/404 errors
...
Brute-Force
Web App Attack