๐ฎ๐ฉ
Incidents Response Neptus Team
2026-10-08 05:09:00
(2 days ago)
Report Abuse IP
Exploited Host
Web App Attack
Hacking
๐ณ๐ฑ
Site.eu
2026-09-27 18:14:32
(1 week ago)
Excessive multi-domain requests
Brute-Force
๐ซ๐ฎ
botwork.se
2026-09-27 06:05:55
(1 week ago)
{"level":"info","ts":"2026-09-27T06:05:50Z","logger":"http.log.access.log2","msg":"handled request", ...
show more
{"level":"info","ts":"2026-09-27T06:05:50Z","logger":"http.log.access.log2","msg":"handled request","request":{"remote_ip":"34.53.220.14","remote_port":"49196","client_ip":"34.53.220.14","proto":"HTTP/1.1","method":"GET","host":"cloud.botwork.se","uri":"/.git/config","headers":{"Accept":["*/*"],"Connection":["keep-alive"],"Next-Action":["x"],"X-Nextjs-Request-Id":["efe438e3"],"Cookie":["REDACTED"],"User-Agent":["Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"],"Accept-Encoding":["gzip, deflate"]},"tls":{"resumed":false,"version":772,"cipher_suite":4865,"proto":"http/1.1","server_name":"cloud.botwork.se","ech":false}},"bytes_read":0,"user_id":"","duration":0.08405257,"size":1744,"status":404,"resp_headers":{"Date":["Sun, 27 Sep 2026 06:05:50 GMT"],"Content-Security-Policy":["default-src 'self' https://*.google-analytics.com:443 https://usercontent.apps.nextcloud.com:443; style-src 'self' 'unsafe-inline'; script-src 'self' 'unsafe-in
...
show less
Web App Attack
๐ต๐ฑ
Budyn
2026-09-27 04:17:04
(1 week ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: cloud.astropot.online | URI: /.git/config | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-26 15:33:43
(2 weeks ago)
[ti-03ov] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail apac ...
show more
[ti-03ov] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail apache-404. Example: 34.53.220.14 - - [26/Sep/2026:17:33:39 +0200] "GET /.git/config HTTP/1.1" 404 2127 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.53.220.14 - - [26/Sep/2026:17:33:39 +0200] "GET /.env HTTP/1.1" 404 2127 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.53.220.14 - - [26/Sep/2026:17:33:39 +0200] "GET /.env.local HTTP/1.1" 404 2127 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.53.220.14 - - [26/Sep/2026:17:33:39 +0200] "GET /.env.production HTTP/1.1" 404 2127 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML,
...
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-09-22 22:00:36
(2 weeks ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-21.
show less
Web App Attack
SSH
Hacking
Anonymous
2026-09-21 18:33:25
(2 weeks ago)
Flagged as abuse by IisGuard automated detection (tier L3, score 65/100). Reasons: Reputation=1, Bad ...
show more
Flagged as abuse by IisGuard automated detection (tier L3, score 65/100). Reasons: Reputation=1, BadPath=23,9, Rate=20, Diversity=20.
show less
Web App Attack
DDoS Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-21 17:12:11
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.53.220.14 (14.220.53.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.53.220.14 (14.220.53.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 13:12:05.024126 2026] [security2:error] [pid 26303:tid 26303] [client 34.53.220.14:53634] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "commercialphotostudiorental.com"] [uri "/.git/config"] [unique_id "arFlZdXkLGbmsHvcp3P-3QAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-09-21 16:40:04
(2 weeks ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-21 08:40:12
(2 weeks ago)
Excessive 404/403 errors
Brute-Force
๐ซ๐ท
dynamix
2026-09-21 08:19:06
(2 weeks ago)
Multiple WAF Violations
Web App Attack
Anonymous
2026-09-21 01:56:50
(2 weeks ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
๐ฎ๐น
sssrit
2026-09-20 16:13:38
(2 weeks ago)
34.53.220.14 - - [20/Sep/2026:18:13:37 +0200] "GET /phpinfo.php HTTP/1.1" 404 3713 "-" "Mozilla/5.0 ...
show more
34.53.220.14 - - [20/Sep/2026:18:13:37 +0200] "GET /phpinfo.php HTTP/1.1" 404 3713 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Web App Attack