๐ซ๐ท
masterguru
2026-10-11 12:48:18
(1 minute ago)
HTTP header is restricted by policy (/x-middleware-subrequest/). String match within "/content-encod ...
show more
HTTP header is restricted by policy (/x-middleware-subrequest/). String match within "/content-encoding/ /proxy/ /lock-token/ /content-range/ /if/ /x-http-method-override/ /x-http-method/ /x-method-override/ /x-middleware-subrequest/ /expect/" at TX:header_name_920450_x-middleware-subrequest. (920450-197)
show less
Bad Web Bot
๐บ๐ธ
Jakub Sikora
2026-10-11 06:00:09
(6 hours ago)
PHP webshell scanner detected by honeytrap. Threat score: 126, total requests: 26. Probed paths: //. ...
show more
PHP webshell scanner detected by honeytrap. Threat score: 126, total requests: 26. Probed paths: //.env, /.env.development, /config/env/aws_credentials.env, /.env_1, /.env.www. Triggered honeypots: canary_env, tarpit.
show less
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
gamabe
2026-10-11 04:14:13
(8 hours ago)
Detected crowdsecurity/http-path-traversal-probing attack pattern. Reported by CrowdSec IDS.
Port Scan
๐จ๐ญ
dalslab ltd
2026-10-11 01:17:09
(11 hours ago)
2026/10/11 03:17:08 [error] 332#332: *540891 limiting requests, excess: 200.170 by zone "rl_per_ip", ...
show more
2026/10/11 03:17:08 [error] 332#332: *540891 limiting requests, excess: 200.170 by zone "rl_per_ip", client: 35.201.244.105, server: auth.dalslab.com, request: "GET /.zshrc HTTP/2.0", host: "auth.dalslab.com"
2026/10/11 03:17:08 [error] 332#332: *540891 limiting requests, excess: 200.040 by zone "rl_per_ip", client: 35.201.244.105, server: auth.dalslab.com, request: "GET /@fs/src/.env?raw?? HTTP/2.0", host: "auth.dalslab.com"
2026/10/11 03:17:08 [error] 332#332: *540891 limiting requests, excess: 200.030 by zone "rl_per_ip", client: 35.201.244.105, server: auth.dalslab.com, request: "GET /@fs/app/.env?raw?? HTTP/2.0", host: "auth.dalslab.com"
2026/10/11 03:17:08 [error] 332#332: *540891 limiting requests, excess: 200.900 by zone "rl_per_ip", client: 35.201.244.105, server: auth.dalslab.com, request: "GET /@fs/../.env?raw?? HTTP/2.0", host: "auth.dalslab.com"
2026/10/11 03:17:09 [error] 332#332: *540891 limiting requests, excess: 200.420 by zone "rl_per_ip", client: 35.201.244.105, serv
...
show less
Brute-Force
SSH
๐ธ๐ฌ
simpeg-adm.bandung.go.id
2026-10-11 00:28:28
(12 hours ago)
11/Oct/2026:00:28:27 +0000;35.201.244.105;"/1xqkxn6sfuqvw3qit0x4"
11/Oct/2026:00:28:27 +0000;35.201. ...
show more
11/Oct/2026:00:28:27 +0000;35.201.244.105;"/1xqkxn6sfuqvw3qit0x4"
11/Oct/2026:00:28:27 +0000;35.201.244.105;"/ckr4iyvzr0xv2q4grcom"
11/Oct/2026:00:28:27 +0000;35.201.244.105;"/dist/.vite/manifest.json"
11/Oct/2026:00:28:28 +0000;35.201.244.105;"/.git/HEAD"
11/Oct/2026:00:28:28 +0000;35.201.244.105;"/.git-credentials"
11/Oct/2026:00:28:28 +0000;35.201.244.105;"/secrets.env"
11/Oct/2026:00:28:28 +0000;35.201.244.105;"/secrets.yml"
...
show less
Web Spam
Brute-Force
Web App Attack
๐บ๐ธ
gamabe
2026-10-10 23:20:21
(13 hours ago)
Detected crowdsecurity/http-sensitive-files attack pattern. Reported by CrowdSec IDS.
Hacking
Anonymous
2026-10-10 23:17:20
(13 hours ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
๐บ๐ธ
WizardsToolkit
2026-10-10 22:46:56
(14 hours ago)
tried to access server backup files
Web App Attack
๐บ๐ธ
gamabe
2026-10-10 22:44:16
(14 hours ago)
Detected crowdsecurity/http-dos-swithcing-ua attack pattern. Reported by CrowdSec IDS.
Hacking
๐ฉ๐ช
kkw
2026-10-10 22:33:22
(14 hours ago)
[REDACTED] 35.201.244.105 - - [11/Oct/2026:00:33:22 +0200] "GET /.git/config HTTP/2.0" 404 343 "-" " ...
show more
[REDACTED] 35.201.244.105 - - [11/Oct/2026:00:33:22 +0200] "GET /.git/config HTTP/2.0" 404 343 "-" "Mozilla/5.0 (compatible; KimiBot/1.0; +https://kimi.ai/)"
... (mode: searching http-sensitive-files)
show less
Bad Web Bot
Web App Attack
๐ง๐ท
radardatelecom
2026-10-10 22:27:03
(14 hours ago)
Blocked by Radar da Telecom firewall โ abuseipdb
Bad Web Bot
Web App Attack
๐บ๐ธ
iwle
2026-10-10 22:00:07
(14 hours ago)
[Sat Oct 10 18:00:03.829420 2026] [:error] [pid 1476:tid 1640] [client 35.201.244.105:0] [client 35. ...
show more
[Sat Oct 10 18:00:03.829420 2026] [:error] [pid 1476:tid 1640] [client 35.201.244.105:0] [client 35.201.244.105] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "125"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.save"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "iwle.com"] [uri "/.env.save"] [unique_id "asq1YxM9iwOnloWQjmIOCgAAAAw"]
[Sat Oct 10 18:00:03.836250 2026] [:error] [pid 1476:tid 1632] [client 35.201.244.105:0] [client 35.201.244.105] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "125"]
...
show less
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-10-10 21:59:49
(14 hours ago)
Auto-ban: >3000 req/min op 2026-10-10
Web App Attack
SSH
Hacking
๐บ๐ธ
Blue Pumpkin
2026-10-10 21:50:48
(14 hours ago)
35.201.244.105 - - [10/Oct/2026:21:50:47 +0000] "GET /secrets.env HTTP/1.1" 302 585 "-" "Mozilla/5.0 ...
show more
35.201.244.105 - - [10/Oct/2026:21:50:47 +0000] "GET /secrets.env HTTP/1.1" 302 585 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
...
show less
Brute-Force
๐ฉ๐ช
Skyrider
2026-10-10 21:18:14
(15 hours ago)
Nginx: HTTP 4xx probe/scan attempts. Automated fail2ban report.
Bad Web Bot
Web App Attack