๐ฉ๐ช
Roper123
2026-10-08 18:28:39
(23 hours ago)
Web exploits
Web App Attack
Anonymous
2026-10-08 15:14:40
(1 day ago)
Scan for .env Files at 2026-10-08T15:14:40+00:00
Web App Attack
Anonymous
2026-10-08 15:14:18
(1 day ago)
Scan for .env Files at 2026-10-08T15:14:18+00:00
Web App Attack
๐ฉ๐ช
Laplus
2026-10-08 14:06:05
(1 day ago)
35.210.120.9 - - [08/Oct/2026:16:05:59 +0200] "GET /.git/config HTTP/1.1" 302 87 "-" "Mozilla/5.0 (M ...
show more
35.210.120.9 - - [08/Oct/2026:16:05:59 +0200] "GET /.git/config HTTP/1.1" 302 87 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-"
35.210.120.9 - - [08/Oct/2026:16:05:59 +0200] "GET /.env HTTP/1.1" 302 78 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-"
35.210.120.9 - - [08/Oct/2026:16:05:59 +0200] "GET /.env.local HTTP/1.1" 302 84 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-"
35.210.120.9 - - [08/Oct/2026:16:06:00 +0200] "GET /.env.production HTTP/1.1" 302 89 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-"
35.210.120.9 - - [08/Oct/2026:16:06:00 +0200] "GET /.env.staging HTTP/1.1" 302 86 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like G
...
show less
Hacking
Web App Attack
๐จ๐ญ
zynex
2026-10-08 13:39:39
(1 day ago)
CrowdSec crowdsecurity/http-sensitive-files
Web App Attack
๐ญ๐ท
IgorS.zg.hr
2026-10-08 12:25:58
(1 day ago)
Web application attack detected by fail2ban
Hacking
Web App Attack
๐ต๐ฑ
Budyn
2026-10-08 11:34:52
(1 day ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: grafana.goblinpot.online | URI: /.env.bak | UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
๐ซ๐ท
mrcrassi
2026-10-08 11:24:35
(1 day ago)
Triggered Cloudflare WAF (botFight) from BE.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1.1 (GET ...
show more
Triggered Cloudflare WAF (botFight) from BE.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1.1 (GET method)
Endpoint: /
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ช๐ธ
Francisco Vallejo
2026-10-08 11:11:20
(1 day ago)
[Thu Oct 08 13:11:19.216982 2026] [authz_core:error] [pid 2249640:tid 133276308068032] [client 35.21 ...
show more
[Thu Oct 08 13:11:19.216982 2026] [authz_core:error] [pid 2249640:tid 133276308068032] [client 35.210.120.9:42242] AH01630: client denied by server configuration: proxy:https://localhost:3000/
[Thu Oct 08 13:11:19.268504 2026] [authz_core:error] [pid 2249640:tid 133277465704128] [client 35.210.120.9:42242] AH01630: client denied by server configuration: proxy:https://localhost:3000/
[Thu Oct 08 13:11:19.542252 2026] [authz_core:error] [pid 2249640:tid 133276828153536] [client 35.210.120.9:42242] AH01630: client denied by server configuration: proxy:https://localhost:3000/
[Thu Oct 08 13:11:19.790540 2026] [authz_core:error] [pid 2249640:tid 133277818001088] [client 35.210.120.9:42242] AH01630: client denied by server configuration: proxy:https://localhost:3000/
[Thu Oct 08 13:11:19.894157 2026] [authz_core:error] [pid 2249640:tid 133276853331648] [client 35.210.120.9:42242] AH01630: client denied by server configuration: proxy:https://localhost:3000/.git/config
...
show less
Brute-Force
SSH
๐ซ๐ฎ
mnazibo
2026-10-08 11:00:19
(1 day ago)
Date: Oct 08 13:13:03 2026 EAT | Reported IP: 35.210.120.9 mod_security | id: 932130 932235 932260 9 ...
show more
Date: Oct 08 13:13:03 2026 EAT | Reported IP: 35.210.120.9 mod_security | id: 932130 932235 932260 933135 934100 934130 942151 942550 949110 930130 920440 920500 | BE/usernameab.my_domain/- | Connections: 1 | Blocked: Permanent Block: [LF_MODSEC] | Logs: ; Remote Command Execution: Unix Shell Expression Found; Remote Command Execution: Unix Command Injection (command without evasion); Remote Command Execution: Direct Unix Command Execution; PHP Injection Attack: Variable Access Found; Node.js Injection Attack 1/2; Node.js Injection Attack 1/2; Node.js Injection Attack 1/2; JavaScript Prototype Pollution; JavaScript Prototype Pollution; SQL Injection Attack: SQL function name detected; JSON-Based SQL Injection; Inbound Anomaly Score Exceeded (Total Score: 55); Restricted File Access Attempt; Restricted File Access Attempt; Restricted File Access Attempt; Restricted File Access Attempt; Remote Command Execution: Unix Shell Expression Foun
show less
SQL Injection
Brute-Force
Bad Web Bot
๐ฉ๐ช
dave
2026-10-08 08:59:36
(1 day ago)
threat-feed-sync observed repeated abuse from this IP after local filtering. scenarios=crowdsecurity ...
show more
threat-feed-sync observed repeated abuse from this IP after local filtering. scenarios=crowdsecurity/appsec-vpatch,crowdsecurity/vpatch-CVE-2025-55182,crowdsecurity/vpatch-env-access,crowdsecurity/vpatch-git-config,custom/traefik-sensitive-path-probe observed_by=1_hosts hit_count=7 first_seen=2026-10-08T08:59:34Z last_seen=2026-10-08T08:59:36Z
show less
Web App Attack
๐ฉ๐ช
Dominik Lysiak
2026-10-08 07:50:37
(1 day ago)
35.210.120.9 - - [08/Oct/2026:09:50:36 +0200] "GET /.git/config HTTP/1.1" 302 57 "-" "Mozilla/5.0 (W ...
show more
35.210.120.9 - - [08/Oct/2026:09:50:36 +0200] "GET /.git/config HTTP/1.1" 302 57 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.210.120.9 - - [08/Oct/2026:09:50:36 +0200] "GET /.env HTTP/1.1" 302 48 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.210.120.9 - - [08/Oct/2026:09:50:36 +0200] "GET /.env.local HTTP/1.1" 302 54 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Web App Attack
๐จ๐ฆ
arsonist
2026-10-08 07:46:02
(1 day ago)
This IP accessed the path /.git/config, which is banned. Powered by ListenCaddy
Bad Web Bot
Web App Attack
๐ฉ๐ช
Blexyel
2026-10-08 07:28:35
(1 day ago)
35.210.120.9 - - [08/Oct/2026:09:28:34 +0200] "GET /.git/config HTTP/1.1" 302 57 "-" "Mozilla/5.0 (W ...
show more
35.210.120.9 - - [08/Oct/2026:09:28:34 +0200] "GET /.git/config HTTP/1.1" 302 57 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Brute-Force
Web App Attack
๐ต๐ฑ
Budyn
2026-10-08 06:50:18
(1 day ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: grafana.astropot.online | URI: /.git/config | UA: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack