Anonymous
2026-09-19 13:30:02
(46 minutes ago)
CrowdSec decision: crowdsecurity/http-admin-interface-probing (origin: crowdsec)
Web App Attack
๐ฉ๐ช
itsolon
2026-09-19 07:30:15
(6 hours ago)
[19/Sep/2026:09:30:15 +0200] 178980301597.052490 35.227.72.232 33128 217.154.7.177 443
[19/Sep/2026: ...
show more
[19/Sep/2026:09:30:15 +0200] 178980301597.052490 35.227.72.232 33128 217.154.7.177 443
[19/Sep/2026:09:30:15 +0200] 178980301539.596173 35.227.72.232 33128 217.154.7.177 443
[19/Sep/2026:09:30:15 +0200] 178980301595.183674 35.227.72.232 33128 217.154.7.177 443
[19/Sep/2026:09:30:15 +0200] 178980301548.856089 35.227.72.232 33128 217.154.7.177 443
[19/Sep/2026:09:30:15 +0200] 178980301593.897002 35.227.72.232 33128 217.154.7.177 443
...
show less
Port Scan
Hacking
Brute-Force
Web App Attack
๐ธ๐ฌ
Cloudkul Cloudkul
2026-09-19 06:36:25
(7 hours ago)
Attempted Brute Force on our application
Brute-Force
Web App Attack
๐ง๐ท
Peregrine
2026-09-19 03:11:49
(11 hours ago)
Fail2Ban Jail: tomcat-honeypot | Evidence: 35.227.72.232 104.22.56.25 - - [17/Sep/2026:02:55:07 -030 ...
show more
Fail2Ban Jail: tomcat-honeypot | Evidence: 35.227.72.232 104.22.56.25 - - [17/Sep/2026:02:55:07 -0300] "GET /private/.env HTTP/1.1" 404 414
35.227.72.232 104.22.56.24 - - [17/Sep/2026:02:55:07 -0300] "GET /var/.env HTTP/1.1" 404 414
35.227.72.232 104.22.56.25 - - [17/Sep/2026:02:55:07 -0300] "GET /assets/.env HTTP/1.1" 404 414
35.227.72.232 104.22.56.24 - - [17/Sep/2026:02:55:07 -0300] "GET /tmp/.env HTTP/1.1" 404 414
35.227.72.232 104.22.56.25 - - [17/Sep/2026:02:55:07 -0300] "GET /static/.env HTTP/1.1" 404 414
35.227.72.232 104.22.56.25 - - [17/Sep/2026:02:55:08 -0300] "GET /temp/.env HTTP/1.1" 404 414
35.227.72.232 104.22.56.24 - - [17/Sep/2026:02:55:08 -0300] "GET /conf/.env HTTP/1.1" 404 414
35.227.72.232 104.22.56.24 - - [17/Sep/2026:02:55:08 -0300] "GET /env/.env HTTP/1.1" 404 414
35.227.72.232 104.22.56.24 - - [17/Sep/2026:02:55:08 -0300] "GET /etc/.env HTTP/1.1" 404 414
show less
Bad Web Bot
Anonymous
2026-09-19 01:30:03
(12 hours ago)
CrowdSec decision: crowdsecurity/http-bad-user-agent (origin: crowdsec)
Port Scan
๐ง๐ท
dermatovirtual
2026-09-18 17:03:07
(21 hours ago)
Dermato Virtual CSIRT: Malicious web exploit/scanning probes against app.dermatovirtual.com.br (Web ...
show more
Dermato Virtual CSIRT: Malicious web exploit/scanning probes against app.dermatovirtual.com.br (Web Server Ports 80/443). 128 unauthorized requests recorded between 2026-09-17 16:59:20 UTC and 2026-09-17 16:59:28 UTC (rate: ~128 req/min). Edge perimeter firewall drop active.
Log sample:
[2026-09-17 16:59:27 UTC] IP: 35.227.72.232 - W3C IIS (Port 443): GET /.env.local -> HTTP 404 [CLIENT: 35.227.72.232]
[2026-09-17 16:59:27 UTC] IP: 35.227.72.232 - W3C IIS (Port 443): GET /.env.local -> HTTP 404 [CLIENT: 35.227.72.232]
[2026-09-17 16:59:27 UTC] IP: 35.227.72.232 - W3C IIS (Port 443): GET /@fs/app/.env.production -> HTTP 404 [CLIENT: 35.227.72.232]
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
TheDjRider
2026-09-18 15:42:12
(22 hours ago)
CrowdSec detected Web application reconnaissance. Scenario: local/framework-recon. Automatic ban tri ...
show more
CrowdSec detected Web application reconnaissance. Scenario: local/framework-recon. Automatic ban triggered. Detection time (UTC): 2026-09-18T15:42:11.278102617Z. Context: http_status=200
show less
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-18 09:25:02
(1 day ago)
[cb-13al] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail apac ...
show more
[cb-13al] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail apache-404. Example: 35.227.72.232 - - [18/Sep/2026:11:24:47 +0200] "GET /api/settings HTTP/2.0" 404 1878 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot)"
35.227.72.232 - - [18/Sep/2026:11:24:47 +0200] "GET /manifest.json HTTP/2.0" 404 1855 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36"
35.227.72.232 - - [18/Sep/2026:11:24:47 +0200] "GET /config.json HTTP/2.0" 404 1855 "-" "Mozilla/5.0 (compatible; PanguBot/1.0; +https://www.huaweicloud.com/)"
35.227.72.232 - - [18/Sep/2026:11:24:47 +0200] "GET /asset-manifest.json HTTP/2.0" 404 1855 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_
...
show less
Bad Web Bot
Web App Attack
๐ซ๐ท
SpaceHost-Server
2026-09-17 22:22:28
(1 day ago)
Brute-Force
Web App Attack
๐ฉ๐ช
FD-IX
2026-09-17 21:55:07
(1 day ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
๐ง๐ท
dermatovirtual
2026-09-17 17:01:56
(1 day ago)
Dermato Virtual CSIRT: Malicious web exploit/scanning probes against app.dermatovirtual.com.br (Web ...
show more
Dermato Virtual CSIRT: Malicious web exploit/scanning probes against app.dermatovirtual.com.br (Web Server Ports 80/443). 109 unauthorized requests recorded between 2026-09-17 16:59:20 UTC and 2026-09-17 16:59:26 UTC (rate: ~109 req/min). Edge perimeter firewall drop active.
Log sample:
[2026-09-17 16:59:26 UTC] IP: 35.227.72.232 - W3C IIS (Port 443): GET /var/.env -> HTTP 404 [CLIENT: 35.227.72.232]
[2026-09-17 16:59:26 UTC] IP: 35.227.72.232 - W3C IIS (Port 443): GET /portal/.env -> HTTP 404 [CLIENT: 35.227.72.232]
[2026-09-17 16:59:26 UTC] IP: 35.227.72.232 - W3C IIS (Port 443): GET /@fs/.env -> HTTP 404 [CLIENT: 35.227.72.232]
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
ConsulHosting
2026-09-17 15:31:59
(1 day ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack
Anonymous
2026-09-17 12:39:19
(2 days ago)
35.227.72.232 - - [17/Sep/2026:07:39:18 -0500] "GET /.env.js HTTP/1.1" 403 199 "-" "Mozilla/5.0 (com ...
show more
35.227.72.232 - - [17/Sep/2026:07:39:18 -0500] "GET /.env.js HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; MistralAI-User/1.0; +https://mistral.ai/)" 35.227.72.232
35.227.72.232 - - [17/Sep/2026:07:39:18 -0500] "GET /.env HTTP/1.1" 403 199 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; [email protected] )" 35.227.72.232
35.227.72.232 - - [17/Sep/2026:07:39:18 -0500] "GET /.env.prod HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; YouBot/1.0; +https://you.com/bot)" 35.227.72.232
35.227.72.232 - - [17/Sep/2026:07:39:18 -0500] "GET /.env_1 HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; Qwenbot/1.0; +https://qwen.alibaba.com/)" 35.227.72.232
35.227.72.232 - - [17/Sep/2026:07:39:18 -0500] "GET /.env.backup HTTP/1.1" 403 199 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Safari/605.1.15 (Applebot/0.1)" 35.227.72.232
35.227.72.232 - - [17/Sep/2026:07:39:19 -0500] "GET /.env.live HTTP/1.1"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฟ๐ฆ
conure.sh
2026-09-17 12:11:41
(2 days ago)
csagent: score 20.0: secrets grab x2; 1 domain(s) in 17s
Web App Attack
๐ธ๐ฌ
khairilgunawan
2026-09-17 11:36:58
(2 days ago)
ZonaKuota Sentinel: Malicious automated scanner/exploit probe trapped. Blocked.
Web App Attack
Bad Web Bot