π§π·
Peregrine
2026-09-16 03:10:30
(11 hours ago)
Fail2Ban Jail: tomcat-honeypot | Evidence: 35.236.54.187 104.22.49.83 - - [12/Sep/2026:09:39:43 -030 ...
show more
Fail2Ban Jail: tomcat-honeypot | Evidence: 35.236.54.187 104.22.49.83 - - [12/Sep/2026:09:39:43 -0300] "GET /files../.env HTTP/1.1" 404 414
35.236.54.187 104.22.49.83 - - [12/Sep/2026:09:39:43 -0300] "GET /static//.env HTTP/1.1" 404 414
35.236.54.187 104.22.49.48 - - [12/Sep/2026:09:39:43 -0300] "GET /media../.env HTTP/1.1" 404 414
35.236.54.187 104.22.49.48 - - [12/Sep/2026:09:39:45 -0300] "GET /.//.env HTTP/1.1" 404 414
35.236.54.187 104.22.49.48 - - [12/Sep/2026:09:39:45 -0300] "GET /static//app/.env HTTP/1.1" 404 414
35.236.54.187 104.22.49.48 - - [12/Sep/2026:09:39:46 -0300] "GET //.env HTTP/1.1" 404 414
35.236.54.187 104.22.49.48 - - [12/Sep/2026:09:39:46 -0300] "GET /static//home/user/.env HTTP/1.1" 404 414
35.236.54.187 104.22.49.48 - - [12/Sep/2026:09:39:46 -0300] "GET /uploads../.env HTTP/1.1" 404 414
35.236.54.187 104.22.49.48 - - [12/Sep/2026:09:39:46 -0300] "GET /assets../.env HTTP/1.1" 404 414
show less
Bad Web Bot
π³π±
Alt255
2026-09-15 18:12:13
(20 hours ago)
[ti-01ov] Web exploit scanning: 7 suspicious requests detected by fail2ban jail <name>. Example: 35. ...
show more
[ti-01ov] Web exploit scanning: 7 suspicious requests detected by fail2ban jail <name>. Example: 35.236.54.187 - - [11/Sep/2026:06:26:11 +0200] "GET /.ssh/id_rsa HTTP/1.1" 404 103966 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot)"
35.236.54.187 - - [11/Sep/2026:06:26:14 +0200] "GET /.ssh/id_dsa HTTP/1.1" 403 223 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; [email protected] )"
35.236.54.187 - - [11/Sep/2026:06:26:14 +0200] "GET /.ssh/authorized_keys HTTP/1.1" 403 5529 "-" "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)"
35.236.54.187 - - [11/Sep/2026:06:26:14 +0200] "GET /.ssh/id_ecdsa HTTP/1.1" 404 98660 "-" "Mozilla/5.0 (compatible;
...
show less
Bad Web Bot
Web App Attack
π§π·
Peregrine
2026-09-15 03:10:25
(1 day ago)
Fail2Ban Jail: tomcat-honeypot | Evidence: 35.236.54.187 104.22.49.83 - - [12/Sep/2026:09:39:43 -030 ...
show more
Fail2Ban Jail: tomcat-honeypot | Evidence: 35.236.54.187 104.22.49.83 - - [12/Sep/2026:09:39:43 -0300] "GET /files../.env HTTP/1.1" 404 414
35.236.54.187 104.22.49.83 - - [12/Sep/2026:09:39:43 -0300] "GET /static//.env HTTP/1.1" 404 414
35.236.54.187 104.22.49.48 - - [12/Sep/2026:09:39:43 -0300] "GET /media../.env HTTP/1.1" 404 414
35.236.54.187 104.22.49.48 - - [12/Sep/2026:09:39:45 -0300] "GET /.//.env HTTP/1.1" 404 414
35.236.54.187 104.22.49.48 - - [12/Sep/2026:09:39:45 -0300] "GET /static//app/.env HTTP/1.1" 404 414
35.236.54.187 104.22.49.48 - - [12/Sep/2026:09:39:46 -0300] "GET //.env HTTP/1.1" 404 414
35.236.54.187 104.22.49.48 - - [12/Sep/2026:09:39:46 -0300] "GET /static//home/user/.env HTTP/1.1" 404 414
35.236.54.187 104.22.49.48 - - [12/Sep/2026:09:39:46 -0300] "GET /uploads../.env HTTP/1.1" 404 414
35.236.54.187 104.22.49.48 - - [12/Sep/2026:09:39:46 -0300] "GET /assets../.env HTTP/1.1" 404 414
show less
Bad Web Bot
π¨π¦
polycoda
2026-09-14 12:21:02
(2 days ago)
π₯ VERY AGGRESSIVE SCANNER probed over 200 inexistent files and PHP scripts in less than an hour.
Hacking
Web App Attack
π§π·
Peregrine
2026-09-14 03:09:56
(2 days ago)
Fail2Ban Jail: tomcat-honeypot | Evidence: 35.236.54.187 104.22.49.83 - - [12/Sep/2026:09:39:43 -030 ...
show more
Fail2Ban Jail: tomcat-honeypot | Evidence: 35.236.54.187 104.22.49.83 - - [12/Sep/2026:09:39:43 -0300] "GET /files../.env HTTP/1.1" 404 414
35.236.54.187 104.22.49.83 - - [12/Sep/2026:09:39:43 -0300] "GET /static//.env HTTP/1.1" 404 414
35.236.54.187 104.22.49.48 - - [12/Sep/2026:09:39:43 -0300] "GET /media../.env HTTP/1.1" 404 414
35.236.54.187 104.22.49.48 - - [12/Sep/2026:09:39:45 -0300] "GET /.//.env HTTP/1.1" 404 414
35.236.54.187 104.22.49.48 - - [12/Sep/2026:09:39:45 -0300] "GET /static//app/.env HTTP/1.1" 404 414
35.236.54.187 104.22.49.48 - - [12/Sep/2026:09:39:46 -0300] "GET //.env HTTP/1.1" 404 414
35.236.54.187 104.22.49.48 - - [12/Sep/2026:09:39:46 -0300] "GET /static//home/user/.env HTTP/1.1" 404 414
35.236.54.187 104.22.49.48 - - [12/Sep/2026:09:39:46 -0300] "GET /uploads../.env HTTP/1.1" 404 414
35.236.54.187 104.22.49.48 - - [12/Sep/2026:09:39:46 -0300] "GET /assets../.env HTTP/1.1" 404 414
show less
Bad Web Bot
Anonymous
2026-09-13 21:20:07
(2 days ago)
| Multiple common web attacks from same source ip. (multiple servers)
Web App Attack
Hacking
SQL Injection
Anonymous
2026-09-13 18:34:52
(2 days ago)
GET secrets.json | UA: Mozilla/5.0 (compatible; KimiBot/1.0; +https://kimi.ai/) | Time: 2026-09-13 1 ...
show more
GET secrets.json | UA: Mozilla/5.0 (compatible; KimiBot/1.0; +https://kimi.ai/) | Time: 2026-09-13 18:34:51 UTC
show less
Web App Attack
πΊπΈ
thieuleu
2026-09-13 18:32:38
(2 days ago)
Unauthorized connection attempt blocked by firewall policy. Web application hardening active.
Brute-Force
Exploited Host
π©πͺ
TheDjRider
2026-09-13 17:48:27
(2 days ago)
CrowdSec detected Web application reconnaissance. Scenario: local/framework-recon. Automatic ban tri ...
show more
CrowdSec detected Web application reconnaissance. Scenario: local/framework-recon. Automatic ban triggered. Detection time (UTC): 2026-09-13T17:48:24.603023742Z. Context: http_status=301, http_status=404
show less
Web App Attack
π«π·
demomodule
2026-09-13 17:41:28
(2 days ago)
PrestaShop Security Module: suspicious probe path detected (/.env)
Web App Attack
πΊπΈ
factor1
2026-09-13 17:41:09
(2 days ago)
CrowdSec at apollo Reports Abuse
Web App Attack
π¨π¦
polycoda
2026-09-13 17:17:26
(2 days ago)
AutoBlock: π― Vulnerability Scanner (Non Decay-Based) - π Directory Traversal (Non Decay-Based) - β E ...
show more
AutoBlock: π― Vulnerability Scanner (Non Decay-Based) - π Directory Traversal (Non Decay-Based) - β Excessive 40X Errors (Decay-Based)
show less
Hacking
Bad Web Bot
Web App Attack
πΈπͺ
vaia.cloud
2026-09-13 17:10:03
(2 days ago)
crowdsecurity/http-cve-2021-41773
Brute-Force
Web App Attack
π«π·
masterguru
2026-09-13 17:05:19
(2 days ago)
URL file extension is restricted by policy. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ ...
show more
URL file extension is restricted by policy. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. (920440-135)
show less
Hacking
πΈπ¬
anotherwatcher
2026-09-13 15:13:22
(2 days ago)
bad bot
Bad Web Bot