🇩🇪
cloudmax
2026-09-09 08:05:59
(2 hours ago)
Cloudmax IPS Block - Suspicious activity. Possible port scanning, service reconnaissance, or vulnera ...
show more
Cloudmax IPS Block - Suspicious activity. Possible port scanning, service reconnaissance, or vulnerability probing
show less
Port Scan
🇩🇪
McClay
2026-09-09 01:29:09
(9 hours ago)
HTTP-404 spam:43.204.215.155 - - [09/Sep/2026:03:29:01 +0200] "GET /000000006aa6c68e-argus404probe H ...
show more
HTTP-404 spam:43.204.215.155 - - [09/Sep/2026:03:29:01 +0200] "GET /000000006aa6c68e-argus404probe HTTP/1.1" 404 5008 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.4.1 Safari/605.1.15"
43.204.215.155 - - [09/Sep/2026:03:29:01 +0200] "GET /.env HTTP/1.1" 404 5008 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.4.1 Safari/605.1.15"
43.204.215.155 - - [09/Sep/2026:03:29:02 +0200] "GET /.env.local HTTP/1.1" 404 5008 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.4.1 Safari/605.1.15"
43.204.215.155 - - [09/Sep/2026:03:29:02 +0200] "GET /.env.production HTTP/1.1" 404 5009 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.4.1 Safari/605.1.15"
43.204.215.155 - - [09/Sep/2026:03:29:03 +0200] "GET /.env.prod HTTP/1.1" 404 5008 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) Apple
...
show less
Web App Attack
🇩🇪
BlueWire Hosting
2026-09-09 00:07:42
(10 hours ago)
High-confidence malicious configuration/VCS probe
Web App Attack
🇩🇪
AetherFox
2026-09-08 19:09:51
(15 hours ago)
AetherFox VoidGuard detected: [Tue Sep 08 19:09:50.008562 2026] [authz_core:error] [pid 1230301:tid ...
show more
AetherFox VoidGuard detected: [Tue Sep 08 19:09:50.008562 2026] [authz_core:error] [pid 1230301:tid 1230347] [client 43.204.215.155:51356] AH01630: client denied by server configuration: proxy:https://freebeegee.draconigen.de/
[Tue Sep 08 19:09:50.008858 2026] [authz_core:error] [pid 1230301:tid 1230347] [client 43.204.215.155:51356] AH01630: client denied by server configuration: /var/www/html/ERRORpages/403.html
[Tue Sep 08 19:09:50.840555 2026] [authz_core:error] [pid 1230301:tid 1230340] [client 43.204.215.155:51372] AH01630: client denied by server configuration: proxy:https://freebeegee.draconigen.de/000000006aa59468-argus404probe
[Tue Sep 08 19:09:50.840780 2026] [authz_core:error] [pid 1230301:tid 1230340] [client 43.204.215.155:51372] AH01630: client denied by server configuration: /var/www/html/ERRORpages/403.html
[Tue Sep 08 19:09:51.402576 2026] [authz_core:error] [pid 1230301:tid 1230353] [client 43.204.215.155:51388] AH01630: client denied by server co
...
show less
Bad Web Bot
Web App Attack
🇩🇪
Melle
2026-09-08 18:58:48
(15 hours ago)
Blocked by CrowdSec | Scenario: crowdsecurity/http-sensitive-files | 43.204.215.155 triggered 5 even ...
show more
Blocked by CrowdSec | Scenario: crowdsecurity/http-sensitive-files | 43.204.215.155 triggered 5 events | Detected: 2026-09-08T18:58:44.810547578Z
show less
Web App Attack
Hacking
🇩🇪
Bedios GmbH
2026-09-08 18:58:45
(15 hours ago)
Login credentials theft attempt
Hacking
🇨🇦
internetworld
2026-09-06 16:43:04
(2 days ago)
43.204.215.155 - - [06/Sep/2026:16:43:03 +0000] "GET /.env HTTP/1.1" 200 513 "-" "Mozilla/5.0 (compa ...
show more
43.204.215.155 - - [06/Sep/2026:16:43:03 +0000] "GET /.env HTTP/1.1" 200 513 "-" "Mozilla/5.0 (compatible; ArgusScanner/0.1; +http://example/abuse)"
...
show less
Bad Web Bot
Web App Attack
🇺🇸
LotPhantom
2026-09-06 16:35:14
(2 days ago)
2026-09-06T16:35:14.140251+00:00 bridginggaps kernel: [UFW BLOCK] IN=eth0 OUT= MAC=2e:bc:64:1d:2c:e1 ...
show more
2026-09-06T16:35:14.140251+00:00 bridginggaps kernel: [UFW BLOCK] IN=eth0 OUT= MAC=2e:bc:64:1d:2c:e1:fe:00:00:00:01:01:08:00 SRC=43.204.215.155 DST=157.230.217.55 LEN=60 TOS=0x00 PREC=0x00 TTL=54 ID=1199 DF PROTO=TCP SPT=60418 DPT=8080 WINDOW=64240 RES=0x00 SYN URGP=0
2026-09-06T16:35:14.140314+00:00 bridginggaps kernel: [UFW BLOCK] IN=eth0 OUT= MAC=2e:bc:64:1d:2c:e1:fe:00:00:00:01:01:08:00 SRC=43.204.215.155 DST=157.230.217.55 LEN=60 TOS=0x00 PREC=0x00 TTL=54 ID=30330 DF PROTO=TCP SPT=36078 DPT=8000 WINDOW=64240 RES=0x00 SYN URGP=0
...
show less
Port Scan
Hacking
🇩🇪
Blexyel
2026-09-06 16:12:27
(2 days ago)
43.204.215.155 - - [06/Sep/2026:18:12:26 +0200] "GET /.git/config HTTP/1.1" 200 264 "-" "Mozilla/5.0 ...
show more
43.204.215.155 - - [06/Sep/2026:18:12:26 +0200] "GET /.git/config HTTP/1.1" 200 264 "-" "Mozilla/5.0 (compatible; ArgusScanner/0.1; +http://example/abuse)"
...
show less
Brute-Force
Web App Attack
🇺🇸
ratcarcher-labs
2026-09-06 15:25:56
(2 days ago)
[Ratcarcher Labs/MutantShield honeypot CTI] actor=human vector=bot_scanner risk=75 attacks=11 depth= ...
show more
[Ratcarcher Labs/MutantShield honeypot CTI] actor=human vector=bot_scanner risk=75 attacks=11 depth=3 node=node-us-east canary=no human_score=50 agentic=15 cc=IN asn=Amazon.com, Inc. | Data provided by Ratcarcher Labs · https://ratcarcher-labs.com · docs https://api.ratcarcher-labs.com/api/v1/public/docs
show less
Port Scan
Bad Web Bot
🇩🇪
_ArminS_
2026-09-06 11:22:38
(2 days ago)
SP-Scan 33774:8000 detected 2026.09.06 13:22:38
blocked until 2026.10.26 05:25:25
Port Scan
Anonymous
2026-09-06 10:42:09
(2 days ago)
[ns3.backorder.gr] httpd-config-scan: logs=/var/log/httpd/access_log; samples=/.env | /.git/config | ...
show more
[ns3.backorder.gr] httpd-config-scan: logs=/var/log/httpd/access_log; samples=/.env | /.git/config | /.git/HEAD
show less
Hacking
Web App Attack
🇨🇭
GAS
2026-09-06 10:01:09
(3 days ago)
Bad Bot.
43.204.215.155 - - [06/Sep/2026:12:01:08 +0200] "GET /.git/config HTTP/1.1" 402 4865 "-" "M ...
show more
Bad Bot.
43.204.215.155 - - [06/Sep/2026:12:01:08 +0200] "GET /.git/config HTTP/1.1" 402 4865 "-" "Mozilla/5.0 (compatible; ArgusScanner/0.1; +http://example/abuse)" "REDACTED" ""
...
show less
Bad Web Bot
Web App Attack
🇩🇪
Hary74656
2026-09-06 09:41:24
(3 days ago)
Fail2Ban on schani.hostmi.at: jail=apache-modsecurity, failures=3. No raw log data included.
Web App Attack
Anonymous
2026-09-05 20:51:52
(3 days ago)
Malicious Probing
Bad Web Bot