๐ณ๐ฑ
Alt255
2026-10-08 22:07:19
(5 hours ago)
[cb-07al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[cb-07al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 45.132.227.199 - - [09/Oct/2026:00:07:16 +0200] "GET /.env.prod HTTP/1.1" 404 7847 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/106.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
๐ซ๐ฎ
Kimmo Rieskaniemi
2026-10-08 21:22:19
(6 hours ago)
CrowdSec triggered crowdsecurity/http-admin-interface-probing
Web App Attack
Hacking
๐ซ๐ท
Baking333
2026-10-08 14:42:28
(13 hours ago)
[redacted] 45.132.227.199 - - [08/Oct/2026:15:42:14 +0100] "GET /enviroments/.env HTTP/1.1" 307 423 ...
show more
[redacted] 45.132.227.199 - - [08/Oct/2026:15:42:14 +0100] "GET /enviroments/.env HTTP/1.1" 307 423 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/106.0.0.0 Safari/537.36" [redacted] 45.132.227.199 - - [08/Oct/2026:15:42:26 +0100] "GET /[redacted] HTTP/1.1" 307 396 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:105.0) Gecko/20100101 Firefox/105.0"
show less
Bad Web Bot
Web App Attack
๐ซ๐ท
Batz
2026-10-08 12:16:03
(15 hours ago)
Automated Web Bot hunting for hidden .env / AI API Credentials
Port Scan
Bad Web Bot
Web App Attack
๐ธ๐ช
SkyDancer
2026-10-08 09:35:02
(18 hours ago)
Multiple unauthorized attempts to access using wrong credentials. Attack automatically blocked by Sk ...
show more
Multiple unauthorized attempts to access using wrong credentials. Attack automatically blocked by SkyDancer Ai. EXT-SYS-Vx
show less
Hacking
Brute-Force
SSH
๐ซ๐ท
Kejult
2026-10-08 07:01:36
(21 hours ago)
Honeypot Finding: repeated TCP service probing on TCP/80 (HTTP); 4 application-level events across 4 ...
show more
Honeypot Finding: repeated TCP service probing on TCP/80 (HTTP); 4 application-level events across 4 source port(s). Sensor(s): Tanner.
show less
Port Scan
๐ฎ๐น
VHosting
2026-10-08 06:25:04
(21 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-10-07 21:29:04
(1 day ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 1247
Exploited Host
Web App Attack
๐น๐ท
oalver
2026-09-16 01:06:55
(3 weeks ago)
Detected by SiberKapan threat intelligence platform (siberkapan.org). Attack types: nginx_path_signa ...
show more
Detected by SiberKapan threat intelligence platform (siberkapan.org). Attack types: nginx_path_signature. Sources: nginx. Details: path_signature: request to /www/.env (HTTP 301); path_signature: request to /wp-login.php (HTTP 200). First seen: 2026-08-25. Risk score: 90/100.
show less
Web App Attack
๐ฎ๐น
CoreTech srl
2026-09-08 15:53:58
(1 month ago)
cloudlinux2 fail2ban: 2026-09-08 17:49:05,948 fail2ban.filter [1794]: INFO [plesk-proftpd ...
show more
cloudlinux2 fail2ban: 2026-09-08 17:49:05,948 fail2ban.filter [1794]: INFO [plesk-proftpd] Found 213.144.214.240 - 2026-09-08 17:49:05cloudlinux2 fail2ban: 2026-09-08 17:49:10,250 fail2ban.filter [1794]: INFO [plesk-wordpress] Found 216.24.212.191 - 2026-09-08 17:49:10cloudlinux2 fail2ban: 2026-09-08 17:49:19,601 fail2ban.filter [1794]: INFO [plesk-proftpd] Found 212.68.34.90 - 2026-09-08 17:49:19cloudlinux2 fail2ban: 2026-09-08 17:49:50,381 fail2ban.filter [1794]: INFO [plesk-wordpress] Found 45.146.55.91 - 2026-09-08 17:49:49cloudlinux2 fail2ban: 2026-09-08 17:50:20,260 fail2ban.filter [1794]: INFO [plesk-wordpress] Found 155.2.215.51 - 2026-09-08 17:50:19cloudlinux2 fail2ban: 2026-09-08 17:51:03,913 fail2ban.filter [1794]: INFO [plesk-wordpress] Found 90.50.223.98 - 2026-09-08 17:51:03cloudlinux2 fail2ban: 2026-09-08 17:50:57,714 fail2ban.filter [1794]: INFO [plesk-wordpress] Found 45.132.227.199 - 2026-09-08 17:50:57cloudlinux2 f
show less
FTP Brute-Force
Web App Attack
๐ซ๐ฎ
geot
2026-08-26 13:03:45
(1 month ago)
GET /wp-admin/.env HTTP/1.1
GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
Hacking
Web App Attack
๐น๐ท
oalver
2026-08-25 21:14:12
(1 month ago)
Detected by SiberKapan threat intelligence platform (siberkapan.org). Attack types: nginx_path_signa ...
show more
Detected by SiberKapan threat intelligence platform (siberkapan.org). Attack types: nginx_path_signature. Sources: nginx. Details: path_signature: request to /www/.env (HTTP 301). First seen: 2026-08-25. Risk score: 30/100.
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-25 11:43:45
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 45.132.227.199 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 45.132.227.199 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 07:43:34.858058 2026] [security2:error] [pid 20988:tid 20988] [client 45.132.227.199:34507] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.122"] [uri "/old/.env"] [unique_id "ao1_5rCg5__NWLvuVc5tQwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-22 06:01:55
(1 month ago)
Fail2Ban - Wordpress brute-force
...
Brute-Force
Web App Attack
๐บ๐ธ
lostswordfish.com
2026-08-21 17:58:04
(1 month ago)
Wordfence waf block on registrymatters
Web App Attack