Anonymous
2026-05-19 17:20:32
(2 weeks ago)
45.135.193.157 - [19/May/2026:10:20:30 -0700] 67.190.132.171 "GET /.env HTTP/1.1" 404 3202
45.135.19 ...
show more
45.135.193.157 - [19/May/2026:10:20:30 -0700] 67.190.132.171 "GET /.env HTTP/1.1" 404 3202
45.135.193.157 - [19/May/2026:10:20:31 -0700] 67.190.132.171 "GET /backend/.env HTTP/1.1" 404 542
45.135.193.157 - [19/May/2026:10:20:31 -0700] 67.190.132.171 "GET /phpinfo.php HTTP/1.1" 404 541
45.135.193.157 - [19/May/2026:10:20:31 -0700] 67.190.132.171 "GET /phpinfo/ HTTP/1.1" 404 538
45.135.193.157 - [19/May/2026:10:20:32 -0700] 67.190.132.171 "GET /admin/.env HTTP/1.1" 404 540
...
show less
Web App Attack
🇳🇱
BellFix
2026-05-19 16:18:44
(2 weeks ago)
Fail2ban reported 45.135.193.157 for npm-docker
Web App Attack
🇺🇸
uchat-ai.com
2026-05-19 15:58:12
(2 weeks ago)
IP 45.135.193.157 在过去24小时内进行了 2 次攻击。详细信息: 攻击类型: Restricted File Access Attempt, 攻击信息: Matched Data: ...
show more
IP 45.135.193.157 在过去24小时内进行了 2 次攻击。详细信息: 攻击类型: Restricted File Access Attempt, 攻击信息: Matched Data: /.env found within REQUEST_FILENAME: /backend/.env"] (Severity: 2); 攻击类型: Restricted File Access Attempt, 攻击信息: Matched Data: /.env found within REQUEST_FILENAME: /.env"] (Severity: 2)
show less
Web App Attack
🇫🇮
habs
2026-05-19 15:49:29
(2 weeks ago)
45.135.193.157 - - [19/May/2026:18:49:28 +0300] "GET /cgi-bin/.env HTTP/1.1" 200 1345 "-" "Mozilla/5 ...
show more
45.135.193.157 - - [19/May/2026:18:49:28 +0300] "GET /cgi-bin/.env HTTP/1.1" 200 1345 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.22 (KHTML, like Gecko) Chrome/25.0.1364.97 Safari/537.22"
...
show less
Web App Attack
🇩🇪
Holger
2026-05-19 15:47:35
(2 weeks ago)
URL probing: GET /.env
Web App Attack
🇦🇺
KevinNeale
2026-05-19 15:16:24
(2 weeks ago)
45.135.193.157 - - [20/May/2026:01:16:24 +1000] "GET /.env HTTP/1.1" 404 492 "-" "Mozilla/5.0 (Windo ...
show more
45.135.193.157 - - [20/May/2026:01:16:24 +1000] "GET /.env HTTP/1.1" 404 492 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.101 Safari/537.36"
...
show less
Brute-Force
Web App Attack
🇯🇵
www.winos.me
2026-05-19 15:15:13
(2 weeks ago)
Shield: Layer4 Port 9 Trap
Port Scan
Hacking
🇬🇧
seniorlinuxadmin
2026-05-19 15:15:03
(2 weeks ago)
45.135.193.157 - - [19/May/2026:16:15:01 +0100] "GET /.env HTTP/1.1" 403 158 "-" "Opera/9.21 (X11; L ...
show more
45.135.193.157 - - [19/May/2026:16:15:01 +0100] "GET /.env HTTP/1.1" 403 158 "-" "Opera/9.21 (X11; Linux x86_64; U; en)"
show less
Port Scan
Web App Attack
🇩🇪
mr.joecat
2026-05-19 15:14:41
(2 weeks ago)
45.135.193.157 - - [19/May/2026:17:14:39 +0200] "GET /.env HTTP/1.1" 404 153 "-" "More Firefox 1.5.0 ...
show more
45.135.193.157 - - [19/May/2026:17:14:39 +0200] "GET /.env HTTP/1.1" 404 153 "-" "More Firefox 1.5.0.7 user agents strings -->>"
45.135.193.157 - - [19/May/2026:17:14:39 +0200] "GET /api/.env HTTP/1.1" 404 153 "-" "More Firefox 1.5.0.7 user agents strings -->>"
45.135.193.157 - - [19/May/2026:17:14:39 +0200] "GET /backend/.env HTTP/1.1" 404 153 "-" "More Firefox 1.5.0.7 user agents strings -->>"
45.135.193.157 - - [19/May/2026:17:14:39 +0200] "GET /phpinfo.php HTTP/1.1" 404 153 "-" "More Firefox 1.5.0.7 user agents strings -->>"
45.135.193.157 - - [19/May/2026:17:14:39 +0200] "GET /phpinfo/ HTTP/1.1" 404 153 "-" "More Firefox 1.5.0.7 user agents strings -->>"
...
show less
Web App Attack
Anonymous
2026-05-19 15:14:02
(2 weeks ago)
This IP was detected by CrowdSec triggering local/abuseipdb-watchlist
Port Scan
🇺🇸
netllama
2026-05-19 15:10:18
(2 weeks ago)
[Tue May 19 08:10:15.262565 2026] [proxy_fcgi:error] [pid 792148:tid 792208] [client 45.135.193.157: ...
show more
[Tue May 19 08:10:15.262565 2026] [proxy_fcgi:error] [pid 792148:tid 792208] [client 45.135.193.157:47312] AH01071: Got error 'Primary script unknown'
[Tue May 19 08:10:17.503593 2026] [proxy_fcgi:error] [pid 792148:tid 792208] [client 45.135.193.157:47312] AH01071: Got error 'Primary script unknown'
...
show less
Hacking
Web App Attack
🇳🇱
tmiland
2026-05-19 15:08:28
(2 weeks ago)
(nginx_404) Dot directory Honeypot Trap 45.135.193.157 (DE/Germany/45.135.193.157.ptr.pfcloud.networ ...
show more
(nginx_404) Dot directory Honeypot Trap 45.135.193.157 (DE/Germany/45.135.193.157.ptr.pfcloud.network): 2 in the last 3600 secs; IP: 45.135.193.157; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 45.135.193.157 - - [19/May/2026:17:08:23 +0200] "GET /.env HTTP/1.1" 404 2992 "-" "Mozilla/5.0 (Linux; U; Android 4.2.2; en-us; RCT6691W3 Build/JDQ39) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 Safari/534.30" 45.135.193.157 - - [19/May/2026:17:08:23 +0200] "GET /.env.example HTTP/1.1" 404 2992 "-" "Mozilla/5.0 (Linux; U; Android 4.2.2; en-us; RCT6691W3 Build/JDQ39) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 Safari/534.30"
show less
Brute-Force
🇳🇱
JCB
2026-05-19 14:48:00
(2 weeks ago)
45.135.193.157 - - [19/May/2026:11:01:12 +0300] "GET /config/.env HTTP/1.1" 403 239
45.135.193.157 ...
show more
45.135.193.157 - - [19/May/2026:11:01:12 +0300] "GET /config/.env HTTP/1.1" 403 239
45.135.193.157 - - [19/May/2026:11:01:12 +0300] "GET /bot/.env HTTP/1.1" 403 239
...
show less
Web App Attack
Hacking
🇬🇧
knock
2026-05-19 14:41:03
(2 weeks ago)
Knock-Knock honeypot brute-force: proto8 (204 total hits)
Brute-Force
🇩🇪
tg_de
2026-05-19 13:53:52
(2 weeks ago)
270 attempts since 12.05.2026 18:16:21 CEST - last search for: /docker/app/.env
Web App Attack