๐ฉ๐ช
v1nc
2026-10-06 05:23:06
(3 hours ago)
45.138.12.90 - - [06/Oct/2026:05:23:05 +0000] "GET /.env.php HTTP/1.1" 301 162 "-" "Mozilla/5.0 (Win ...
show more
45.138.12.90 - - [06/Oct/2026:05:23:05 +0000] "GET /.env.php HTTP/1.1" 301 162 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"
...
show less
Hacking
๐บ๐ธ
wbsouza
2026-10-06 03:33:17
(4 hours ago)
CrowdSec: infra/firewall-drop-flood โ automated firewall drops on self-hosted IDS sensor
Port Scan
๐ฉ๐ช
v1nc
2026-10-06 00:38:41
(7 hours ago)
45.138.12.90 - - [06/Oct/2026:00:38:40 +0000] "GET /.env.php HTTP/1.1" 404 118 "-" "Mozilla/5.0 (Win ...
show more
45.138.12.90 - - [06/Oct/2026:00:38:40 +0000] "GET /.env.php HTTP/1.1" 404 118 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"
...
show less
Hacking
๐ง๐ท
radardatelecom
2026-10-05 22:27:03
(9 hours ago)
Blocked by Radar da Telecom firewall โ abuseipdb
Bad Web Bot
Web App Attack
๐ฉ๐ช
updown.io
2026-10-05 22:23:08
(10 hours ago)
{"level":"info","ts":1791238987.9281235,"logger":"http.log.access.log1","msg":"handled request","req ...
show more
{"level":"info","ts":1791238987.9281235,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"45.138.12.90","remote_port":"49554","client_ip":"45.138.12.90","proto":"HTTP/1.1","method":"GET","host":"status.reveles.ai","uri":"/.env.dist","headers":{"User-Agent":["Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"],"Accept-Encoding":["gzip"]},"tls":{"resumed":false,"version":772,"cipher_suite":4865,"proto":"","server_name":"status.reveles.ai","ech":false}},"bytes_read":0,"user_id":"","duration":0.000672481,"size":0,"status":429,"resp_headers":{"Server":["Caddy"],"Alt-Svc":["h3=\":443\"; ma=2592000"],"Retry-After":["1"]}}
{"level":"info","ts":1791238987.9283497,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"45.138.12.90","remote_port":"49604","client_ip":"45.138.12.90","proto":"HTTP/1.1","method":"GET","host":"status.reveles.ai","uri":"/php-info.php","headers":{"User-Agent":["Mozilla/5.0 (Windows NT 10.0; Win64; x64) Ap
...
show less
DDoS Attack
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-10-05 22:00:58
(10 hours ago)
Auto-ban: >3000 req/min op 2026-10-05
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-10-05 14:18:35
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 45.138.12.90 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 45.138.12.90 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 10:18:29.322669 2026] [security2:error] [pid 22893:tid 22893] [client 45.138.12.90:52670] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ddpsmokehouse.com"] [uri "/.env"] [unique_id "asOxtXNHvDFqRXyDF7mYegAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
ConsulHosting
2026-10-05 13:19:30
(19 hours ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 12:45:50
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 45.138.12.90 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 45.138.12.90 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 08:45:45.209088 2026] [security2:error] [pid 10651:tid 10651] [client 45.138.12.90:51622] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "daveweisman.com"] [uri "/cron/.env"] [unique_id "asOb-aMrSn3AZ0JBab0EfgAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
helios.live
2026-10-05 12:43:00
(19 hours ago)
2026/10/05 12:42:59 [error] 3750927#3750927: *5743437 access forbidden by rule, client: 45.138.12.90 ...
show more
2026/10/05 12:42:59 [error] 3750927#3750927: *5743437 access forbidden by rule, client: 45.138.12.90, server: kocerroxy.com, request: "GET /.env.example HTTP/1.1", host: "kocerroxy.com"
2026/10/05 12:42:59 [error] 3750927#3750927: *5742829 access forbidden by rule, client: 45.138.12.90, server: kocerroxy.com, request: "GET /.aws/credentials HTTP/1.1", host: "kocerroxy.com"
2026/10/05 12:42:59 [error] 3750927#3750927: *5743437 access forbidden by rule, client: 45.138.12.90, server: kocerroxy.com, request: "GET /.boto HTTP/1.1", host: "kocerroxy.com"
2026/10/05 12:42:59 [error] 3750927#3750927: *5742829 access forbidden by rule, client: 45.138.12.90, server: kocerroxy.com, request: "GET /.env.local HTTP/1.1", host: "kocerroxy.com"
2026/10/05 12:42:59 [error] 3750927#3750927: *5742829 FastCGI sent in stderr: "Primary script unknown" while reading response header from upstream, client: 45.138.12.90, server: kocerroxy.com, request: "GET /p.php HTTP/1.1", upstream: "fastcgi://unix:/var/run/p
...
show less
Web App Attack
๐ฉ๐ช
Sรฉfora Srl
2026-10-05 12:27:47
(19 hours ago)
crowdsecurity/http-probing detected by CrowdSec
Web App Attack
๐ฉ๐ช
v1nc
2026-10-05 11:55:35
(20 hours ago)
45.138.12.90 - - [05/Oct/2026:11:55:35 +0000] "GET /wp-links-opml.php HTTP/1.1" 301 162 "-" "Mozilla ...
show more
45.138.12.90 - - [05/Oct/2026:11:55:35 +0000] "GET /wp-links-opml.php HTTP/1.1" 301 162 "-" "Mozilla/5.0 (X11; Linux x86_64; rv:133.0) Gecko/20100101 Firefox/133.0"
...
show less
Hacking
๐ฌ๐ง
spamverify.com
2026-10-05 11:29:35
(20 hours ago)
Honeypot Hit: WordPress Users
Web Spam
Blog Spam
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-10-05 10:55:56
(21 hours ago)
[ti-26al] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail apac ...
show more
[ti-26al] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail apache-404. Example: 45.138.12.90 - - [05/Oct/2026:12:55:48 +0200] "GET /config/local.json HTTP/1.1" 404 6492 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"
45.138.12.90 - - [05/Oct/2026:12:55:48 +0200] "GET /vendor/.env HTTP/1.1" 404 6492 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"
45.138.12.90 - - [05/Oct/2026:12:55:48 +0200] "GET /config/credentials.yml HTTP/1.1" 404 6492 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"
45.138.12.90 - - [05/Oct/2026:12:55:48 +0200] "GET /app/.env HTTP/1.1" 404 717 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"
45.138.12.90 - - [05/Oct/2026:12:55:48 +0200] "GET /sitemaps/.
...
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-10-05 10:34:18
(21 hours ago)
[ti-01ov] Web exploit scanning: 1 suspicious requests detected by fail2ban jail <name>. Example: 45. ...
show more
[ti-01ov] Web exploit scanning: 1 suspicious requests detected by fail2ban jail <name>. Example: 45.138.12.90 - - \[05/Oct/2026:12:33:59 +0200\] "GET / HTTP/1.1" 200 7244 "https://tarnmilitaria.nl/docs/.env" "Mozilla/5.0 \(Windows NT 10.0\; Win64\; x64\) AppleWebKit/537.36"
...
show less
Bad Web Bot
Web App Attack