Anonymous
2026-06-08 09:20:50
(6 days ago)
FortiWeb WAF: 18 attacks detected. Threat Score: 12600. Types: Client Management(9), Block IP List(9 ...
show more
FortiWeb WAF: 18 attacks detected. Threat Score: 12600. Types: Client Management(9), Block IP List(9). Origin: Germany.
show less
Web App Attack
๐ฉ๐ช
Lino Project
2026-06-08 08:31:26
(6 days ago)
CrowdSec abuse IP report (host SRV-2) Scenario: crowdsecurity/http-sensitive-files
Hacking
Anonymous
2026-06-08 07:22:36
(6 days ago)
(caddyscan) Scanner path probe from 46.202.156.21 (DE/Germany/-): 5 in the last 3600 secs; Ports: *; ...
show more
(caddyscan) Scanner path probe from 46.202.156.21 (DE/Germany/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 46.202.156.21 - - [08/Jun/2026:07:22:34 +0000] "GET /new/.env HTTP/1.1"
[REDACTED] 200 2627 46.202.156.21 - - [08/Jun/2026:07:22:34 +0000] "GET /core/.env HTTP/1.1"
[REDACTED] 200 2627 46.202.156.21 - - [08/Jun/2026:07:22:34 +0000] "GET /backend/.env HTTP/1.1"
[REDACTED] 200 2627 46.202.156.21 - - [08/Jun/2026:07:22:34 +0000] "GET /dev/.env HTTP/1.1"
[REDACTED] 200 2627 46.202.156.21 - - [08/Jun/2026:07:22:34 +0000] "GET /app/.env HTTP/1.1"
show less
Port Scan
๐บ๐ธ
WellSpring
2026-06-08 06:40:45
(6 days ago)
env leak on liteehr.com/new/.env โ WellSpr.ing/NetSentinel civic-AI security layer
Web App Attack
๐ฌ๐ง
consul.to
2026-06-08 05:52:29
(6 days ago)
Web attack/malicious scanning detected
Web App Attack
Anonymous
2026-06-08 05:52:22
(6 days ago)
(caddyscan) Scanner path probe from 46.202.156.21 (DE/Germany/-): 5 in the last 3600 secs; Ports: *; ...
show more
(caddyscan) Scanner path probe from 46.202.156.21 (DE/Germany/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 46.202.156.21 - - [08/Jun/2026:05:52:19 +0000] "GET /admin/.env HTTP/1.1"
[REDACTED] 200 2627 46.202.156.21 - - [08/Jun/2026:05:52:19 +0000] "GET /app/.env HTTP/1.1"
[REDACTED] 200 2627 46.202.156.21 - - [08/Jun/2026:05:52:19 +0000] "GET /new/.env HTTP/1.1"
[REDACTED] 200 2627 46.202.156.21 - - [08/Jun/2026:05:52:19 +0000] "GET /api/.env HTTP/1.1"
[REDACTED] 200 2627 46.202.156.21 - - [08/Jun/2026:05:52:19 +0000] "GET /core/.env HTTP/1.1"
show less
Port Scan
๐บ๐ธ
rdpguard.com
2026-06-07 21:26:51
(6 days ago)
RdpGuard detected brute-force attempt on HTTP
Brute-Force
Anonymous
2026-06-07 21:21:51
(6 days ago)
(caddyscan) Scanner path probe from 46.202.156.21 (DE/Germany/-): 5 in the last 3600 secs; Ports: *; ...
show more
(caddyscan) Scanner path probe from 46.202.156.21 (DE/Germany/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 46.202.156.21 - - [07/Jun/2026:21:21:46 +0000] "GET /admin/.env HTTP/1.1"
[REDACTED] 200 2627 46.202.156.21 - - [07/Jun/2026:21:21:46 +0000] "GET /member/.env HTTP/1.1"
[REDACTED] 200 2627 46.202.156.21 - - [07/Jun/2026:21:21:46 +0000] "GET /new/.env HTTP/1.1"
[REDACTED] 200 2627 46.202.156.21 - - [07/Jun/2026:21:21:46 +0000] "GET /dev/.env HTTP/1.1"
[REDACTED] 200 2627 46.202.156.21 - - [07/Jun/2026:21:21:46 +0000] "GET /backend/.env HTTP/1.1"
show less
Port Scan
Anonymous
2026-06-07 19:35:18
(6 days ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
๐ฉ๐ช
paissangroup
2026-06-07 15:57:42
(6 days ago)
Multiple WAF Violations
Web App Attack
๐ซ๐ท
masterguru
2026-06-07 11:53:10
(1 week ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-195)
Hacking
Web App Attack
๐ฆ๐บ
paulshipley.com.au
2026-06-07 07:48:56
(1 week ago)
[Sun Jun 07 17:48:55.478602 2026] [security2:error] [pid 877064] [client 46.202.156.21:63886] [clien ...
show more
[Sun Jun 07 17:48:55.478602 2026] [security2:error] [pid 877064] [client 46.202.156.21:63886] [client 46.202.156.21] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "levellapromotions.com.au"] [uri "/.env"] [unique_id "aiUiZ1OCcO4vM9iUpKylWgAAABA"], referer: https://levellapromotions.com/.env
...
show less
Web App Attack
๐ซ๐ท
dynamix
2026-06-07 06:19:48
(1 week ago)
Multiple WAF Violations
Web App Attack
๐จ๐ฆ
lakered
2026-06-07 05:17:58
(1 week ago)
Detectors: [NGINX, CROWDSEC] | Reasons: CrowdSec: Security alert | Nginx Honeypot: Sensitive configu ...
show more
Detectors: [NGINX, CROWDSEC] | Reasons: CrowdSec: Security alert | Nginx Honeypot: Sensitive configuration file search | Tech Evidence: JA4H: 6ffaa43d4a770afc2f11ca03815de1dc, Incomplete-Browser-Profile (Missing: Accept, Accept-Encoding, Accept-Language), Fake-Chrome-Desktop (No-CH), TLS-JA4-Spoofing-Detected (UA claims Browser but JA4 reports No-HTTP/2: t13d190900), JA4: t13d190900 | UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36
show less
Web App Attack
Hacking
๐ฌ๐ง
consul.to
2026-06-07 03:40:27
(1 week ago)
Web attack/malicious scanning detected
Web App Attack