๐ฉ๐ช
Manuel Braeuer
2026-09-29 11:04:30
(29 minutes ago)
54.20.75.0 - - [29/Sep/2026:13:04:30 +0200] "GET /.htpasswd HTTP/1.1" 403 6268 "-" "Mozilla/5.0 (Win ...
show more
54.20.75.0 - - [29/Sep/2026:13:04:30 +0200] "GET /.htpasswd HTTP/1.1" 403 6268 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36 c2570bac-3656-46f6-8099-c5b6b90fb6fc"
54.20.75.0 - - [29/Sep/2026:13:04:30 +0200] "GET /.envrc HTTP/1.1" 403 6073 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36 Edg/117.0.2045.36"
54.20.75.0 - - [29/Sep/2026:13:04:30 +0200] "GET /config/env.js HTTP/1.1" 403 6073 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.2.1 Safari/605.6.16"
54.20.75.0 - - [29/Sep/2026:13:04:30 +0200] "GET /config.php HTTP/1.1" 403 6073 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36 Edg/125.0.2535.87"
54.20.75.0 - - [29/Sep/2026:13:04:30 +0200] "GET /.env.old HTTP/1.1" 403 6073 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/53
...
show less
Web App Attack
๐ฆ๐น
Shadow77
2026-09-29 10:38:00
(56 minutes ago)
54.20.75.0 - - [29/Sep/2026:12:34:07 +0200] "GET /htpasswd HTTP/1.1" 404 363 "-" "Mozilla/5.0 (Macin ...
show more
54.20.75.0 - - [29/Sep/2026:12:34:07 +0200] "GET /htpasswd HTTP/1.1" 404 363 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.3 Safari/605.1.15 XTPT/1.0"
54.20.75.0 - - [29/Sep/2026:12:34:07 +0200] "GET /.sh_history HTTP/1.1" 403 366 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_13_6) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.4 Safari/605.1.15"
54.20.75.0 - - [29/Sep/2026:12:34:07 +0200] "GET /.psql_history HTTP/1.1" 403 366 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.4.1 Safari/605.1.15 RDDocuments/7.20.4.1140"
54.
show less
Brute-Force
Web App Attack
๐น๐ท
ScchutzZ
2026-09-29 10:05:07
(1 hour ago)
Fail2Ban banฤฑ. Jail: plesk-modsecurity.
Brute-Force
๐ฉ๐ช
ger-stg-sifi1
2026-09-29 09:46:47
(1 hour ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
๐จ๐ฆ
polycoda
2026-09-29 09:11:12
(2 hours ago)
AutoBlock: ๐ฏ Vulnerability Scanner (Non Decay-Based) - โ๏ธ Configuration File Access (Non Decay-Based ...
show more
AutoBlock: ๐ฏ Vulnerability Scanner (Non Decay-Based) - โ๏ธ Configuration File Access (Non Decay-Based) - โ Excessive 40X Errors (Decay-Based)
show less
Hacking
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-29 08:27:34
(3 hours ago)
[formsbd] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[formsbd] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 54.20.75.0 - - [29/Sep/2026:10:27:24 +0200] "GET /.env.local HTTP/1.1" 301 6200 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:124.0) Gecko/20100101 Firefox/124.0"
...
show less
Bad Web Bot
Web App Attack
Anonymous
2026-09-29 07:20:48
(4 hours ago)
(mod_security) mod_security triggered on hostname [redacted])
SQL Injection
๐ต๐ฑ
Budyn
2026-09-29 06:47:41
(4 hours ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: elastic.goblinpot.tech | URI: /.env.save | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/100.0.4896.127 Safari/537.36 Edg/100.0.1185.44 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 05:19:52
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 54.20.75.0 (ec2-54-20-75-0.sa-east-1.compute.am ...
show more
(mod_security) mod_security (id:210492) triggered by 54.20.75.0 (ec2-54-20-75-0.sa-east-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 01:19:46.858527 2026] [security2:error] [pid 12837:tid 12837] [client 54.20.75.0:56948] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "randomgroovemusic.com.englishmagic.us"] [uri "/.env"] [unique_id "artKcvZGsRMux-XuKxyZRAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
sel
2026-09-29 04:28:57
(7 hours ago)
Web scanner across joetheaverageone.com: 25 suspicious requests
GET /config.php.bak 404 | GET /confi ...
show more
Web scanner across joetheaverageone.com: 25 suspicious requests
GET /config.php.bak 404 | GET /config.php.txt 404 | GET /config.php~ 404
show less
Web App Attack
Bad Web Bot
๐ธ๐ช
vaia.cloud
2026-09-29 02:50:02
(8 hours ago)
crowdsecurity/http-probing
Brute-Force
Web App Attack
๐ต๐ฑ
Budyn
2026-09-29 00:34:17
(11 hours ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: forum.astropot.tech | URI: /.env.test | UA: Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:109.0) Gecko/20100101 Firefox/114.0 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 00:00:12
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 54.20.75.0 (ec2-54-20-75-0.sa-east-1.compute.am ...
show more
(mod_security) mod_security (id:210492) triggered by 54.20.75.0 (ec2-54-20-75-0.sa-east-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 19:59:57.423359 2026] [security2:error] [pid 4753:tid 4753] [client 54.20.75.0:45018] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "marisa-mcphee.com"] [uri "/.env.production"] [unique_id "arr_fS_HfTb4p0B-5PT8-wAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Bedios GmbH
2026-09-28 23:46:35
(11 hours ago)
Keyfile theft attempt
Hacking
๐ฉ๐ช
Savvii
2026-09-28 22:27:10
(13 hours ago)
20 attempts against mh-misbehave-ban on rose
Brute-Force
Bad Web Bot
Web App Attack