Anonymous
2025-03-21 09:47:55
(6 minutes ago)
Scenario: crowdsecurity/http-sensitive-files
Web App Attack
LotPhantom
2025-03-21 09:39:30
(15 minutes ago)
78.153.140.177 - - [21/Mar/2025:09:38:29 +0000] "GET /.env HTTP/1.1" 404 146 "-" "Mozilla/5.0 (Macin ... show more 78.153.140.177 - - [21/Mar/2025:09:38:29 +0000] "GET /.env HTTP/1.1" 404 146 "-" "Mozilla/5.0 (Macintosh; U; PPC Mac OS X 10_4_11; ja-jp) AppleWebKit/533.16 (KHTML, like Gecko) Version/4.1 Safari/533.16" "0"
... show less
Web App Attack
dwmp
2025-03-21 09:09:09
(45 minutes ago)
[21/Mar/2025:10:09:06.878895 +0100] Z90sspMqC6mH@ID632QE7wAAAAE 78.153.140.177 41320 38.242.227.117 ... show more [21/Mar/2025:10:09:06.878895 +0100] Z90sspMqC6mH@ID632QE7wAAAAE 78.153.140.177 41320 38.242.227.117 7080
[21/Mar/2025:10:09:07.312577 +0100] Z90ss5MqC6mH@ID632QE8AAAAAI 78.153.140.177 41322 38.242.227.117 7080
[21/Mar/2025:10:09:08.598384 +0100] Z90stJMqC6mH@ID632QE8QAAAAo 78.153.140.177 41328 38.242.227.117 7080
... show less
Brute-Force
SSH
Anonymous
2025-03-21 09:08:08
(46 minutes ago)
[20/Mar/2025:07:01:16 -0400] - [20/Mar/2025:07:01:54 -0400] General direct-IP acc.
Hacking
sid3windr
2025-03-21 08:58:21
(56 minutes ago)
GET /.env (Tarpitted for 20m10s, wasted 71.02kB)
Web App Attack
JCB
2025-03-21 08:57:00
(57 minutes ago)
78.153.140.177 - - [21/Mar/2025:10:52:16 +0200] "GET /.env HTTP/1.1" 404 196 "-" "Mozilla/5.0 (Windo ... show more 78.153.140.177 - - [21/Mar/2025:10:52:16 +0200] "GET /.env HTTP/1.1" 404 196 "-" "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/54.0.2840.71 Safari/537.36"
78.153.140.177 - - [21/Mar/2025:10:52:16 +0200] "\x16\x03\x01" 400 226 "-" "-"
... show less
Hacking
Web App Attack
Anonymous
2025-03-21 07:13:31
(2 hours ago)
Ports: 80,443; Direction: 0; Trigger: LF_MODSEC
Brute-Force
SSH
RCS
2025-03-21 07:06:53
(2 hours ago)
fail2ban apache-modsecurity
...
Bad Web Bot
Web App Attack
ipblock.com
2025-03-21 06:22:00
(3 hours ago)
IPBlock protected site ID [3192-af][s=02].
Exploit request, vulnerability scanner.
Hacking
Bad Web Bot
Web App Attack
boxed-it
2025-03-21 05:05:47
(4 hours ago)
GET /.env (Tarpitted for 2m10s, wasted 7.73kB)
Web App Attack
subnetprotocol
2025-03-21 04:44:58
(5 hours ago)
21/Mar/2025:05:44:54.925414 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client ... show more 21/Mar/2025:05:44:54.925414 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 78.153.140.177] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "125"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.7"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "51.159.22.164"] [uri "/.env"] [unique_id "Z9zuxuVsU0XLW_qxtH5WhQAACAo"]
21/Mar/2025:05:44:55.164150 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 78.153.140.177] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-930-APPLICATION-AT
... show less
Hacking
Web App Attack
service Informatique
2025-03-21 04:00:37
(5 hours ago)
GET /crm/.env
Web App Attack
stypr
2025-03-21 03:23:10
(6 hours ago)
Malicious activity detected on HTTP/HTTPS
Hacking
Brute-Force
Web App Attack
Mendip_Defender
2025-03-21 03:04:30
(6 hours ago)
[21/Mar/2025:03:04:26.519737 +0000] Z9zXOjYqhH1TZnPGPRI5PQAAAFg 78.153.140.177 56504 188.246.206.60 ... show more [21/Mar/2025:03:04:26.519737 +0000] Z9zXOjYqhH1TZnPGPRI5PQAAAFg 78.153.140.177 56504 188.246.206.60 7080
[21/Mar/2025:03:04:26.936575 +0000] Z9zXOmycDfAeMecEdpjV1QAAAA4 78.153.140.177 56518 188.246.206.60 7080
... show less
Brute-Force
Anonymous
2025-03-21 01:38:12
(8 hours ago)
[Fri Mar 21 02:38:11.096998 2025] [authz_core:error] [pid 30076] [client 78.153.140.177:59326] AH016 ... show more [Fri Mar 21 02:38:11.096998 2025] [authz_core:error] [pid 30076] [client 78.153.140.177:59326] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Fri Mar 21 02:38:11.202092 2025] [authz_core:error] [pid 30477] [client 78.153.140.177:34172] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Fri Mar 21 02:38:11.304321 2025] [authz_core:error] [pid 30886] [client 78.153.140.177:37226] AH01630: client denied by server configuration: /etc/httpd/htdocs
... show less
Web App Attack