๐ฎ๐ฑ
spd.co.il
2026-08-25 05:02:15
(3 days ago)
Web application attack detected
Hacking
Web App Attack
๐ฎ๐ฉ
Burayot
2026-08-24 21:31:22
(3 days ago)
LF_APACHE_403: 79.110.49.145 (FR/France/-), more than 30 Apache 403 hits in the last 3600 secs
Web App Attack
๐ฉ๐ช
hidemail.app
2026-08-24 20:09:43
(3 days ago)
Automated scan for exposed config/secret files and known web exploits (e.g. /.env, RCE probes); auto ...
show more
Automated scan for exposed config/secret files and known web exploits (e.g. /.env, RCE probes); auto-banned by fail2ban.
show less
Web App Attack
Hacking
๐ซ๐ท
MatStef132
2026-08-24 18:54:08
(4 days ago)
MatShield L7: blocked on ptero.mathost.eu (secret-path-probe)
DDoS Attack
๐ซ๐ท
Baking333
2026-08-24 18:33:34
(4 days ago)
[redacted] 79.110.49.145 - - [24/Aug/2026:19:33:32 +0100] "GET /.aws/credentials HTTP/1.1" 302 6773 ...
show more
[redacted] 79.110.49.145 - - [24/Aug/2026:19:33:32 +0100] "GET /.aws/credentials HTTP/1.1" 302 6773 0/34055 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" [redacted] 79.110.49.145 - - [24/Aug/2026:19:33:32 +0100] "GET /.c9/metadata/environment/.env HTTP/1.1" 302 6773 0/48159 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
H24
2026-08-24 18:16:38
(4 days ago)
/.env~ /.c9/metadata/environment/.env /.docker/laravel/app/.env /.docker/.env /.aws/credentials /.en ...
show more
/.env~ /.c9/metadata/environment/.env /.docker/laravel/app/.env /.docker/.env /.aws/credentials /.env /.env.bak
show less
Web App Attack
๐ซ๐ท
Baking333
2026-08-24 15:08:36
(4 days ago)
[redacted] 79.110.49.145 - - [24/Aug/2026:16:08:34 +0100] "GET /.aws/credentials HTTP/1.1" 302 1528 ...
show more
[redacted] 79.110.49.145 - - [24/Aug/2026:16:08:34 +0100] "GET /.aws/credentials HTTP/1.1" 302 1528 0/46020 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" [redacted] 79.110.49.145 - - [24/Aug/2026:16:08:34 +0100] "GET /.c9/metadata/environment/.env HTTP/1.1" 302 1527 0/35133 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-08-24 13:19:34
(4 days ago)
Excessive multi-domain requests
Brute-Force
๐ซ๐ท
Baking333
2026-08-24 10:58:26
(4 days ago)
[redacted] 79.110.49.145 - - [24/Aug/2026:11:58:24 +0100] "GET /.aws/credentials HTTP/1.1" 302 6778 ...
show more
[redacted] 79.110.49.145 - - [24/Aug/2026:11:58:24 +0100] "GET /.aws/credentials HTTP/1.1" 302 6778 0/71900 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" [redacted] 79.110.49.145 - - [24/Aug/2026:11:58:24 +0100] "GET /.c9/metadata/environment/.env HTTP/1.1" 302 6778 0/77228 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
MusicLibrary
2026-08-24 09:37:14
(4 days ago)
Probing foreign-stack admin panels / known exploit paths (Joomla, phpMyAdmin, phpunit, OWA, etc.)
Bad Web Bot
Web App Attack
๐ซ๐ท
Catalin Negru
2026-08-24 09:25:38
(4 days ago)
Recidive ban by fail2ban on server.blackbit.ro
Brute-Force
๐ซ๐ท
Baking333
2026-08-24 08:16:43
(4 days ago)
[redacted] 79.110.49.145 - - [24/Aug/2026:09:16:40 +0100] "GET /.aws/credentials HTTP/1.1" 302 6753 ...
show more
[redacted] 79.110.49.145 - - [24/Aug/2026:09:16:40 +0100] "GET /.aws/credentials HTTP/1.1" 302 6753 0/52227 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" [redacted] 79.110.49.145 - - [24/Aug/2026:09:16:41 +0100] "GET /.c9/metadata/environment/.env HTTP/1.1" 302 6753 0/39277 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" [redacted] 79.110.49.145 - - [24/Aug/2026:09:16:41 +0100] "GET /.docker/.env HTTP/1.1" 302 1534 0/72087 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-24 06:42:17
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 79.110.49.145 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 79.110.49.145 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 02:42:13.163982 2026] [security2:error] [pid 8733:tid 8733] [client 79.110.49.145:53798] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wallawallafirearmstraining.com"] [uri "/wp-config.php.bak"] [unique_id "aovnxfinjux54I9evuoEJwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
helios.live
2026-08-24 05:04:03
(4 days ago)
2026/08/24 05:03:58 [error] 1924870#1924870: *833777 access forbidden by rule, client: 79.110.49.145 ...
show more
2026/08/24 05:03:58 [error] 1924870#1924870: *833777 access forbidden by rule, client: 79.110.49.145, server: kocerroxy.com, request: "GET /.aws/credentials HTTP/1.1", host: "kocerroxy.com"
2026/08/24 05:04:01 [error] 1924870#1924870: *833777 access forbidden by rule, client: 79.110.49.145, server: kocerroxy.com, request: "GET /.env-bak HTTP/1.1", host: "kocerroxy.com"
2026/08/24 05:04:01 [error] 1924870#1924870: *833777 access forbidden by rule, client: 79.110.49.145, server: kocerroxy.com, request: "GET /.env.1 HTTP/1.1", host: "kocerroxy.com"
2026/08/24 05:04:02 [error] 1924870#1924870: *833777 access forbidden by rule, client: 79.110.49.145, server: kocerroxy.com, request: "GET /.env.2023 HTTP/1.1", host: "kocerroxy.com"
2026/08/24 05:04:03 [error] 1924870#1924870: *833777 access forbidden by rule, client: 79.110.49.145, server: kocerroxy.com, request: "GET /.env.2024 HTTP/1.1", host: "kocerroxy.com"
...
show less
Web App Attack
๐ซ๐ท
Baking333
2026-08-24 04:51:55
(4 days ago)
[redacted] 79.110.49.145 - - [24/Aug/2026:05:51:52 +0100] "GET /.aws/credentials HTTP/1.1" 302 1528 ...
show more
[redacted] 79.110.49.145 - - [24/Aug/2026:05:51:52 +0100] "GET /.aws/credentials HTTP/1.1" 302 1528 0/61539 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" [redacted] 79.110.49.145 - - [24/Aug/2026:05:51:53 +0100] "GET /.c9/metadata/environment/.env HTTP/1.1" 302 1528 0/153002 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
show less
Bad Web Bot
Web App Attack