Automated secrets-harvesting scan against public API host.
2026-09-04 13:15:44 UTC - ~22 requests ...
show moreAutomated secrets-harvesting scan against public API host.
2026-09-04 13:15:44 UTC - ~22 requests in <100ms
Source: 34.62.9.68 (nginx $remote_addr, direct-to-origin, no CDN)
User-Agent: crusader-worker/1.0 - all responses 404
Paths: /.env plus .production .local .prod .dev .backup .bak .old
.save .example, /env, /wp-config.php~ .bak .swp,
/storage/logs/laravel.log, /_ignition/health-check (CVE-2021-3129),
/actuator/env, /actuator/configprops, /crusader-404-probe (soft-404
baseline calibration).
Sent to the server IP directly, no hostname, no referer, no prior
session. Framework-agnostic wordlist hitting Laravel, WordPress and
Spring Boot credential files and debug endpoints simultaneously -
opportunistic scanning. No content disclosed.
show less
Unsolicited HTTP reconnaissance against public-facing API host.
2026-09-04 12:56:32 UTC
Source ...
show moreUnsolicited HTTP reconnaissance against public-facing API host.
2026-09-04 12:56:32 UTC
Source: 45.135.193.198:51854
Request: GET / HTTP/1.0
User-Agent: 0day
Response: 200
Request was made directly to the server IP rather than any hostname,
indicating indiscriminate IP-range scanning / service fingerprinting
rather than legitimate traffic. Declared User-Agent "0day" is not a
recognised crawler and appears deliberately chosen; no robots.txt
fetch, no referer, no subsequent legitimate session.
Same source also generated malformed traffic logged by the server as
"Invalid HTTP request received" (non-HTTP bytes to an HTTP port),
consistent with multi-protocol probing.
No exploitation attempt observed in this event. Reporting as scanning
/ bad bot activity for correlation purposes.
show less
Sample log lines:
May 11 14:22:32 vps-0caa7a4f sshd-session[2943870]: pam_unix(sshd:auth): auth ...
show moreSample log lines:
May 11 14:22:32 vps-0caa7a4f sshd-session[2943870]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=85.111.68.99
May 11 14:22:34 vps-0caa7a4f sshd-session[2943870]: Failed password for invalid user admin from 85.111.68.99 port 44194 ssh2
May 11 14:22:34 vps-0caa7a4f sshd-session[2943870]: Connection closed by invalid user admin 85.111.68.99 port 44194 [preauth]
May 11 14:27:57 vps-0caa7a4f sshd-session[2945210]: Invalid user admin from 85.111.68.99 port 55962
May 11 14:27:57 vps-0caa7a4f sshd-session[2945210]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=85.111.68.99
show less
Sample log lines:
May 11 14:32:24 vps-0caa7a4f sshd-session[2946386]: pam_unix(sshd:auth): auth ...
show moreSample log lines:
May 11 14:32:24 vps-0caa7a4f sshd-session[2946386]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=195.178.110.30
May 11 14:32:26 vps-0caa7a4f sshd-session[2946386]: Failed password for invalid user solana from 195.178.110.30 port 43876 ssh2
May 11 14:32:26 vps-0caa7a4f sshd-session[2946386]: Connection closed by invalid user solana 195.178.110.30 port 43876 [preauth]
May 11 14:34:45 vps-0caa7a4f sshd-session[2946995]: Invalid user solana from 195.178.110.30 port 44014
May 11 14:34:45 vps-0caa7a4f sshd-session[2946995]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=195.178.110.30
show less