๐ฉ๐ช
[email protected]
2026-02-14 00:30:29
(4 months ago)
...
Brute-Force
SSH
๐ฉ๐ช
kranem
2026-02-14 00:01:11
(4 months ago)
Triggered Cloudflare WAF from US.
Action taken: BLOCK
ASN: 174 (COGENT-174 - Cogent Communications, ...
show more
Triggered Cloudflare WAF from US.
Action taken: BLOCK
ASN: 174 (COGENT-174 - Cogent Communications, LLC)
Protocol: HTTP/1.1 (GET method)
Endpoint: /.env
Timestamp: 2026-02-13T21:54:36Z
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0
show less
Bad Web Bot
๐ฉ๐ช
Gwyneth Llewelyn
2026-02-13 21:41:02
(4 months ago)
102.129.234.102 - - [13/Feb/2026:21:41:01 +0000] "GET /.env HTTP/2.0" 301 162 "-" "Mozilla/5.0 (Maci ...
show more
102.129.234.102 - - [13/Feb/2026:21:41:01 +0000] "GET /.env HTTP/2.0" 301 162 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0"
2026/02/13 21:41:01 [error] 2608829#2608829: *9294848 access forbidden by rule, client: 102.129.234.102, server: lisbon-pre-1755-earthquake.org, request: "GET /.env HTTP/2.0", host: "lisbon-pre-1755-earthquake.org"
102.129.234.102 - - [13/Feb/2026:21:41:01 +0000] "GET /.env HTTP/2.0" 403 1045 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0"
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-13 21:38:11
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 102.129.234.102 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 102.129.234.102 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 13 16:38:05.167067 2026] [security2:error] [pid 2813553:tid 2813553] [client 102.129.234.102:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.yggdrasil.org"] [uri "/.env"] [unique_id "aY-Zvb4qUXfK_dqEGfAhcgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
enpepet
2026-02-13 19:59:01
(4 months ago)
GENERAL: parametres: [url:env=] UA:Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/2010 ...
show more
GENERAL: parametres: [url:env=] UA:Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0 URL:/.env
show less
Port Scan
Hacking
Brute-Force
Bad Web Bot
๐บ๐ธ
Epimetheus
2026-02-13 14:12:32
(4 months ago)
Unauthorized access attempts:
From:
102.129.234.102
Method:
HTTP GET
URI Path:
/.env
UA:
"Mo ...
show more
Unauthorized access attempts:
From:
102.129.234.102
Method:
HTTP GET
URI Path:
/.env
UA:
"Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0"
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-13 12:56:49
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 102.129.234.102 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 102.129.234.102 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 13 07:56:43.177909 2026] [security2:error] [pid 6456:tid 6456] [client 102.129.234.102:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sportsbookcommission.com"] [uri "/.env"] [unique_id "aY8fiy7eb3A7zs-FzsaTzAAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
S.O.B.A. Dev.
2026-02-13 12:41:26
(4 months ago)
Threat Blocked by BeeHive from (ASN:174) (Network:COGENT-174 - Cogent Communications, LLC) (Host:sob ...
show more
Threat Blocked by BeeHive from (ASN:174) (Network:COGENT-174 - Cogent Communications, LLC) (Host:soba.dev) (Method:GET) (Protocol:HTTP/1.1) (Timestamp:2026-02-13T12:41:26Z)
show less
Web Spam
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-13 11:30:05
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 102.129.234.102 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 102.129.234.102 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 13 06:29:58.694307 2026] [security2:error] [pid 2358191:tid 2358197] [client 102.129.234.102:64590] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.tamarkummel.com"] [uri "/.env"] [unique_id "aY8LNlR8nh0GEUZGmRXS2gAAAUA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-02-13 11:21:59
(4 months ago)
Web App Attack
Brute-Force
Exploited Host
Web App Attack
๐ต๐ฑ
ketovoila.pl
2026-02-13 11:13:58
(4 months ago)
ketovoila.pl HONEYPOT traffic: count=1, paths=1; sample_path=ketovoila.pl/.env; UA=Mozilla/5.0 (Maci ...
show more
ketovoila.pl HONEYPOT traffic: count=1, paths=1; sample_path=ketovoila.pl/.env; UA=Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0; window=2026-02-13T10:33:55Z..2026-02-13T10:33:55Z
show less
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-02-13 10:57:06
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 102.129.234.102 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 102.129.234.102 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 13 05:57:01.250792 2026] [security2:error] [pid 32696:tid 32696] [client 102.129.234.102:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kryptonome.com"] [uri "/.env"] [unique_id "aY8DfXWTQcqVlUabZJZkDwAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Baking333
2026-02-13 10:46:17
(4 months ago)
[redacted] 102.129.234.102 - - [13/Feb/2026:11:46:14 +0100] "GET /.env HTTP/2.0" 301 286 "-" "Mozill ...
show more
[redacted] 102.129.234.102 - - [13/Feb/2026:11:46:14 +0100] "GET /.env HTTP/2.0" 301 286 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0" [redacted] 102.129.234.102 - - [13/Feb/2026:11:46:15 +0100] "GET /fr/.env/ HTTP/2.0" 404 25569 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0"
show less
Bad Web Bot
Web App Attack
Anonymous
2026-02-13 10:23:38
(4 months ago)
(mod_security) mod_security triggered on hostname [redacted] 102.129.234.102 (US/United States/-)
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-02-13 10:21:47
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 102.129.234.102 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 102.129.234.102 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 13 05:21:41.052659 2026] [security2:error] [pid 17295:tid 17295] [client 102.129.234.102:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "shubil.com"] [uri "/.env"] [unique_id "aY77NX7J3lSmvOss9ImF3QAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack