Anonymous
2026-06-28 08:17:04
(10 minutes ago)
102.220.160.176 - - [28/Jun/2026:08:17:04 +0000] "GET /.env HTTP/1.1" 302 441 "-" "Go-http-client/1. ...
show more
102.220.160.176 - - [28/Jun/2026:08:17:04 +0000] "GET /.env HTTP/1.1" 302 441 "-" "Go-http-client/1.1"
...
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
Gwyneth Llewelyn
2026-06-28 07:48:39
(38 minutes ago)
2026/06/28 08:48:38 [error] 1094874#1094874: *1716517 access forbidden by rule, client: 102.220.160. ...
show more
2026/06/28 08:48:38 [error] 1094874#1094874: *1716517 access forbidden by rule, client: 102.220.160.176, server: centroestudostibetanos.org, request: "GET /.env HTTP/1.1", host: "programanalanda.centroestudostibetanos.org:443"
2026/06/28 08:48:38 [error] 1094874#1094874: *1716518 access forbidden by rule, client: 102.220.160.176, server: centroestudostibetanos.org, request: "GET /.env HTTP/1.1", host: "programanalanda.centroestudostibetanos.org", referrer: "http://programanalanda.centroestudostibetanos.org:80/.env"
102.220.160.176 - - [28/Jun/2026:08:48:38 +0100] "GET /.env HTTP/1.1" 403 1057 "-" "Go-http-client/2.0"
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-28 07:31:59
(55 minutes ago)
(mod_security) mod_security (id:210492) triggered by 102.220.160.176 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 102.220.160.176 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 28 03:31:52.717032 2026] [security2:error] [pid 19399:tid 19399] [client 102.220.160.176:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.antitribu.com"] [uri "/.env"] [unique_id "akDN6NyYuaX6bBnRJLkxYgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
macrob
2026-06-28 07:14:40
(1 hour ago)
2026/06/28 07:14:38 [error] 269587#269587: *335721759 access forbidden by rule, client: 102.220.160. ...
show more
2026/06/28 07:14:38 [error] 269587#269587: *335721759 access forbidden by rule, client: 102.220.160.176, server: binixo.mx, request: "GET /.env HTTP/2.0", host: "binixo.mx:443"
2026/06/28 07:14:38 [error] 269582#269582: *335721768 access forbidden by rule, client: 102.220.160.176, server: binixo.mx, request: "GET /.env HTTP/2.0", host: "binixo.mx", referrer: "http://binixo.mx:80/.env"
2026/06/28 07:14:38 [error] 269582#269582: *335721770 access forbidden by rule, client: 102.220.160.176, server: binixo.mx, request: "GET /.git/HEAD HTTP/2.0", host: "binixo.mx:443"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-28 07:09:45
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 102.220.160.176 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 102.220.160.176 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 28 03:09:38.875393 2026] [security2:error] [pid 11972:tid 11972] [client 102.220.160.176:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "southernbroadcast.com"] [uri "/.env"] [unique_id "akDIshs5Thpof8Z_DoyE5gAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฑ๐ป
garmtech.com
2026-06-28 06:01:17
(2 hours ago)
Attempted access to sensitive endpoint (/.env) detected. Automated scan or unauthorized probing.
Web App Attack
๐ฉ๐ช
ramazan
2026-06-28 05:42:28
(2 hours ago)
Fail2Ban: nginx-4xx | Failures: 10 | Log: /.env /.git/refs/heads/dev /.git/refs/heads/develop /.git/ ...
show more
Fail2Ban: nginx-4xx | Failures: 10 | Log: /.env /.git/refs/heads/dev /.git/refs/heads/develop /.git/refs/heads/production /.git/refs/heads/release
show less
Web App Attack
Hacking
๐ฌ๐ง
openstrike.co.uk
2026-06-28 05:15:02
(3 hours ago)
6 attacks on env grabbing URLs, VC URLs:
GET /.env HTTP/1.1
GET /.git/HEAD HTTP/1.1
Hacking
๐บ๐ธ
TPI-Abuse
2026-06-28 04:43:49
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 102.220.160.176 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 102.220.160.176 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 28 00:43:43.263950 2026] [security2:error] [pid 27934:tid 27934] [client 102.220.160.176:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.sportsbookcommission.com"] [uri "/.env"] [unique_id "akCmf54nfSq6DiFxCAxI3gAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
taivas.nl
2026-06-28 04:32:32
(3 hours ago)
Many_bad_calls
Web App Attack
Anonymous
2026-06-28 04:27:11
(3 hours ago)
Sensitive file access attempt
Hacking
๐ฉ๐ช
NetShield-DE
2026-06-28 04:07:30
(4 hours ago)
Auto-report via Fail2Ban aggregation. IP observed in jails: abuseipdb, modsecurity.
Events: 2. First ...
show more
Auto-report via Fail2Ban aggregation. IP observed in jails: abuseipdb, modsecurity.
Events: 2. First: 2026-06-28T06:07:01+0200. Last: 2026-06-28T06:07:01+0200.
Samples:
- 2026-06-28 01:27:07,858 fail2ban.actions [996924]: NOTICE [modsecurity] Ban 102.220.160.176
- 2026-06-28 01:27:13,102 fail2ban.actions [996924]: NOTICE [abuseipdb] Ban 102.220.160.176
show less
Web App Attack
๐ฉ๐ช
Holger
2026-06-28 03:57:21
(4 hours ago)
URL probing: GET /.env
Web App Attack
๐บ๐ธ
Epimetheus
2026-06-28 03:20:10
(5 hours ago)
Zombie network / Bot scanner detected:
[GET] /.git/HEAD
[GET] /.env
[GET] /.git/HEAD
[GET] /.env
U ...
show more
Zombie network / Bot scanner detected:
[GET] /.git/HEAD
[GET] /.env
[GET] /.git/HEAD
[GET] /.env
UA: Go-http-client/2.0
show less
Bad Web Bot
Exploited Host
Web App Attack
๐บ๐ธ
jcbriar
2026-06-28 03:05:13
(5 hours ago)
Searching for vulnerable scripts
Hacking
Web App Attack