๐ฉ๐ช
Vegascosmetics
2026-05-26 21:50:46
(2 weeks ago)
Kingcopy(AI-IDS): IP is wandering around the site and acting suspiciously.
Bad Web Bot
Anonymous
2026-05-24 02:50:18
(3 weeks ago)
Web App Attack, Hacking
Hacking
Web App Attack
Anonymous
2026-05-17 07:12:33
(4 weeks ago)
103.153.210.69 - - [17/May/2026:07:12:33 +0000] "GET /.env HTTP/1.1" 404 381 "-" "Mozilla/5.0 (Macin ...
show more
103.153.210.69 - - [17/May/2026:07:12:33 +0000] "GET /.env HTTP/1.1" 404 381 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0"
...
show less
Bad Web Bot
Web App Attack
๐ซ๐ท
LRNP
2026-05-17 07:01:35
(4 weeks ago)
_:80 103.153.210.69 - - [17/May/2026:07:01:34 +0000] "GET /.env HTTP/1.1" 404 146 "-" "Mozilla/5.0 ( ...
show more
_:80 103.153.210.69 - - [17/May/2026:07:01:34 +0000] "GET /.env HTTP/1.1" 404 146 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-02 02:38:50
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 103.153.210.69 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 103.153.210.69 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 01 22:38:33.805244 2026] [security2:error] [pid 16534:tid 16534] [client 103.153.210.69:59825] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.151.27"] [uri "/.env"] [unique_id "afVjqcq156AsDx33IBs0KgAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
kumiko
2026-05-01 16:45:02
(1 month ago)
[2026-05-01 19:44:56] Probing for dotfiles
"GET /.env HTTP/1.1" 403
Bad Web Bot
Web App Attack
๐บ๐ธ
Al Coholic
2026-04-25 18:22:39
(1 month ago)
Detected By Fail2ban
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-25 16:52:03
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 103.153.210.69 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 103.153.210.69 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 25 12:51:49.147287 2026] [security2:error] [pid 2182:tid 2182] [client 103.153.210.69:61112] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.68"] [uri "/.env"] [unique_id "aezxJZ1raqQI6oXw4jCDRgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Baking333
2026-04-14 04:23:22
(2 months ago)
redacted:80 103.153.210.69 - - [14/Apr/2026:05:23:20 +0100] "GET /.env HTTP/1.1" 200 147 0/16317 "-" ...
show more
redacted:80 103.153.210.69 - - [14/Apr/2026:05:23:20 +0100] "GET /.env HTTP/1.1" 200 147 0/16317 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0" redacted:80 103.153.210.69 - - [14/Apr/2026:05:23:20 +0100] "GET /wp-content/ HTTP/1.1" 301 533 0/374 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0"
show less
Bad Web Bot
Web App Attack
๐ซ๐ท
Bedios GmbH
2026-04-05 03:12:09
(2 months ago)
Login credentials theft attempt
Hacking
๐ฉ๐ช
EGP Abuse Dept
2026-04-03 02:36:06
(2 months ago)
Scraping webshop URLs (www.badgehouder.nl), likely botnet drone
Bad Web Bot
Exploited Host
๐ซ๐ท
Dechavanne
2026-03-24 05:00:13
(2 months ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
๐น๐ญ
Sawasdee
2026-03-16 06:36:05
(2 months ago)
Unwanted checking 80 or 443 port
...
Bad Web Bot
๐ซ๐ท
sthoyer.de
2026-03-05 14:00:46
(3 months ago)
103.153.210.69 - - [05/Mar/2026:15:00:39 +0100] "GET /.env HTTP/1.1" 302 794 "-" "Mozilla/5.0 (Macin ...
show more
103.153.210.69 - - [05/Mar/2026:15:00:39 +0100] "GET /.env HTTP/1.1" 302 794 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0"
103.153.210.69 - - [05/Mar/2026:15:00:44 +0100] "GET /.env HTTP/1.1" 302 794 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0"
103.153.210.69 - - [05/Mar/2026:15:00:44 +0100] "GET /wp-content/ HTTP/1.1" 302 794 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0"
...
show less
Web App Attack
๐ช๐ธ
bohl-aiG5aef
2026-03-05 13:34:25
(3 months ago)
Suricata Alert [SID:2031502] ET INFO Request to Hidden Environment File - Inbound
Hacking