๐บ๐ธ
nyt
2026-10-09 20:31:43
(1 day ago)
Sensitive File Probe, Attempt to access eval-stdin.php, potential exploit
Web App Attack
๐ซ๐ท
dynamix
2026-10-09 18:52:33
(1 day ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 18:06:05
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.28.197.112 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.28.197.112 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 14:05:58.573182 2026] [security2:error] [pid 29871:tid 29871] [client 104.28.197.112:30261] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.acquivest.net"] [uri "/.env"] [unique_id "asktBo68J58A4gTB9QzFcAAAACU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ด
jad-abuse
2026-10-09 14:20:06
(1 day ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: env_probe ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: env_probe. Observed by 1 sensor(s); 11 hits.
show less
Web App Attack
๐ฉ๐ช
Phenix Info
2026-10-09 13:22:55
(1 day ago)
SmallGuard.fr - Forbidden Ext.
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 11:36:38
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.28.197.112 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.28.197.112 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 07:36:32.171858 2026] [security2:error] [pid 25565:tid 25565] [client 104.28.197.112:49065] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nnrentacar.com"] [uri "/.env"] [unique_id "asjRwIKNOIPEnWoMwd4P-QAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-10-09 06:51:26
(1 day ago)
[09/Oct/2026:09:51:25 +0300] -- 104.28.197.112 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET ...
show more
[09/Oct/2026:09:51:25 +0300] -- 104.28.197.112 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET /.env HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 06:46:28
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.28.197.112 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.28.197.112 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 02:46:21.089325 2026] [security2:error] [pid 29228:tid 29228] [client 104.28.197.112:11634] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "solcargomiami.com"] [uri "/solcargomiami.com/.env"] [unique_id "asiNvZWFYCkTsKu8ByuPwgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
netclix.gr
2026-10-09 06:42:27
(1 day ago)
(c5_sensitive_scan) Custom6 Sensitive File Exploit Blocked 104.28.197.112 (MA/Morocco/-)
Hacking
๐บ๐ธ
TPI-Abuse
2026-10-09 05:36:00
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.28.197.112 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.28.197.112 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 01:35:54.301543 2026] [security2:error] [pid 5985:tid 6056] [client 104.28.197.112:17224] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bbpuertadelsol.com"] [uri "/bbpuertadelsol.com/.env"] [unique_id "ash9OuR1teSr5HWlZ3h05gAAAZc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
todix
2026-10-05 20:45:08
(5 days ago)
Web App Attack Exploid from 104.28.197.112
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-27 16:38:44
(1 week ago)
[ti-01ov] Web exploit scanning: 1 suspicious requests detected by fail2ban jail <name>. Example: 104 ...
show more
[ti-01ov] Web exploit scanning: 1 suspicious requests detected by fail2ban jail <name>. Example: 104.28.197.112 - - \[27/Sep/2026:18:38:34 +0200\] "GET /.env HTTP/1.1" 301 588 "-" "Mozilla/5.0 \(Macintosh\; Intel Mac OS X 10_10_1\) AppleWebKit/537.36 \(KHTML, like Gecko\) Chrome/39.0.2171.95 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
๐ฌ๐ง
thetomtaylor.co.uk
2026-09-23 11:08:00
(2 weeks ago)
Fail2Ban - [NGINX]WordPress Logins Sniffings on nginx-wordpress-sniffer ... [ice02]
Bad Web Bot
Web App Attack
๐ฌ๐ง
thetomtaylor.co.uk
2026-09-23 10:07:02
(2 weeks ago)
Fail2Ban - [NGINX]WordPress Logins Sniffings on nginx-wordpress-sniffer ... [wa01,wa02]
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-09-16 00:28:22
(3 weeks ago)
Host header is a numeric IP address. Pattern match "(?:^( (920350-196)
Hacking
Bad Web Bot