๐บ๐ธ
nyt
2026-10-09 20:31:43
(7 hours ago)
Sensitive File Probe, Repeated attempt to access eval-stdin.php, scanning
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 19:47:45
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.28.197.113 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.28.197.113 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 15:47:38.753278 2026] [security2:error] [pid 30300:tid 30300] [client 104.28.197.113:45343] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "acquivest.net"] [uri "/.env"] [unique_id "aslE2giKCXOmDuTkcrn7rwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2026-10-09 19:39:36
(8 hours ago)
103 requests with url.path /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php
Brute-Force
Bad Web Bot
๐ฎ๐ฉ
PENJAGA.AUM
2026-10-09 15:50:47
(12 hours ago)
104.28.197.113 - Attack: Possible XSS attack, js event handler
Web App Attack
SQL Injection
Spoofing
๐ณ๐ด
jad-abuse
2026-10-09 14:20:14
(13 hours ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: env_probe ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: env_probe, phpunit_rce. Observed by 1 sensor(s); 32 hits.
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 13:32:24
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.28.197.113 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.28.197.113 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 09:32:16.440549 2026] [security2:error] [pid 30231:tid 30231] [client 104.28.197.113:53657] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "solcargomiami.com"] [uri "/.env"] [unique_id "asjs4COumabyPrSuJGQ1owAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Phenix Info
2026-10-09 13:22:57
(14 hours ago)
SmallGuard.fr - Forbidden Ext.
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 11:36:33
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.28.197.113 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.28.197.113 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 07:36:30.384326 2026] [security2:error] [pid 28708:tid 28708] [client 104.28.197.113:60770] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nnrentacar.com"] [uri "/.env"] [unique_id "asjRvpAEh9Ixr6rfiI4lAAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
MusicLibrary
2026-10-09 10:20:38
(17 hours ago)
Attempted access to sensitive configuration files (.env, .git, etc.)
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-10-09 06:51:21
(21 hours ago)
[09/Oct/2026:09:51:20 +0300] -- 104.28.197.113 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET ...
show more
[09/Oct/2026:09:51:20 +0300] -- 104.28.197.113 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET /.env HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 05:35:50
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.28.197.113 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.28.197.113 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 01:35:47.878189 2026] [security2:error] [pid 14966:tid 14983] [client 104.28.197.113:62556] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bbpuertadelsol.com"] [uri "/vendor/.env"] [unique_id "ash9M_JdKxx82poakvWHigAAAQ8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
j-tap
2026-10-09 03:35:10
(1 day ago)
WordPress honeypot: automated scanner (xmlrpc / installer / .env / direct login POST)
Web App Attack
๐ซ๐ท
dynamix
2026-10-09 03:24:14
(1 day ago)
Multiple WAF Violations
Web App Attack
๐ซ๐ท
j-tap
2026-10-06 02:16:44
(4 days ago)
WordPress honeypot: automated scanner (xmlrpc / installer / .env / direct login POST)
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-27 16:39:04
(1 week ago)
[ti-01ov] Web exploit scanning: 1 suspicious requests detected by fail2ban jail <name>. Example: 104 ...
show more
[ti-01ov] Web exploit scanning: 1 suspicious requests detected by fail2ban jail <name>. Example: 104.28.197.113 - - \[27/Sep/2026:18:38:51 +0200\] "GET /.env HTTP/1.1" 403 5707 "-" "Mozilla/5.0 \(Macintosh\; Intel Mac OS X 10_10_1\) AppleWebKit/537.36 \(KHTML, like Gecko\) Chrome/39.0.2171.95 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack