๐บ๐ธ
rdpguard.com
2026-09-16 00:00:17
(4 days ago)
RdpGuard detected brute-force attempt on HTTP
Brute-Force
๐ณ๐ฑ
homeshowdomain.nl
2026-09-15 22:04:17
(4 days ago)
Auto-ban: >3000 req/min op 2026-09-15
Web App Attack
SSH
Hacking
๐ณ๐ฑ
Alt255
2026-09-15 18:01:10
(4 days ago)
[ti-01ov] Web exploit scanning: 3 suspicious requests detected by fail2ban jail <name>. Example: 105 ...
show more
[ti-01ov] Web exploit scanning: 3 suspicious requests detected by fail2ban jail <name>. Example: 105.158.170.53 - - [15/Sep/2026:04:05:33 +0200] "GET /.env HTTP/1.1" 301 5682 "-" "-"
105.158.170.53 - - [15/Sep/2026:04:05:33 +0200] "GET /.env HTTP/1.1" 404 96021 "-" "-"
105.158.170.53 - - [15/Sep/2026:04:05:34 +0200] "GET /.env HTTP/1.1" 404 96021 "https://www.maplegroup.nl/.env" "-"
...
show less
Bad Web Bot
Web App Attack
๐ฌ๐ง
kie
2026-09-15 17:11:39
(4 days ago)
15-09-2026:17:10:46UTC [Nginx Web Server] Suspicious web request: path:/.env (1 request(s)).
Bad Web Bot
Web App Attack
๐ฎ๐น
CoreTech srl
2026-09-15 16:13:58
(4 days ago)
cloudlinux2 fail2ban: 2026-09-15 18:09:11,240 fail2ban.actions [1908]: NOTICE [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-09-15 18:09:11,240 fail2ban.actions [1908]: NOTICE [plesk-modsecurity] Unban 34.40.93.90cloudlinux2 fail2ban: 2026-09-15 18:10:23,413 fail2ban.filter [1908]: INFO [plesk-wordpress] Found 116.203.193.119 - 2026-09-15 18:10:23cloudlinux2 fail2ban: 2026-09-15 18:10:52,480 fail2ban.filter [1908]: INFO [plesk-modsecurity] Found 105.158.170.53 - 2026-09-15 18:10:52cloudlinux2 fail2ban: 2026-09-15 18:10:52,552 fail2ban.filter [1908]: INFO [plesk-modsecurity] Found 105.158.170.53 - 2026-09-15 18:10:52cloudlinux2 fail2ban: 2026-09-15 18:11:19,825 fail2ban.filter [1908]: INFO [plesk-modsecurity] Found 34.65.89.54 - 2026-09-15 18:11:19cloudlinux2 fail2ban: 2026-09-15 18:11:14,586 fail2ban.actions [1908]: NOTICE [plesk-modsecurity] Unban 34.64.49.97cloudlinux2 fail2ban: 2026-09-15 18:11:19,814 fail2ban.filter [1908]: INFO [plesk-modsecurity] Found 34.65.89.54 - 2026-09-15 18:11:19cloudlinux2 fail2ban: 2026-09-15 18:11:19,805
show less
Web App Attack
๐ต๐ฑ
Budyn
2026-09-15 16:05:24
(4 days ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: apm.astropot.website | URI: /.env | UA: Unknown User-Agent | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-15 15:00:25
(5 days ago)
[ti-03tr] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-03tr] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 105.158.170.53 - - [15/Sep/2026:17:00:21 +0200] "GET /.env HTTP/1.1" 404 9024 "-" "-"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 14:05:06
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 105.158.170.53 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 105.158.170.53 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 10:05:02.836664 2026] [security2:error] [pid 3070:tid 3070] [client 105.158.170.53:35948] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.fab.zunosaki.com"] [uri "/.env"] [unique_id "aqlQjokRI7_4izqnGjcU9QAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
boxed-it
2026-09-15 13:23:07
(5 days ago)
GET /.env (Tarpitted for 19m44s, wasted 69.49kB)
Web App Attack
๐ฉ๐ช
LRob
2026-09-15 13:03:38
(5 days ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.env | 2026-09-15 13:03 UTC
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 13:02:51
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 105.158.170.53 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 105.158.170.53 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 09:02:46.015694 2026] [security2:error] [pid 26893:tid 26893] [client 105.158.170.53:59454] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "voidpope.com"] [uri "/.env"] [unique_id "aqlB9lYyGtOJacsAleTynwAAACk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 12:10:36
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 105.158.170.53 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 105.158.170.53 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 08:10:32.901401 2026] [security2:error] [pid 12591:tid 12591] [client 105.158.170.53:47964] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mathstuff.walkenfeld.com"] [uri "/.env"] [unique_id "aqk1uHXTDOaSIlKMIPWdCwAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ต๐ฑ
Budyn
2026-09-15 12:00:47
(5 days ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: db.goblinpot.website | URI: /.env | UA: Unknown User-Agent | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
Aufpasser_1973
2026-09-15 12:00:25
(5 days ago)
Fail2Ban Caddy: Web App Attack, /.env
Web App Attack
๐ซ๐ท
UnixPrime
2026-09-15 11:03:53
(5 days ago)
105.158.170.53 - - [15/Sep/2026:13:03:52 +0200] "GET /.env HTTP/1.1" 404 13948 "-" "-"
105.158.170.5 ...
show more
105.158.170.53 - - [15/Sep/2026:13:03:52 +0200] "GET /.env HTTP/1.1" 404 13948 "-" "-"
105.158.170.53 - - [15/Sep/2026:13:03:52 +0200] "GET /.env HTTP/1.1" 404 14020 "-" "-"
...
show less
Bad Web Bot
Web App Attack