๐ฌ๐ง
openstrike.co.uk
2026-09-18 05:14:19
(1 hour ago)
4 attacks on env grabbing URLs:
GET /.env HTTP/1.1
Hacking
๐ฒ๐ฝ
octageeks.com
2026-09-18 04:19:43
(2 hours ago)
Wordpress malicious attack:[octablocked]
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-18 02:26:54
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 119.234.202.138 (dnssec1.singnet.com.sg): 1 in ...
show more
(mod_security) mod_security (id:210492) triggered by 119.234.202.138 (dnssec1.singnet.com.sg): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 22:26:50.103600 2026] [security2:error] [pid 29518:tid 29541] [client 119.234.202.138:40358] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "econpage.com"] [uri "/.env"] [unique_id "aqyhaoCUMO2GW9uCIIo_RAAAAU4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-18 01:38:45
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 119.234.202.138 (dnssec1.singnet.com.sg): 1 in ...
show more
(mod_security) mod_security (id:210492) triggered by 119.234.202.138 (dnssec1.singnet.com.sg): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 21:38:38.915584 2026] [security2:error] [pid 9273:tid 9273] [client 119.234.202.138:43546] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dualspiralsystems.com"] [uri "/.env"] [unique_id "aqyWHp14Eyo0Ny6YN8-zuwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-18 00:58:28
(5 hours ago)
(mod_security) mod_security (id:949110) triggered by 119.234.202.138 (dnssec1.singnet.com.sg): 1 in ...
show more
(mod_security) mod_security (id:949110) triggered by 119.234.202.138 (dnssec1.singnet.com.sg): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 20:58:23.813035 2026] [security2:error] [pid 4837:tid 4837] [client 119.234.202.138:37748] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "donkeywaffle.com"] [uri "/.env"] [unique_id "aqyMr2R8i0lbpf3uuWHgAwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-18 00:35:26
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 119.234.202.138 (dnssec1.singnet.com.sg): 1 in ...
show more
(mod_security) mod_security (id:210492) triggered by 119.234.202.138 (dnssec1.singnet.com.sg): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 20:35:21.465993 2026] [security2:error] [pid 19969:tid 19969] [client 119.234.202.138:54168] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "djbadger.com"] [uri "/.env"] [unique_id "aqyHSaof823P_lPr3hBJkgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
cwytech
2026-09-17 22:18:44
(8 hours ago)
Fleet-wide ban from the Ghostfleet ๐ป. Triggered by scenario: cwy/http-honeypath-sniper-crit.
Bad Web Bot
Web App Attack
Anonymous
2026-09-17 22:03:43
(8 hours ago)
apache vulnerability scan
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-09-17 22:00:00
(8 hours ago)
Auto-ban: >3000 req/min op 2026-09-17
Web App Attack
SSH
Hacking
Anonymous
2026-09-17 21:54:04
(8 hours ago)
Bot / scanning and/or hacking attempts: GET /.env HTTP/1.1
Hacking
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-17 21:37:48
(9 hours ago)
[ti-01ov] Web exploit scanning: 1 suspicious requests detected by fail2ban jail <name>. Example: 119 ...
show more
[ti-01ov] Web exploit scanning: 1 suspicious requests detected by fail2ban jail <name>. Example: 119.234.202.138 - - \[17/Sep/2026:23:37:36 +0200\] "GET /.env HTTP/1.1" 403 5756 "-" "Mozilla/5.0 \(X11\; Ubuntu\; Linux x86_64\; rv:62.0\) Gecko/20100101 Firefox/62.0"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
Lee Daniel
2026-09-17 21:05:43
(9 hours ago)
119.234.202.138 - - [17/Sep/2026:17:05:43 -0400] "GET /.env HTTP/1.1" 403 6300 "-" "Mozilla/5.0 (X11 ...
show more
119.234.202.138 - - [17/Sep/2026:17:05:43 -0400] "GET /.env HTTP/1.1" 403 6300 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:62.0) Gecko/20100101 Firefox/62.0"
...
show less
DDoS Attack
Web Spam
Email Spam
Port Scan
Brute-Force
Bad Web Bot
Web App Attack
๐ท๐ด
iulianh
2026-09-17 20:52:36
(9 hours ago)
80,443
Brute-Force
SSH
๐ฉ๐ฐ
HostingGroup
2026-09-17 20:31:53
(10 hours ago)
Automated malicious activity (Honeypot Trap) detected and blocked at the CDN edge by NordicCDN Shiel ...
show more
Automated malicious activity (Honeypot Trap) detected and blocked at the CDN edge by NordicCDN Shield. Offenses: 1. First blocked: 2026-09-17.
show less
Bad Web Bot
Web App Attack
๐จ๐ญ
sternwart
2026-09-17 20:23:33
(10 hours ago)
Automatisch erkannt: Zugriff auf /.env (coaching-planet.ch)
Web App Attack
Bad Web Bot