๐ฐ๐ท
windykc
2026-08-28 00:31:13
(17 hours ago)
Honeypot capture. HTTP: 12 attacks (sample URIs: ['/.env.production', '/.env.old', '/.env.example', ...
show more
Honeypot capture. HTTP: 12 attacks (sample URIs: ['/.env.production', '/.env.old', '/.env.example', '/.env.prod', '/actuator/env']). Geo/ISP: US/Google LLC. Last seen: 2026-08-28T07:05:44Z.
show less
Hacking
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-08-27 22:00:53
(20 hours ago)
Auto-ban: >3000 req/min op 2026-08-27
Web App Attack
SSH
Hacking
๐ท๐บ
DZBOT
2026-08-27 20:30:43
(21 hours ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
Anonymous
2026-08-27 20:01:37
(22 hours ago)
136.114.2.44 ip4-46-39-185-24.cust.nbox.cz - [27/Aug/2026:22:01:36 +0200] "GET /.env.backup HTTP/1.1 ...
show more
136.114.2.44 ip4-46-39-185-24.cust.nbox.cz - [27/Aug/2026:22:01:36 +0200] "GET /.env.backup HTTP/1.1" 404 158 "-" "crusader-worker/1.0"
...
show less
Hacking
Web App Attack
๐ณ๐ฑ
BlueWire Hosting
2026-08-27 19:39:06
(22 hours ago)
Probing websites for vulnerabilities
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 19:23:53
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.114.2.44 (44.2.114.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 136.114.2.44 (44.2.114.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 15:23:49.542102 2026] [security2:error] [pid 5517:tid 5517] [client 136.114.2.44:60360] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.thedieselgroupllc.com.resilientigm.com"] [uri "/.env.old"] [unique_id "apCOxVXQzTj8wuy0mLZWGwAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
zynex
2026-08-27 18:30:20
(23 hours ago)
URL Probing: /wp-config.php~
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 18:23:45
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 136.114.2.44 (44.2.114.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 136.114.2.44 (44.2.114.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 14:23:38.873081 2026] [security2:error] [pid 4822:tid 4822] [client 136.114.2.44:37152] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "multimediaperformances.com"] [uri "/.env.prod"] [unique_id "apCAqstUYW--JKxo-KVu4gAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-08-27 18:02:23
(1 day ago)
Try to access /.env
Web App Attack
๐ฉ๐ช
AetherFox
2026-08-27 18:00:18
(1 day ago)
AetherFox VoidGuard detected: [Thu Aug 27 18:00:17.918737 2026] [authz_core:error] [pid 3551574:tid ...
show more
AetherFox VoidGuard detected: [Thu Aug 27 18:00:17.918737 2026] [authz_core:error] [pid 3551574:tid 3551593] [client 136.114.2.44:33532] AH01630: client denied by server configuration: proxy:https://freebeegee.draconigen.de/.env.bak
[Thu Aug 27 18:00:17.918907 2026] [authz_core:error] [pid 3551574:tid 3551593] [client 136.114.2.44:33532] AH01630: client denied by server configuration: /var/www/html/ERRORpages/403.html
[Thu Aug 27 18:00:17.920905 2026] [authz_core:error] [pid 3551574:tid 3551610] [client 136.114.2.44:33524] AH01630: client denied by server configuration: proxy:https://freebeegee.draconigen.de/.env.dev
[Thu Aug 27 18:00:17.920985 2026] [authz_core:error] [pid 3551574:tid 3551610] [client 136.114.2.44:33524] AH01630: client denied by server configuration: /var/www/html/ERRORpages/403.html
[Thu Aug 27 18:00:17.921122 2026] [authz_core:error] [pid 3551575:tid 3551605] [client 136.114.2.44:33542] AH01630: client denied by server configuration: proxy:https
...
show less
Bad Web Bot
Web App Attack
๐ซ๐ฎ
paissangroup
2026-08-27 17:40:18
(1 day ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 16:51:05
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 136.114.2.44 (44.2.114.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 136.114.2.44 (44.2.114.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 12:51:01.215492 2026] [security2:error] [pid 13027:tid 13027] [client 136.114.2.44:37124] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.fishaways.jbaydeliveries.com"] [uri "/.env.bak"] [unique_id "apBq9QjtFtTc6hN1ha0ZLgAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 16:29:39
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 136.114.2.44 (44.2.114.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 136.114.2.44 (44.2.114.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 12:29:32.997872 2026] [security2:error] [pid 25986:tid 25986] [client 136.114.2.44:45396] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "idgcasadelgeologo.com"] [uri "/.env.dev"] [unique_id "apBl7H56Jn3Qczuh9OCQFgAAACg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ger-stg-sifi1
2026-08-27 15:53:42
(1 day ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
Anonymous
2026-08-27 15:48:12
(1 day ago)
[ns3.backorder.gr] httpd-config-scan: logs=/var/log/httpd/access_log; samples=/.env | /.env.producti ...
show more
[ns3.backorder.gr] httpd-config-scan: logs=/var/log/httpd/access_log; samples=/.env | /.env.production | /.env.backup
show less
Hacking
Web App Attack