Anonymous
2026-09-08 20:37:41
(10 hours ago)
"GET /.env HTTP/1.1"
Hacking
Web App Attack
🇺🇸
Floofie
2026-09-08 13:35:52
(17 hours ago)
147.90.209.153 - - [08/Sep/2026:09:35:51 -0400] "GET /.env HTTP/1.1" 444 0 "-" "-"
147.90.209.153 - ...
show more
147.90.209.153 - - [08/Sep/2026:09:35:51 -0400] "GET /.env HTTP/1.1" 444 0 "-" "-"
147.90.209.153 - - [08/Sep/2026:09:35:51 -0400] "GET /.env HTTP/1.1" 444 0 "-" "-"
147.90.209.153 - - [08/Sep/2026:09:35:52 -0400] "GET /.env HTTP/1.1" 444 0 "-" "-"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 13:29:00
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 147.90.209.153 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 147.90.209.153 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 09:28:55.513398 2026] [security2:error] [pid 12915:tid 12915] [client 147.90.209.153:39953] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.235"] [uri "/.env"] [unique_id "aqANlzKrGblXs3JJ0k4a-AAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Phenix Info
2026-09-08 13:21:56
(17 hours ago)
SmallGuard.fr/Prestashop Forbidden Ext.
Web App Attack
🇩🇪
Marcin Stepien
2026-09-08 13:19:32
(18 hours ago)
Hit honeypot endpoint /.env. Automated scanner/bot detected.
Bad Web Bot
Web App Attack
🇺🇸
sefinek.net
2026-09-08 12:48:21
(18 hours ago)
Blocked by UFW on NY01 [80/tcp] | SPT: 51177 | TTL: 52 | LEN: 60 | TOS: 0x08 • Reported by: github.c ...
show more
Blocked by UFW on NY01 [80/tcp] | SPT: 51177 | TTL: 52 | LEN: 60 | TOS: 0x08 • Reported by: github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
Anonymous
2026-09-08 12:21:04
(18 hours ago)
Fuzzing/Looking for credentials files.
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 11:23:55
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 147.90.209.153 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 147.90.209.153 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 07:23:52.649103 2026] [security2:error] [pid 27486:tid 27486] [client 147.90.209.153:59073] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.53"] [uri "/.env"] [unique_id "ap_wSAJ_XhI1guHN1SVT_gAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
bescared
2026-09-08 11:07:18
(20 hours ago)
F2B - Malicious activity detected. URL Probing. -8ff06ede-
Hacking
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 10:58:22
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 147.90.209.153 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 147.90.209.153 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 06:58:16.118783 2026] [security2:error] [pid 4856:tid 4856] [client 147.90.209.153:31935] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.167"] [uri "/.env"] [unique_id "ap_qSHFWLRotUrKqrJO-6wAAAHQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
bescared
2026-09-08 10:43:54
(20 hours ago)
F2B - Malicious activity detected. URL Probing. -c0423ad6-
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 10:24:34
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 147.90.209.153 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 147.90.209.153 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 06:24:28.123406 2026] [security2:error] [pid 8652:tid 8652] [client 147.90.209.153:46071] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.89"] [uri "/.env"] [unique_id "ap_iXDu4kGD21wn-9xxnsgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
aks4226
2026-09-08 10:09:39
(21 hours ago)
Bot search, attacking common web applications.
Web App Attack
🇦🇹
Pingger Shikkoken
2026-09-08 10:00:52
(21 hours ago)
2026-09-08T10:00:52+00:00 iskariot kernel: AbuseIPDB-Blacklist-Dropped: IN=ens3 OUT=ServerBridge MAC ...
show more
2026-09-08T10:00:52+00:00 iskariot kernel: AbuseIPDB-Blacklist-Dropped: IN=ens3 OUT=ServerBridge MAC=b6:ab:74:e6:2e:14:2c:dd:e9:13:03:d9:08:00 SRC=147.90.209.153 DST=10.1.1.2 LEN=60 TOS=0x00 PREC=0x00 TTL=53 ID=31247 DF PROTO=TCP SPT=45217 DPT=80 WINDOW=64240 RES=0x00 SYN URGP=0 2026-09-08T10:00:53+00:00 iskariot kernel: AbuseIPDB-Blacklist-Dropped: IN=ens3 OUT=ServerBridge MAC=b6:ab:74:e6:2e:14:2c:dd:e9:13:03:d9:08:00 SRC=147.90.209.153 DST=10.1.1.2 LEN=60 TOS=0x00 PREC=0x00 TTL=53 ID=31248 DF PROTO=TCP SPT=45217 DPT=80 WINDOW=64240 RES=0x00 SYN URGP=0 2026-09-08T10:00:55+00:00 iskariot kernel: AbuseIPDB-Blacklist-Dropped: IN=ens3 OUT=ServerBridge MAC=b6:ab:74:e6:2e:14:2c:dd:e9:13:03:d9:08:00 SRC=147.90.209.153 DST=10.1.1.2 LEN=60 TOS=0x00 PREC=0x00 TTL=53 ID=31249 DF PROTO=TCP SPT=45217 DPT=80 WINDOW=64240 RES=0x00 SYN URGP=0 ...
show less
Hacking
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-08 09:55:41
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 147.90.209.153 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 147.90.209.153 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 05:55:35.909942 2026] [security2:error] [pid 4169:tid 4169] [client 147.90.209.153:35593] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.49"] [uri "/.env"] [unique_id "ap_bl9zCF8tjIKfumRw4LgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack