|
π§π·
Peregrine
|
|
Fail2Ban Jail: tomcat-honeypot | Evidence: 156.146.39.35 162.158.175.217 - - [09/Mar/2026:20:08:48 - ...
show more
Fail2Ban Jail: tomcat-honeypot | Evidence: 156.146.39.35 162.158.175.217 - - [09/Mar/2026:20:08:48 -0300] "GET /.env HTTP/1.1" 404 414
show less
|
Bad Web Bot
|
|
|
π§π·
Peregrine
|
|
Fail2Ban Jail: tomcat-honeypot | Evidence: 156.146.39.35 162.158.175.217 - - [09/Mar/2026:20:08:48 - ...
show more
Fail2Ban Jail: tomcat-honeypot | Evidence: 156.146.39.35 162.158.175.217 - - [09/Mar/2026:20:08:48 -0300] "GET /.env HTTP/1.1" 404 414
show less
|
Bad Web Bot
|
|
|
πΊπΈ
sailor
|
|
GET .../.env
|
Web App Attack
Hacking
|
|
|
Anonymous
|
|
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
|
Exploited Host
|
|
|
πΊπΈ
TPI-Abuse
|
|
(mod_security) mod_security (id:210492) triggered by 156.146.39.35 (unn-156-146-39-35.cdn77.com): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 156.146.39.35 (unn-156-146-39-35.cdn77.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 09 19:17:41.725206 2026] [security2:error] [pid 14223:tid 14223] [client 156.146.39.35:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nyemdr-online.com"] [uri "/.env"] [unique_id "aa9VFWSEJBv1rJiwuvllWwAAAAc"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
π§π·
Peregrine
|
|
Fail2Ban Jail: tomcat-honeypot | Evidence: 156.146.39.35 162.158.175.217 - - [09/Mar/2026:20:08:48 - ...
show more
Fail2Ban Jail: tomcat-honeypot | Evidence: 156.146.39.35 162.158.175.217 - - [09/Mar/2026:20:08:48 -0300] "GET /.env HTTP/1.1" 404 414
show less
|
Bad Web Bot
|
|
|
πΊπΈ
mnsf
|
|
Scanning/Probing (23)
|
Brute-Force
Web App Attack
|
|
|
πΊπΈ
TPI-Abuse
|
|
(mod_security) mod_security (id:210492) triggered by 156.146.39.35 (unn-156-146-39-35.cdn77.com): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 156.146.39.35 (unn-156-146-39-35.cdn77.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 09 19:00:33.922237 2026] [security2:error] [pid 32207:tid 32207] [client 156.146.39.35:60113] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "berlatinc.com"] [uri "/.env"] [unique_id "aa9REasrdPX7MaDDpBajGAAAAAI"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
π©πͺ
bryth
|
|
Wordpress login/xmlrpc abuse (Mon Mar 9 10:46:26 PM UTC 2026)
|
Hacking
Web App Attack
|
|
|
π³π±
Lentini
|
|
visuitslagen.nl: malicious request:/.env
|
Web App Attack
|
|
|
π¨πΏ
akac
|
|
Web vulnerability scanning: HTTP/1.1 GET /.env
|
Hacking
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
π³π±
Savvii
|
|
26 attempts against mh-misbehave-ban on redirect
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
πΊπΈ
TPI-Abuse
|
|
(mod_security) mod_security (id:210492) triggered by 156.146.39.35 (unn-156-146-39-35.cdn77.com): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 156.146.39.35 (unn-156-146-39-35.cdn77.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 09 16:30:23.826046 2026] [security2:error] [pid 19325:tid 19325] [client 156.146.39.35:14415] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "1954topresent.com"] [uri "/.env"] [unique_id "aa8t3z-1cofPu1oJjUqcowAAAAg"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
πΊπΈ
TPI-Abuse
|
|
(mod_security) mod_security (id:210492) triggered by 156.146.39.35 (unn-156-146-39-35.cdn77.com): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 156.146.39.35 (unn-156-146-39-35.cdn77.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 09 16:04:01.372314 2026] [security2:error] [pid 1524:tid 1524] [client 156.146.39.35:38150] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "vitess.com"] [uri "/.env"] [unique_id "aa8nsVNMLTmHPScDxI9ZgQAAABA"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
π³π±
Savvii
|
|
20 attempts against mh-misbehave-ban on redirect
|
Brute-Force
Bad Web Bot
Web App Attack
|
|