๐ฌ๐ง
thetomtaylor.co.uk
2026-10-10 05:07:02
(1 day ago)
Fail2Ban - [WEB]Custom exploit pattern detected on customexploits ... [ice01,wa01,wa02]
Hacking
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-10-10 05:01:12
(1 day ago)
Web attack/malicious scanning detected
Web App Attack
๐จ๐ฆ
Anytech
2026-10-10 04:54:18
(1 day ago)
Blocked by Conn-Monitor: env-probing
Web App Attack
Hacking
๐บ๐ธ
WPJoe
2026-10-10 04:22:09
(1 day ago)
158.173.165.58 - - [10/Oct/2026:04:22:00 +0000] "GET /.env HTTP/1.1" 301 529 "-" "Mozilla/5.0 (Linux ...
show more
158.173.165.58 - - [10/Oct/2026:04:22:00 +0000] "GET /.env HTTP/1.1" 301 529 "-" "Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30"
158.173.165.58 - - [10/Oct/2026:04:22:08 +0000] "GET /.env HTTP/1.1" 403 4419 "-" "Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30"
...
show less
Web App Attack
Bad Web Bot
๐ฌ๐ง
thetomtaylor.co.uk
2026-10-10 04:08:00
(1 day ago)
Fail2Ban - [WEB]Custom exploit pattern detected on customexploits ... [ice02]
Hacking
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
interbiznw.com
2026-10-10 02:45:09
(1 day ago)
malicious-web-requests-vulnerability-scanning
Hacking
Brute-Force
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-10 01:32:04
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 158.173.165.58 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 158.173.165.58 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 21:32:00.525714 2026] [security2:error] [pid 26069:tid 26069] [client 158.173.165.58:24545] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.sicktrax.com"] [uri "/.env"] [unique_id "asmVkLKx_ycXmq8vIkb76wAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
MyGlobalFlowers
2026-10-10 01:30:08
(1 day ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-10 01:06:57
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 158.173.165.58 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 158.173.165.58 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 21:06:53.254208 2026] [security2:error] [pid 26151:tid 26151] [client 158.173.165.58:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.empoweruamerica.org"] [uri "/.env"] [unique_id "asmPrQPLd-zZ3rKSxgYongAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Kejult
2026-10-08 09:37:11
(3 days ago)
Honeypot Finding: verified TCP multi-port scan/probing; 5 application-level events across 2 target p ...
show more
Honeypot Finding: verified TCP multi-port scan/probing; 5 application-level events across 2 target ports and 3 source port(s). Ports: 80/HTTP, 443/HTTPS. Sensors: Tanner, H0neytr4p.
show less
Port Scan
๐บ๐ธ
ambor
2026-10-08 08:55:13
(3 days ago)
Attack type: honeypot_lure | Target: /.env | UA: Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NO ...
show more
Attack type: honeypot_lure | Target: /.env | UA: Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NO | Country: MY
show less
Hacking
๐ณ๐ฑ
Alt255
2026-10-08 08:54:00
(3 days ago)
[ti-24al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-24al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 158.173.165.58 - - [08/Oct/2026:10:53:52 +0200] "GET /.env HTTP/1.1" 301 612 "-" "Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30"
...
show less
Bad Web Bot
Web App Attack
๐ฆ๐บ
nzhost.co.nz
2026-10-08 08:39:31
(3 days ago)
$f2bV_matches
Hacking
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-10-08 08:20:55
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 158.173.165.58 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 158.173.165.58 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 04:20:48.064424 2026] [security2:error] [pid 1190:tid 1190] [client 158.173.165.58:24433] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gre-home.com"] [uri "/.env"] [unique_id "asdSYNQ3eBGTMz0mnZ16vwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-31 02:28:00
(2 months ago)
wordpress webshell
Web App Attack
Hacking