๐บ๐ธ
TPI-Abuse
2026-10-08 13:10:47
(16 minutes ago)
(mod_security) mod_security (id:210492) triggered by 160.177.3.196 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 160.177.3.196 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 09:10:39.574838 2026] [security2:error] [pid 12956:tid 12956] [client 160.177.3.196:36756] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "internationalavionics.com"] [uri "/.env"] [unique_id "aseWTwg3rRKECK-SbQp3gAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Charlesiv
2026-10-08 12:07:59
(1 hour ago)
Triggered Cloudflare WAF (firewallCustom) from MA.
Action taken: BLOCK
ASN: 36903 (Office National d ...
show more
Triggered Cloudflare WAF (firewallCustom) from MA.
Action taken: BLOCK
ASN: 36903 (Office National des Postes et Telecommunications ONPT (Maroc Telecom) / IAM)
Protocol: HTTP/1.1 (GET method)
Endpoint: /.env
Timestamp: 2026-10-08T11:59:55Z
Ray ID: a474fb768aea4aaf
UA: Empty string
show less
Bad Web Bot
๐ฉ๐ช
Teufel100
2026-10-08 12:01:40
(1 hour ago)
ModSecurity rejected a query
Brute-Force
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 11:59:54
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 160.177.3.196 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 160.177.3.196 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 07:59:50.576090 2026] [security2:error] [pid 23987:tid 23987] [client 160.177.3.196:48236] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "web15.dnchosting.com"] [uri "/.env"] [unique_id "aseFttbpN54Af4YEJMT0DgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
[email protected]
2026-10-08 11:47:40
(1 hour ago)
Fail2Ban jail apache-json-scanners detected activity on 2026-10-08T11:47:40Z
Brute-Force
๐ต๐ฑ
Budyn
2026-10-08 11:44:03
(1 hour ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: admin.astropot.website | URI: /.env | UA: Unknown User-Agent | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
RH5
2026-10-08 11:40:57
(1 hour ago)
Restricted URL probing (/.env) (UTC 2026-10-08 11:40)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 11:35:48
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 160.177.3.196 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 160.177.3.196 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 07:35:41.732635 2026] [security2:error] [pid 17503:tid 17503] [client 160.177.3.196:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.byloveshand.com"] [uri "/.env"] [unique_id "aseADWnq499zv0wRfql8kAAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 11:03:46
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 160.177.3.196 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 160.177.3.196 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 07:03:39.715954 2026] [security2:error] [pid 17173:tid 17173] [client 160.177.3.196:40152] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "web202.dnchosting.com"] [uri "/.env"] [unique_id "asd4i5LSIA3kmePYop0BCAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
sdos.es
2026-10-08 10:53:29
(2 hours ago)
"Restricted File Access Attempt - Matched Data: /.env found within REQUEST_FILENAME: /.env"
Web App Attack
๐ฉ๐ฐ
HostingGroup
2026-10-08 10:31:53
(2 hours ago)
Automated malicious activity (Honeypot Trap) detected and blocked at the CDN edge by NordicCDN Shiel ...
show more
Automated malicious activity (Honeypot Trap) detected and blocked at the CDN edge by NordicCDN Shield. Offenses: 2. First blocked: 2026-10-08.
show less
Bad Web Bot
Web App Attack
๐จ๐ฆ
alexbfr
2026-10-08 10:25:37
(3 hours ago)
Fail2Ban report from nginx-bot-trap; automated HTTP honeypot detection.
Web App Attack
๐บ๐ธ
LotPhantom
2026-10-08 10:10:28
(3 hours ago)
2026/10/08 10:10:27 [error] 3718516#3718516: *57233 access forbidden by rule, client: 160.177.3.196, ...
show more
2026/10/08 10:10:27 [error] 3718516#3718516: *57233 access forbidden by rule, client: 160.177.3.196, server: wynnesmiles.com, request: "GET /.env HTTP/1.1", host: "wynnesmiles.com"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 09:50:18
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 160.177.3.196 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 160.177.3.196 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 05:50:10.208267 2026] [security2:error] [pid 30498:tid 30498] [client 160.177.3.196:50052] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "web227.dnchosting.com"] [uri "/.env"] [unique_id "asdnUhoUYfnbJYNBTBn0uwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
[email protected]
2026-10-08 09:33:05
(3 hours ago)
Fail2Ban jail apache-json-scanners detected activity on 2026-10-08T09:33:05Z
Brute-Force