๐จ๐ญ
๐จ๐ญ Hosting
2026-07-02 05:10:14
(1 month ago)
Automated WAF report: 175-200 blocked requests from this IP detected by our WAF.
Bad Web Bot
Web App Attack
๐ฎ๐น
paoloartone
2026-07-02 05:00:04
(1 month ago)
Reverse proxy TCO: 62 richieste malevole bloccate (scan/exploit/brute-force WordPress) il 01/07/2026 ...
show more
Reverse proxy TCO: 62 richieste malevole bloccate (scan/exploit/brute-force WordPress) il 01/07/2026.
show less
Web App Attack
Hacking
Port Scan
๐ฉ๐ช
on-com
2026-07-02 04:50:22
(1 month ago)
URL scan
Brute-Force
Web App Attack
๐ณ๐ฑ
Site.eu
2026-07-02 04:24:42
(1 month ago)
Excessive multi-domain requests
Brute-Force
๐ซ๐ท
ELYAZ
2026-07-02 03:32:52
(1 month ago)
(y3) Failed access -byebye- from 167.86.80.238 (DE/Germany/smtp.vhost.store): (CF_ENABLE)
Hacking
Anonymous
2026-07-02 03:03:49
(1 month ago)
fail2ban_an apache-modsecurity [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [uri "/.env.a ...
show more
fail2ban_an apache-modsecurity [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [uri "/.env.azure"]
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
AetherFox
2026-07-02 02:50:37
(1 month ago)
AetherFox VoidGuard detected: [Thu Jul 02 02:50:36.400641 2026] [authz_core:error] [pid 3226035:tid ...
show more
AetherFox VoidGuard detected: [Thu Jul 02 02:50:36.400641 2026] [authz_core:error] [pid 3226035:tid 3226086] [client 167.86.80.238:48538] AH01630: client denied by server configuration: proxy:http://[MASKED]/.env.prod
[Thu Jul 02 02:50:36.400860 2026] [authz_core:error] [pid 3226035:tid 3226086] [client 167.86.80.238:48538] AH01630: client denied by server configuration: /var/www/html/ERRORpages/403.html
[Thu Jul 02 02:50:36.412333 2026] [authz_core:error] [pid 3226034:tid 3226074] [client 167.86.80.238:48618] AH01630: client denied by server configuration: proxy:http://[MASKED]/.env.sample.php
[Thu Jul 02 02:50:36.412430 2026] [authz_core:error] [pid 3226034:tid 3226037] [client 167.86.80.238:48582] AH01630: client denied by server configuration: proxy:http://[MASKED]/.env.queue
[Thu Jul 02 02:50:36.412442 2026] [authz_core:error] [pid 3226035:tid 3226082] [client 167.86.80.238:48562] AH01630: client denied by server configuration: proxy:http://[MASKED]
...
show less
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-07-02 02:35:37
(1 month ago)
Multiple WAF Violations
Web App Attack
Anonymous
2026-07-02 02:20:48
(1 month ago)
167.86.80.238 - - [02/Jul/2026:02:20:47 +0000] "GET /.env.dist HTTP/1.1" 302 491 "-" "Mozilla/5.0 (X ...
show more
167.86.80.238 - - [02/Jul/2026:02:20:47 +0000] "GET /.env.dist HTTP/1.1" 302 491 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/123.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
interbiznw.com
2026-07-02 01:54:34
(1 month ago)
malicious-web-requests-vulnerability-scanning
Hacking
Brute-Force
Exploited Host
Web App Attack
Anonymous
2026-07-02 01:51:22
(1 month ago)
167.86.80.238 - - [02/Jul/2026:01:51:22 +0000] "GET /.env.2 HTTP/1.1" 302 493 "-" "Mozilla/5.0 (Maci ...
show more
167.86.80.238 - - [02/Jul/2026:01:51:22 +0000] "GET /.env.2 HTTP/1.1" 302 493 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
๐ช๐ธ
alferez
2026-07-02 01:27:12
(1 month ago)
Searching .(env|sql|zip|tar|rar) files
Hacking
Exploited Host
Web App Attack
๐ฉ๐ฐ
ScamAware
2026-07-01 23:16:10
(2 months ago)
Detected by Cloudflare Security Events via WordPress automation. Detection: sensitive_files (Sensiti ...
show more
Detected by Cloudflare Security Events via WordPress automation. Detection: sensitive_files (Sensitive files, source control, config, and backups). Hits from same IP in last 60 minutes: 24. Unique request paths counted internally: 24. Cloudflare action: block. Cloudflare source: firewallCustom.
show less
Web App Attack
๐ซ๐ท
SpaceHost-Server
2026-07-01 22:41:12
(2 months ago)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-01 22:14:35
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 167.86.80.238 (smtp.vhost.store): 1 in the last ...
show more
(mod_security) mod_security (id:210492) triggered by 167.86.80.238 (smtp.vhost.store): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 01 18:14:28.129172 2026] [security2:error] [pid 8267:tid 8267] [client 167.86.80.238:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "local639.com"] [uri "/.env.0"] [unique_id "akWRROj2akveV39UxiumRAAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack