๐ฉ๐ช
thesimonmanuel
2026-07-26 23:28:28
(8 hours ago)
169.58.45.73 - - [27/Jul/2026:04:58:27 +0530] "GET /.env HTTP/1.1" 403 117 "-" "Mozilla/5.0 (Macinto ...
show more
169.58.45.73 - - [27/Jul/2026:04:58:27 +0530] "GET /.env HTTP/1.1" 403 117 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.4.1 Safari/605.1.15" "-"
show less
Web App Attack
๐ฌ๐ง
openstrike.co.uk
2026-07-25 05:14:51
(2 days ago)
2 attacks on env grabbing URLs:
GET /.env.production HTTP/1.1
Hacking
๐บ๐ธ
interbiznw.com
2026-07-24 19:52:58
(2 days ago)
fail2ban-ban
Hacking
Brute-Force
Exploited Host
Web App Attack
๐บ๐ธ
HamSammich
2026-07-24 08:06:30
(2 days ago)
Automated sensor: 1 HTTPS connection/probe attempts over the last 24h (latest 2026-07-24T08:06Z).
Brute-Force
Web App Attack
๐ณ๐ฑ
hxsain
2026-07-23 19:12:23
(3 days ago)
Triggered Cloudflare WAF (firewallCustom) from FR.
Action: BLOCK | Protocol: HTTP/1.1 (GET) | Endpoi ...
show more
Triggered Cloudflare WAF (firewallCustom) from FR.
Action: BLOCK | Protocol: HTTP/1.1 (GET) | Endpoint: /.env | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:133.0) Gecko/20100101 Firefox/133.0 โข Generated by: github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-07-23 17:50:57
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 169.58.45.73 (vmi3452647.contaboserver.net): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 169.58.45.73 (vmi3452647.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 13:50:48.482387 2026] [security2:error] [pid 75895:tid 75895] [client 169.58.45.73:41622] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "keithhooperteam.com"] [uri "/.env"] [unique_id "amJUeCXuFkA9gzdky6vuZQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-23 10:44:44
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 169.58.45.73 (vmi3452647.contaboserver.net): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 169.58.45.73 (vmi3452647.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 06:44:39.351487 2026] [security2:error] [pid 2216785:tid 2216785] [client 169.58.45.73:36134] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sarrisbilliards.com"] [uri "/.env"] [unique_id "amHwl99clBMQcrgj8-lK6wAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
HamSammich
2026-07-23 08:08:46
(3 days ago)
Automated sensor: 1 HTTPS connection/probe attempts over the last 24h (latest 2026-07-23T08:08Z).
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-22 13:22:47
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 169.58.45.73 (vmi3452647.contaboserver.net): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 169.58.45.73 (vmi3452647.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 22 09:22:39.855745 2026] [security2:error] [pid 2140570:tid 2140570] [client 169.58.45.73:37598] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "birdsofnewcaledonia.com"] [uri "/.env"] [unique_id "amDEH73ukSiIriutj5eeuwAAACs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Rom74
2026-07-21 22:08:44
(5 days ago)
[Wed Jul 22 00:08:43.862625 2026] [security2:error] [pid 1915964:tid 132156386952896] [client 169.58 ...
show more
[Wed Jul 22 00:08:43.862625 2026] [security2:error] [pid 1915964:tid 132156386952896] [client 169.58.45.73:50156] [client 169.58.45.73] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "unreflexeunevie.fr"] [uri "/config.json"] [unique_id "al_t64gMlVDbSShy9C4a6QAAAFc"]
[Wed Jul 22 00:08:43.862654 2026] [security2:error] [pid 1915962:tid 132157141935808] [client 169.58.45.73:50170] [client 169.58.45.73] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded
...
show less
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-07-21 21:59:37
(5 days ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-07-20.
show less
Web App Attack
SSH
Hacking
๐ท๐บ
DZBOT
2026-07-21 08:05:42
(5 days ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐บ๐ธ
HamSammich
2026-07-21 08:03:11
(5 days ago)
Automated sensor: 1 HTTPS connection/probe attempts over the last 24h (latest 2026-07-21T08:03Z).
Brute-Force
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-07-20 21:59:18
(6 days ago)
Auto-ban: >3000 req/min op 2026-07-20
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-07-20 07:07:14
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 169.58.45.73 (vmi3452647.contaboserver.net): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 169.58.45.73 (vmi3452647.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 03:07:06.057110 2026] [security2:error] [pid 3646225:tid 3646225] [client 169.58.45.73:44538] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "agkgt.org"] [uri "/.env"] [unique_id "al3JGpIxWZWzrTu2hB2J2QAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack