π§π·
Peregrine
2026-07-08 03:09:17
(2 weeks ago)
Fail2Ban Jail: tomcat-honeypot | Evidence: 170.106.117.163 104.22.20.123 - - [04/Jul/2026:02:40:59 - ...
show more
Fail2Ban Jail: tomcat-honeypot | Evidence: 170.106.117.163 104.22.20.123 - - [04/Jul/2026:02:40:59 -0300] "GET /.env HTTP/1.1" 404 414
show less
Bad Web Bot
π§π·
Peregrine
2026-07-06 03:09:12
(2 weeks ago)
Fail2Ban Jail: tomcat-honeypot | Evidence: 170.106.117.163 104.22.20.123 - - [04/Jul/2026:02:40:59 - ...
show more
Fail2Ban Jail: tomcat-honeypot | Evidence: 170.106.117.163 104.22.20.123 - - [04/Jul/2026:02:40:59 -0300] "GET /.env HTTP/1.1" 404 414
show less
Bad Web Bot
πΊπΈ
Epimetheus
2026-07-04 07:08:35
(2 weeks ago)
Unauthorized access attempts:
[GET] /.env
[GET] /.env
UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 1 ...
show more
Unauthorized access attempts:
[GET] /.env
[GET] /.env
UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0
show less
Web App Attack
πΊπΈ
ArturShelby
2026-07-04 06:46:38
(2 weeks ago)
Critical file access: /.env
Web App Attack
πΊπΈ
jsjdmediallc
2026-07-04 06:40:06
(2 weeks ago)
Auto-blocked: score 70 (threshold 10). Tier: HIGH. Hits: 9. Flags: env-file. Paths: /.env, /.env, /. ...
show more
Auto-blocked: score 70 (threshold 10). Tier: HIGH. Hits: 9. Flags: env-file. Paths: /.env, /.env, /.env, /.env, /.env
show less
Bad Web Bot
Web App Attack
π΅π±
sefinek.net
2026-07-04 06:21:24
(2 weeks ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action: BLOCK | Protocol: HTTP/1.1 (GET) | Endpoi ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action: BLOCK | Protocol: HTTP/1.1 (GET) | Endpoint: /.env | UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0 β’ Generated by: github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
π§π·
Peregrine
2026-07-04 05:41:06
(2 weeks ago)
Fail2Ban Jail: tomcat-honeypot | Evidence: 170.106.117.163 104.22.20.123 - - [04/Jul/2026:02:40:59 - ...
show more
Fail2Ban Jail: tomcat-honeypot | Evidence: 170.106.117.163 104.22.20.123 - - [04/Jul/2026:02:40:59 -0300] "GET /.env HTTP/1.1" 404 414
show less
Bad Web Bot
πΊπΈ
Epimetheus
2026-07-04 04:50:35
(2 weeks ago)
Unauthorized access attempts:
[GET] /.env
UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77. ...
show more
Unauthorized access attempts:
[GET] /.env
UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0
show less
Web App Attack
π«π·
Baking333
2026-07-04 03:54:17
(2 weeks ago)
[redacted] 170.106.117.163 - - [04/Jul/2026:04:34:01 +0100] "GET /.env HTTP/1.1" 302 6783 0/89614 "- ...
show more
[redacted] 170.106.117.163 - - [04/Jul/2026:04:34:01 +0100] "GET /.env HTTP/1.1" 302 6783 0/89614 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0" [redacted] 170.106.117.163 - - [04/Jul/2026:04:54:16 +0100] "GET /.env HTTP/1.1" 302 6743 0/56792 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0"
show less
Bad Web Bot
Web App Attack
πΊπΈ
nationaleventpros.com
2026-07-04 03:08:44
(2 weeks ago)
vulnerability scan
Web App Attack
π³π±
homeshowdomain.nl
2026-07-03 21:59:07
(2 weeks ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-07-02.
show less
Web App Attack
SSH
Hacking
ππΊ
kranem
2026-07-03 15:00:07
(2 weeks ago)
Triggered Cloudflare WAF from US.
Action taken: BLOCK
ASN: 132203 (Tencent Building, Kejizhongyi Ave ...
show more
Triggered Cloudflare WAF from US.
Action taken: BLOCK
ASN: 132203 (Tencent Building, Kejizhongyi Avenue)
Protocol: HTTP/1.1 (GET method)
Endpoint: /.env
Timestamp: 2026-07-03T14:31:39Z
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0
show less
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-07-03 14:15:56
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 170.106.117.163 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 170.106.117.163 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 03 10:15:51.100647 2026] [security2:error] [pid 6073:tid 6073] [client 170.106.117.163:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pixacast.com"] [uri "/.env"] [unique_id "akfEF5qN19dPj0uegaTvRAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-03 14:06:39
(2 weeks ago)
Automated report (2026-07-03T10:06:39-04:00). Caught probing for env file.
Hacking
Web App Attack
π±π»
garmtech.com
2026-07-03 13:16:53
(2 weeks ago)
IM360 WAF: Direct access to sensitive file or dotfile MV:/.env
Web App Attack