๐บ๐ธ
TPI-Abuse
2026-09-24 09:57:05
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.179.0.102 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.179.0.102 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 05:57:02.099255 2026] [security2:error] [pid 4592:tid 4592] [client 172.179.0.102:56698] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "northstar-village.org"] [uri "/.env"] [unique_id "arTz7l7ddgPAoS-GjBeKvgAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
craudiovizai
2026-09-23 18:30:33
(2 days ago)
Automated honeypot detection. honeypot against a Next.js application. Paths: /.env. Blocked at the e ...
show more
Automated honeypot detection. honeypot against a Next.js application. Paths: /.env. Blocked at the edge.
show less
Web App Attack
Bad Web Bot
๐จ๐ญ
lufi
2026-09-23 17:57:36
(2 days ago)
2026-09-23 19:57:36 172.179.0.102: blacklistedPath: /.env
...
Web Spam
Brute-Force
Hacking
Web App Attack
๐ซ๐ท
regishoussin
2026-09-23 17:52:57
(2 days ago)
Automated web scanning detected by Wazuh (rule 100241): repeated 400/404 errors from mass probing of ...
show more
Automated web scanning detected by Wazuh (rule 100241): repeated 400/404 errors from mass probing of admin/backdoor paths (e.g. wp-login.php, known CMS shell filenames) on an Apache web server, on 2026-09-23 17:52 UTC.
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-09-23 17:19:57
(2 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 12
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 17:16:17
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 172.179.0.102 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.179.0.102 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 13:16:09.753252 2026] [security2:error] [pid 15072:tid 15072] [client 172.179.0.102:61755] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jackieherbach.com"] [uri "/.env"] [unique_id "arQJWRW71QqOhtFK630_hwAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 16:24:51
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 172.179.0.102 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.179.0.102 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 12:24:46.847849 2026] [security2:error] [pid 9901:tid 9901] [client 172.179.0.102:52126] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "marydeal.com"] [uri "/.env"] [unique_id "arP9TqJKqtOwiVKqRO_gBwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ต๐ฑ
Budyn
2026-09-23 15:41:58
(2 days ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit Block. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: sweetpuddingtrap.online | URI: /.env | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 | BODY: [Empty / GET Request]
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 15:26:02
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 172.179.0.102 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.179.0.102 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 11:25:58.738220 2026] [security2:error] [pid 612:tid 612] [client 172.179.0.102:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ndanetworks.com"] [uri "/.env"] [unique_id "arPvhtYuALeAISayVujKxwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
interbiznw.com
2026-09-23 15:05:44
(2 days ago)
malicious-web-requests-vulnerability-scanning
Hacking
Brute-Force
Exploited Host
Web App Attack
๐ฉ๐ช
Vegascosmetics
2026-09-23 14:20:03
(2 days ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after sensitive config/credentials exposure ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after sensitive config/credentials exposure probe. Evidence: AttackPattern: /\.env (Match: /.env)
show less
Hacking
Brute-Force
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-23 14:16:47
(2 days ago)
[ti-17al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-17al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 172.179.0.102 - - [23/Sep/2026:16:16:44 +0200] "GET /.env HTTP/1.1" 404 7839 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 13:18:03
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 172.179.0.102 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.179.0.102 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 09:17:58.140969 2026] [security2:error] [pid 32196:tid 32196] [client 172.179.0.102:49189] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "naturalunfinishedfurniture.com"] [uri "/.env"] [unique_id "arPRhhkZh8j292gQPKKwMgAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
cwytech
2026-09-23 11:37:51
(2 days ago)
Fleet-wide ban from the Ghostfleet ๐ป. Triggered by scenario: cwy/tpot-http-sensitive-files.
Bad Web Bot
Web App Attack
๐บ๐ธ
RamSet
2026-09-23 11:29:17
(2 days ago)
[swy,ycr] HTTP-Probe on port 443 (via domain). 1 distinct paths probed in 1s. Sustained 3 req/min. P ...
show more
[swy,ycr] HTTP-Probe on port 443 (via domain). 1 distinct paths probed in 1s. Sustained 3 req/min. Paths: /.env
show less
Bad Web Bot
Web App Attack