๐บ๐ธ
gu-alvareza
2026-09-13 05:06:14
(3 days ago)
AndroxGh0st.Malware
Hacking
Exploited Host
๐บ๐ธ
TPI-Abuse
2026-09-13 01:46:05
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 172.233.243.178 (172-233-243-178.ip.linodeuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 172.233.243.178 (172-233-243-178.ip.linodeusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 21:45:59.825861 2026] [security2:error] [pid 21599:tid 21599] [client 172.233.243.178:53478] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.19"] [uri "/.env"] [unique_id "aqYAV79T9Hgks8H6WVJZFQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
kosada.com
2026-09-13 01:33:33
(3 days ago)
Repeated requests for suspicious nonexistent URLs, for example: /.env (HTTP/1.1 port 80, bogus vhost ...
show more
Repeated requests for suspicious nonexistent URLs, for example: /.env (HTTP/1.1 port 80, bogus vhost, user agent: "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36")
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-13 01:28:09
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 172.233.243.178 (172-233-243-178.ip.linodeuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 172.233.243.178 (172-233-243-178.ip.linodeusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 21:28:05.128231 2026] [security2:error] [pid 10694:tid 10694] [client 172.233.243.178:63240] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.53"] [uri "/.env"] [unique_id "aqX8JaNbLAqr3EbhqV6jRgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
donarev419
2026-09-13 01:24:39
(3 days ago)
Connection to port 80 with data transfer.
Data preview: GET /.env HTTP/1.1
Host: 167.253.66.144
Us ...
show more
Connection to port 80 with data transfer.
Data preview: GET /.env HTTP/1.1
Host: 167.253.66.144
User-agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/53
show less
Port Scan
Hacking
๐ฌ๐ง
Smish
2026-09-13 01:24:31
(3 days ago)
HONEYPOT HIT --> Fail2ban time=1789262670 log=2026-09-13T02:24:30+01:00 ip=172.233.243.178 host=89.3 ...
show more
HONEYPOT HIT --> Fail2ban time=1789262670 log=2026-09-13T02:24:30+01:00 ip=172.233.243.178 host=89.39.211.7 method=GET uri="/.env" status=404 ua="Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" ref="-" rid=0d4c96cc16bc8f7b73d8e59253d1fe04
show less
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-09-13 01:20:06
(3 days ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-13 01:10:21
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 172.233.243.178 (172-233-243-178.ip.linodeuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 172.233.243.178 (172-233-243-178.ip.linodeusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 21:10:14.610666 2026] [security2:error] [pid 6448:tid 6448] [client 172.233.243.178:49382] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.142"] [uri "/.env"] [unique_id "aqX39hg_bRfB9Uhph9epzAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
thetomtaylor.co.uk
2026-09-13 01:05:04
(3 days ago)
Fail2Ban - [WEB]Custom exploit pattern detected on customexploits ... [ice01,ice02,wa01,wa02]
Hacking
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ช
AutosOnShow
2026-09-13 01:04:05
(3 days ago)
blocked for webapp attack | path requested: /.env | seen at 2026-09-13 01:03:44.767 |
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-13 00:54:21
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 172.233.243.178 (172-233-243-178.ip.linodeuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 172.233.243.178 (172-233-243-178.ip.linodeusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 20:54:14.412149 2026] [security2:error] [pid 1228:tid 1228] [client 172.233.243.178:51551] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.7"] [uri "/.env"] [unique_id "aqX0NrbU0MAazDdS6UeYegAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-13 00:53:58
(3 days ago)
Fail2Ban triggered
Web App Attack
๐ฌ๐ง
[email protected]
2026-09-13 00:51:15
(3 days ago)
Automated report [Server: quest1]: IP caught scanning and attacking Aison Active Defense Honeypot tr ...
show more
Automated report [Server: quest1]: IP caught scanning and attacking Aison Active Defense Honeypot traps.
show less
Port Scan
Hacking
Brute-Force
๐ธ๐ช
eagle
2026-09-13 00:39:54
(3 days ago)
172.233.243.178 - - [13/Sep/2026:00:39:54 +0000] "GET /.env HTTP/1.1" 301 162 "-" "Mozilla/5.0 (X11; ...
show more
172.233.243.178 - - [13/Sep/2026:00:39:54 +0000] "GET /.env HTTP/1.1" 301 162 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-13 00:36:49
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 172.233.243.178 (172-233-243-178.ip.linodeuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 172.233.243.178 (172-233-243-178.ip.linodeusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 20:36:43.082898 2026] [security2:error] [pid 2970:tid 2970] [client 172.233.243.178:65077] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.114"] [uri "/.env"] [unique_id "aqXwGwCgogDPByvDzIVI2gAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack