๐ง๐ช
boxed-it
2026-07-24 07:26:27
(1 day ago)
GET /.env (Tarpitted for 1d15h8m28s, wasted 8.06MB)
Web App Attack
๐ฉ๐ช
Balthasar Morpheus Jรถrmundur (JKweb Service)
2026-07-23 07:04:20
(2 days ago)
JKweb Security: Severe and dangerous web attack detected. Attacker permanently banned by Fail2Ban.
Port Scan
Bad Web Bot
Web App Attack
๐ฎ๐ณ
evicky2002
2026-07-23 06:00:00
(2 days ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐ซ๐ฎ
kumiko
2026-07-22 18:15:31
(2 days ago)
[2026-07-22 21:15:30] Probing for dotfiles
"GET /.env.0 HTTP/1.1" 403
Bad Web Bot
Web App Attack
Anonymous
2026-07-22 17:12:52
(2 days ago)
Jul 22 19:12:51 mail2 Nextcloud[200142]: {"reqId":"amD6E65Dn3ILsRqaVy3I1AAAAE8","level":1,"time":"20 ...
show more
Jul 22 19:12:51 mail2 Nextcloud[200142]: {"reqId":"amD6E65Dn3ILsRqaVy3I1AAAAE8","level":1,"time":"2026-07-22T17:12:51+00:00","remoteAddr":"172.236.150.179","user":"--","app":"core","method":"GET","url":"/.env.1","scriptName":"/index.php","message":"Trusted domain error. \"172.236.150.179\" tried to access using \"cloud.akcurate.de\" as host.","userAgent":"Mozilla/5.0 (X11; Linux x86_64; rv:134.0) Gecko/20100101 Firefox/134.0","version":"32.0.9.2","data":{"app":"core"}}
Jul 22 19:12:51 mail2 Nextcloud[178948]: {"reqId":"amD6E65Dn3ILsRqaVy3I1QAAAFU","level":1,"time":"2026-07-22T17:12:51+00:00","remoteAddr":"172.236.150.179","user":"--","app":"core","method":"GET","url":"/.env.0","scriptName":"/index.php","message":"Trusted domain error. \"172.236.150.179\" tried to access using \"cloud.akcurate.de\" as host.","userAgent":"Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:134.0) Gecko/20100101 Firefox/134.0","version":"32.0.9.2","data":{"app":"core"}}
Jul 22 19:12:51 mail2 Nextcloud[256894]: {
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
MatCat
2026-07-22 16:05:15
(2 days ago)
Banned by fail2ban: apache-webprobe
Port Scan
Bad Web Bot
๐บ๐ธ
its101
2026-07-22 15:35:04
(2 days ago)
Automated detection by LockdownAccess security system. Attack type(s): env_grab. Reason: Nginx: env_ ...
show more
Automated detection by LockdownAccess security system. Attack type(s): env_grab. Reason: Nginx: env_grab attack. Path targeted: unknown. Blocked in Cloudflare.
show less
Web App Attack
๐ฌ๐ง
sc user
2026-07-22 15:24:12
(2 days ago)
Fail2Ban nginx: repeated suspicious HTTP requests consistent with automated probing, scanning or bad ...
show more
Fail2Ban nginx: repeated suspicious HTTP requests consistent with automated probing, scanning or bad bot behaviour. Technical log details and local server identifiers intentionally omitted for privacy.
show less
Bad Web Bot
Web App Attack
Port Scan
๐บ๐ฆ
URAN Publishing Service
2026-07-22 14:48:08
(2 days ago)
172.236.150.179 - - [22/Jul/2026:17:48:06 +0300] "GET /.env HTTP/1.1" 404 764 "-" "Mozilla/5.0 (Wind ...
show more
172.236.150.179 - - [22/Jul/2026:17:48:06 +0300] "GET /.env HTTP/1.1" 404 764 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
172.236.150.179 - - [22/Jul/2026:17:48:06 +0300] "GET /tools/.env HTTP/1.1" 404 764 "-" "Mozilla/5.0 (Linux; Android 14; SM-S928B) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Mobile Safari/537.36"
...
show less
Web App Attack
๐ธ๐ช
KIDOS
2026-07-22 14:27:52
(2 days ago)
Apache monitor: ssrf_log_spoofing
Brute-Force
SSH
๐บ๐ธ
Matthew Ping
2026-07-22 14:15:01
(3 days ago)
ModSecurity rule 949110 triggered on d865. Web application attack blocked by CSF/LFD.
Web App Attack
Hacking
Anonymous
2026-07-22 13:11:18
(3 days ago)
172.236.150.179 - - [22/Jul/2026:13:11:17 +0000] "GET /.env.build HTTP/1.1" 404 8798 "-" "Mozilla/5. ...
show more
172.236.150.179 - - [22/Jul/2026:13:11:17 +0000] "GET /.env.build HTTP/1.1" 404 8798 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.2 Safari/605.1.15"
...
show less
Brute-Force
Web App Attack
๐ง๐ฌ
pa4080
2026-07-22 13:02:59
(3 days ago)
Detected by ModSecurity. Host header is an IP address, Request URI: /
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-22 13:01:50
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 172.236.150.179 (172-236-150-179.ip.linodeuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 172.236.150.179 (172-236-150-179.ip.linodeusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 22 09:01:42.348655 2026] [security2:error] [pid 958155:tid 958155] [client 172.236.150.179:38110] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "noel-designs.com.stormwlf.com"] [uri "/.env"] [unique_id "amC_Np8tP4fGIOunnexJIgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-22 12:02:33
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 172.236.150.179 (172-236-150-179.ip.linodeuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 172.236.150.179 (172-236-150-179.ip.linodeusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 22 08:02:26.957042 2026] [security2:error] [pid 971287:tid 971287] [client 172.236.150.179:38842] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nordicbuilders.net"] [uri "/.env.build"] [unique_id "amCxUgsOw5QuZQWrkxWKtgAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack