๐ซ๐ท
SpaceHost-Server
2026-01-14 23:33:42
(4 months ago)
Brute-Force
Web App Attack
๐ฒ๐พ
Rizzy
2026-01-13 21:18:58
(5 months ago)
Multiple WAF Violations
Brute-Force
Web App Attack
Anonymous
2026-01-13 19:03:56
(5 months ago)
178.128.48.43 - - [13/Jan/2026:19:03:55 +0000] "GET /.env.save HTTP/1.1" 404 6138 "-" "Mozilla/5.0 ( ...
show more
178.128.48.43 - - [13/Jan/2026:19:03:55 +0000] "GET /.env.save HTTP/1.1" 404 6138 "-" "Mozilla/5.0 (X11; Linux x86_64)"
...
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
macrob
2026-01-13 17:47:54
(5 months ago)
2026/01/13 17:47:53 [error] 989789#989789: *226059244 access forbidden by rule, client: 178.128.48.4 ...
show more
2026/01/13 17:47:53 [error] 989789#989789: *226059244 access forbidden by rule, client: 178.128.48.43, server: finami.ph, request: "GET /.env HTTP/2.0", host: "finami.ph"
2026/01/13 17:47:53 [error] 989786#989786: *226059482 access forbidden by rule, client: 178.128.48.43, server: finami.ph, request: "GET /.env.production HTTP/2.0", host: "finami.ph"
2026/01/13 17:47:53 [error] 989789#989789: *226059682 access forbidden by rule, client: 178.128.48.43, server: finami.ph, request: "GET /.env.save HTTP/2.0", host: "finami.ph"
...
show less
Web App Attack
๐ต๐น
Information Security
2026-01-13 14:04:30
(5 months ago)
Web App Attack
Web App Attack
๐บ๐ธ
myagent.site
2026-01-13 13:13:27
(5 months ago)
Blocking for trying to access an exploit file: /.env.production
Hacking
๐ต๐ฑ
sefinek.net
2026-01-13 12:13:02
(5 months ago)
Triggered Cloudflare WAF (firewallCustom) from SG.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET metho ...
show more
Triggered Cloudflare WAF (firewallCustom) from SG.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /.env.save
UA: Mozilla/5.0 (X11; Linux x86_64)
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
Anonymous
2026-01-13 10:20:09
(5 months ago)
FortiWeb WAF: 96 attacks detected. Threat Score: 38200. Types: Client Management(48), GEO IP(48). Or ...
show more
FortiWeb WAF: 96 attacks detected. Threat Score: 38200. Types: Client Management(48), GEO IP(48). Origin: Singapore.
show less
Web App Attack
๐ต๐ฑ
nfsec.pl
2026-01-13 10:13:09
(5 months ago)
178.128.48.43 - - [13/Jan/2026:10:13:08 +0000] "GET /.env.production HTTP/1.1" 403 9176 "-" "Mozilla ...
show more
178.128.48.43 - - [13/Jan/2026:10:13:08 +0000] "GET /.env.production HTTP/1.1" 403 9176 "-" "Mozilla/5.0 (X11; Linux x86_64)"
178.128.48.43 - - [13/Jan/2026:10:13:08 +0000] "GET /.env HTTP/1.1" 403 9176 "-" "Mozilla/5.0 (X11; Linux x86_64)"
178.128.48.43 - - [13/Jan/2026:10:13:08 +0000] "GET /.env.save HTTP/1.1" 403 9176 "-" "Mozilla/5.0 (X11; Linux x86_64)"
178.128.48.43 - - [13/Jan/2026:10:13:08 +0000] "GET /app/.env HTTP/1.1" 403 9176 "-" "Mozilla/5.0 (X11; Linux x86_64)"
178.128.48.43 - - [13/Jan/2026:10:13:08 +0000] "GET /.env.local HTTP/1.1" 403 9176 "-" "Mozilla/5.0 (X11; Linux x86_64)"
...
show less
Exploited Host
Web App Attack
๐ซ๐ท
thilo
2026-01-13 09:13:34
(5 months ago)
Probe for vulnerabilities. Path attempted: /.env.local
Web App Attack
๐ซ๐ท
Savoie
2026-01-13 09:11:00
(5 months ago)
178.128.48.43 ***.*** - [13/Jan/2026:10:11:57 +0100] "GET /.env.save HTTP/1.1" 302 250 "-" "Mozilla/ ...
show more
178.128.48.43 ***.*** - [13/Jan/2026:10:11:57 +0100] "GET /.env.save HTTP/1.1" 302 250 "-" "Mozilla/5.0 (X11; Linux x86_64)"
AND :
GET /.env.production HTTP/1.1
GET /.env.local HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐ต๐ฑ
Niko's Stuff
2026-01-13 08:01:21
(5 months ago)
Triggered crowdsecurity/http-sensitive-files. More information at: https://app.crowdsec.net/cti/178. ...
show more
Triggered crowdsecurity/http-sensitive-files. More information at: https://app.crowdsec.net/cti/178.128.48.43
show less
Hacking
Web App Attack
๐ฉ๐ช
itsolon
2026-01-13 05:26:01
(5 months ago)
Fail2Ban plesk-modsecurity ban
Web App Attack
SSH
๐ณ๐ฑ
ReyhZhao
2026-01-13 03:28:00
(5 months ago)
Repeated security blocks triggered due to protocol violations involving numeric IP addresses in Host ...
show more
Repeated security blocks triggered due to protocol violations involving numeric IP addresses in Host headers.
show less
Brute-Force
๐ฉ๐ช
BlueWire Hosting
2026-01-13 02:14:56
(5 months ago)
Probing websites for vulnerabilities
SQL Injection
Web App Attack