🇩🇪
klaus_ph
2026-08-15 03:05:14
(3 weeks ago)
...
Bad Web Bot
🇺🇸
jkhorvath.com
2026-08-11 20:45:50
(3 weeks ago)
Request for URL /.env
Phishing
Brute-Force
Web App Attack
Anonymous
2026-08-11 20:07:00
(3 weeks ago)
DNS Compromise
DDoS Attack
🇮🇹
CoreTech srl
2026-08-11 14:53:57
(3 weeks ago)
cloudlinux2 fail2ban: 2026-08-11 16:48:51,743 fail2ban.filter [1708]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-08-11 16:48:51,743 fail2ban.filter [1708]: INFO [plesk-modsecurity] Found 197.245.44.99 - 2026-08-11 16:48:51cloudlinux2 fail2ban: 2026-08-11 16:49:45,014 fail2ban.filter [1708]: INFO [plesk-modsecurity] Found 197.245.44.99 - 2026-08-11 16:49:45cloudlinux2 fail2ban: 2026-08-11 16:49:45,167 fail2ban.actions [1708]: NOTICE [plesk-modsecurity] Ban 197.245.44.99cloudlinux2 fail2ban: 2026-08-11 16:49:45,173 fail2ban.filter [1708]: INFO [recidive] Found 197.245.44.99 - 2026-08-11 16:49:45cloudlinux2 fail2ban: 2026-08-11 16:51:29,629 fail2ban.filter [1708]: INFO [plesk-modsecurity] Found 223.185.52.229 - 2026-08-11 16:51:29cloudlinux2 fail2ban: 2026-08-11 16:52:15,197 fail2ban.filter [1708]: INFO [plesk-modsecurity] Found 185.163.2.12 - 2026-08-11 16:52:15cloudlinux2 fail2ban: 2026-08-11 16:52:21,117 fail2ban.filter [1708]: INFO [plesk-modsecurity] Found 223.185.52.229 - 2026-08-11 16:52:20cloudlinux2 fail2ban: 2026-
show less
Brute-Force
🇦🇺
FEWA
2026-08-11 14:02:20
(3 weeks ago)
Fail2Ban Ban Triggered
Hacking
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-11 12:24:13
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 185.163.2.12 (shopyeaster.example.com): 1 in th ...
show more
(mod_security) mod_security (id:210492) triggered by 185.163.2.12 (shopyeaster.example.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 11 08:24:09.421415 2026] [security2:error] [pid 414719:tid 414719] [client 185.163.2.12:53106] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.197"] [uri "/.env"] [unique_id "ansUabNPrMXnMI3UAWXZGQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇪
Jim Keir
2026-08-11 12:17:04
(3 weeks ago)
2026-08-11 12:17:03 185.163.2.12 File scanning, blocking 185.163.2.12 for 5 minutes
Web App Attack
🇯🇵
VXG-NET
2026-08-11 12:13:10
(3 weeks ago)
port=80, indicator_type=info-leak
Hacking
🇺🇸
TPI-Abuse
2026-08-11 12:04:13
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 185.163.2.12 (shopyeaster.example.com): 1 in th ...
show more
(mod_security) mod_security (id:210492) triggered by 185.163.2.12 (shopyeaster.example.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 11 08:04:07.865499 2026] [security2:error] [pid 925388:tid 925388] [client 185.163.2.12:55761] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.202"] [uri "/.env"] [unique_id "ansPt5V0xgMto6ZP-CBrwAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
Rayulcifer
2026-08-11 11:53:21
(3 weeks ago)
185.163.2.12 - - [11/Aug/2026:06:53:18 -0500] "GET /.env HTTP/1.1" 403 400 "-" "python-requests/2.28 ...
show more
185.163.2.12 - - [11/Aug/2026:06:53:18 -0500] "GET /.env HTTP/1.1" 403 400 "-" "python-requests/2.28.1"
...
show less
Open Proxy
Port Scan
Hacking
Web App Attack
SSH
🇺🇸
TPI-Abuse
2026-08-11 11:40:13
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 185.163.2.12 (shopyeaster.example.com): 1 in th ...
show more
(mod_security) mod_security (id:210492) triggered by 185.163.2.12 (shopyeaster.example.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 11 07:40:09.131690 2026] [security2:error] [pid 24856:tid 24881] [client 185.163.2.12:52908] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.201"] [uri "/.env"] [unique_id "ansKGVlcacPJDVk9DDFqUgAAAJY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-11 11:35:05
(3 weeks ago)
Automatic report - Vulnerability scan
/.env
Web App Attack
🇧🇪
voormedia
2026-08-11 11:23:37
(3 weeks ago)
Accessed trap at '/.env'
Web App Attack
🇸🇬
anotherwatcher
2026-08-11 11:20:53
(3 weeks ago)
bad bot
Bad Web Bot
🇩🇪
MusicLibrary
2026-08-11 11:20:46
(3 weeks ago)
Attempted access to sensitive configuration files (.env, .git, etc.)
Bad Web Bot
Web App Attack