🇺🇸
mnsf
2026-08-27 12:05:07
(2 days ago)
Abuse Detected (23)
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-08-26 10:39:29
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 185.213.193.213 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 185.213.193.213 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 06:39:25.106263 2026] [security2:error] [pid 21639:tid 21672] [client 185.213.193.213:49842] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.cynosurefinishes.com.cynosureinternetservices.com"] [uri "/.env"] [unique_id "ao7CXUmEBRv4GEcjX9xd1wAAAVM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-25 22:15:06
(3 days ago)
185.213.193.213 - - [26/Aug/2026:00:15:05 +0200] "GET /.env HTTP/1.1" 301 169 "-" "Mozilla/5.0 (X11; ...
show more
185.213.193.213 - - [26/Aug/2026:00:15:05 +0200] "GET /.env HTTP/1.1" 301 169 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0 Safari/537.36"
show less
Web App Attack
🇩🇪
bescared
2026-08-25 15:38:41
(3 days ago)
F2B - Malicious activity detected. URL Probing. -8ff06ede-
Hacking
Bad Web Bot
Web App Attack
🇺🇸
mnsf
2026-08-25 11:05:10
(4 days ago)
Abuse Detected (11)
Brute-Force
Web App Attack
🇵🇱
Budyn
2026-08-24 04:48:31
(5 days ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit Block. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: 51.83.237.XX | URI: /.env | UA: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Hacking
Web App Attack
🇩🇪
Ilop
2026-08-20 00:09:09
(1 week ago)
[hp-100] 2 unsolicited packets to honeypot ports 8000 (OCI DShield sensor)
Port Scan
🇮🇩
Antasena
2026-08-19 00:00:00
(1 week ago)
Sensitive Configuration File Probe from 185.213.193.213
Web App Attack
🇩🇪
big-cloud.nl
2026-08-18 03:41:45
(1 week ago)
Try to access /.env
Web App Attack
🇺🇸
TPI-Abuse
2026-08-17 21:01:50
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 185.213.193.213 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 185.213.193.213 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 17:01:44.172541 2026] [security2:error] [pid 29092:tid 29092] [client 185.213.193.213:42456] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.register-yacht-belize.com.yacht-register-holland.com"] [uri "/.env"] [unique_id "aoN2uDd6IdgDUujEW2U--AAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-17 17:03:59
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 185.213.193.213 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 185.213.193.213 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 13:03:52.612430 2026] [security2:error] [pid 17537:tid 17537] [client 185.213.193.213:46342] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.honeybeeawareness.org.garyrankin.com"] [uri "/.env"] [unique_id "aoM--C9-2rTI3xCbDeKuvQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
LRob
2026-08-17 11:04:04
(1 week ago)
Credential and secrets file probing | req: /.env | UA: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/5 ...
show more
Credential and secrets file probing | req: /.env | UA: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0 Safari/537.36
show less
Hacking
Web App Attack
Anonymous
2026-08-17 10:55:01
(1 week ago)
suspicious request in access.log
Web App Attack
🇺🇸
knock
2026-07-26 02:11:09
(1 month ago)
Knock-Knock honeypot brute-force: SIP (3 total hits)
Hacking
Brute-Force
🇩🇪
CELOS-SOC
2025-12-24 20:31:24
(8 months ago)
Multiple Unauthorized SSLVPN Login Attempts
Hacking
Brute-Force