Anonymous
2026-09-05 10:54:42
(34 minutes ago)
Scanner hitting /.env on picsou.cloud (TC-DATACENTER-LIMITED) — aaguard
Brute-Force
Port Scan
🇬🇧
neo101
2026-09-05 06:24:34
(5 hours ago)
Secret Hunting & Credential Harvesting: Automated scanner (Nuclei (Secret Hunter)) probed decoy secr ...
show more
Secret Hunting & Credential Harvesting: Automated scanner (Nuclei (Secret Hunter)) probed decoy secrets path '/.env~'. Served AI System Override decoy payload as counter-measure.
show less
Hacking
Web App Attack
🇩🇪
Manuel Braeuer
2026-09-05 01:22:03
(10 hours ago)
185.218.86.7 - - [05/Sep/2026:03:21:52 +0200] "GET /config/application.yml HTTP/1.1" 403 6274 "-" "M ...
show more
185.218.86.7 - - [05/Sep/2026:03:21:52 +0200] "GET /config/application.yml HTTP/1.1" 403 6274 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/135.0.0.0 Safari/537.36"
185.218.86.7 - - [05/Sep/2026:03:22:02 +0200] "GET /config/settings.old.php HTTP/1.1" 403 6274 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.36"
185.218.86.7 - - [05/Sep/2026:03:22:02 +0200] "GET /config/settings.php.bak HTTP/1.1" 403 6274 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/135.0.0.0 Safari/537.36"
185.218.86.7 - - [05/Sep/2026:03:22:02 +0200] "GET /config/staging.json HTTP/1.1" 403 6274 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.36"
185.218.86.7 - - [05/Sep/2026:03:22:02 +0200] "GET /config/development.json HTTP/1.1" 403 6274 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36
...
show less
Web App Attack
🇪🇸
Gem
2026-09-04 22:11:47
(13 hours ago)
Unauthorized web scan.
Web App Attack
🇳🇱
homeshowdomain.nl
2026-09-04 21:59:09
(13 hours ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-03.
show less
Web App Attack
SSH
Hacking
🇺🇸
TPI-Abuse
2026-09-04 21:40:47
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 185.218.86.7 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 185.218.86.7 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 17:40:42.425935 2026] [security2:error] [pid 21485:tid 21485] [client 185.218.86.7:27114] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kdgsf.xyz"] [uri "/.env.dev.local"] [unique_id "aps62oXNFX41nIykB4orYwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-04 19:04:46
(16 hours ago)
185.218.86.7 - - [04/Sep/2026:21:04:42 +0200] "GET /rw-probe-ccc3d4bafe3b1d0f.html HTTP/1.1" 404 184 ...
show more
185.218.86.7 - - [04/Sep/2026:21:04:42 +0200] "GET /rw-probe-ccc3d4bafe3b1d0f.html HTTP/1.1" 404 184 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/135.0.0.0 Safari/537.36"
185.218.86.7 - - [04/Sep/2026:21:04:43 +0200] "GET /rw-check-9d0cc60399ad96ea.htm HTTP/1.1" 404 184 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.36"
185.218.86.7 - - [04/Sep/2026:21:04:43 +0200] "GET /sitemap.xml HTTP/1.1" 404 184 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.36"
185.218.86.7 - - [04/Sep/2026:21:04:43 +0200] "GET /sitemap_index.xml HTTP/1.1" 404 184 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/135.0.0.0 Safari/537.36"
185.218.86.7 - - [04/Sep/2026:21:04:43 +0200] "GET /sitemap.xml.gz HTTP/1.1" 404 184 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML,
...
show less
Bad Web Bot
Web App Attack
🇩🇪
fds.io
2026-09-04 12:04:37
(23 hours ago)
detected and blocked repeated malicious bot scanner or crawler requests on the webserver
Bad Web Bot
Anonymous
2026-09-04 12:01:17
(23 hours ago)
[PathScanning] Path scanning/probing detected: WordPress system file probe (path: /xmlrpc.php) | [Xm ...
show more
[PathScanning] Path scanning/probing detected: WordPress system file probe (path: /xmlrpc.php) | [XmlRpc] XML-RPC abuse detected: XML-RPC endpoint probe (GET)
show less
Port Scan
Hacking
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 11:47:27
(23 hours ago)
(mod_security) mod_security (id:210730) triggered by 185.218.86.7 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 185.218.86.7 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 07:47:22.974465 2026] [security2:error] [pid 5104:tid 5104] [client 185.218.86.7:33026] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||fanarch.xyz|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "fanarch.xyz"] [uri "/env.ini"] [unique_id "apqvygm-NEJbrRf3h5ROLQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
MusicLibrary
2026-09-04 10:12:11
(1 day ago)
Attempted access to sensitive configuration files (.env, .git, etc.)
Bad Web Bot
Web App Attack
🇩🇪
lolyay
2026-09-04 09:01:12
(1 day ago)
185.218.86.7 - - [04/Sep/2026:09:01:11 +0000] "GET /.env.local HTTP/1.1" 200 4 "-" "Mozilla/5.0 (Mac ...
show more
185.218.86.7 - - [04/Sep/2026:09:01:11 +0000] "GET /.env.local HTTP/1.1" 200 4 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.36"
185.218.86.7 - - [04/Sep/2026:09:01:11 +0000] "GET /.env HTTP/1.1" 200 4 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.36 Edg/136.0.0.0"
...
show less
Web App Attack
Bad Web Bot
🇺🇸
deskpass.com
2026-09-04 07:51:21
(1 day ago)
GET /connection.php.bak
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 03:25:32
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 185.218.86.7 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 185.218.86.7 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 23:25:26.770365 2026] [security2:error] [pid 8824:tid 8824] [client 185.218.86.7:11636] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||cier.xyz|F|2"] [data ".axd"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "cier.xyz"] [uri "/trace.axd"] [unique_id "apo6JolfthbOGEQ-T7NphQAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-04 03:24:56
(1 day ago)
Ports: *; Direction: 0; Trigger: CT_LIMIT
Brute-Force
SSH