🇺🇸
TPI-Abuse
2026-08-29 11:07:04
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 193.124.179.244 (free.ihor-hosting.ru): 1 in th ...
show more
(mod_security) mod_security (id:210492) triggered by 193.124.179.244 (free.ihor-hosting.ru): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 07:06:58.619892 2026] [security2:error] [pid 19730:tid 19730] [client 193.124.179.244:48716] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "controldent.net"] [uri "/.env"] [unique_id "apK9UiaItJW1QLxYScll6AAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇱
spd.co.il
2026-08-27 14:03:03
(2 days ago)
Web application attack detected
Hacking
Web App Attack
Anonymous
2026-08-25 16:14:12
(4 days ago)
193.124.179.244 - - [25/Aug/2026:18:14:11 +0200] "GET /.env.stage HTTP/1.1" 403 124 "-" "python-http ...
show more
193.124.179.244 - - [25/Aug/2026:18:14:11 +0200] "GET /.env.stage HTTP/1.1" 403 124 "-" "python-httpx/0.28.1"
193.124.179.244 - - [25/Aug/2026:18:14:11 +0200] "GET /.env.uat HTTP/1.1" 403 124 "-" "python-httpx/0.28.1"
193.124.179.244 - - [25/Aug/2026:18:14:11 +0200] "GET /.env.demo HTTP/1.1" 403 124 "-" "python-httpx/0.28.1"
193.124.179.244 - - [25/Aug/2026:18:14:11 +0200] "GET /.env.dist HTTP/1.1" 403 124 "-" "python-httpx/0.28.1"
193.124.179.244 - - [25/Aug/2026:18:14:11 +0200] "GET /.env.dev.local HTTP/1.1" 403 124 "-" "python-httpx/0.28.1"
193.124.179.244 - - [25/Aug/2026:18:14:11 +0200] "GET /.env.sample HTTP/1.1" 403 124 "-" "python-httpx/0.28.1"
193.124.179.244 - - [25/Aug/2026:18:14:11 +0200] "GET /.env.backup HTTP/1.1" 403 124 "-" "python-httpx/0.28.1"
193.124.179.244 - - [25/Aug/2026:18:14:11 +0200] "GET /.env.prod HTTP/1.1" 403 124 "-" "python-httpx/0.28.1"
193.124.179.244 - - [25/Aug/2026:18:14:11 +0200] "GET /.env.example HTTP/1.1" 403 124 "-" "python-httpx/0.28.1"
193.124
...
show less
Bad Web Bot
Web App Attack
🇮🇹
CoreTech srl
2026-08-15 14:28:57
(2 weeks ago)
cloudlinux2 fail2ban: 2026-08-15 16:24:31,910 fail2ban.filter [1695]: INFO [plesk-wordpre ...
show more
cloudlinux2 fail2ban: 2026-08-15 16:24:31,910 fail2ban.filter [1695]: INFO [plesk-wordpress] Found 216.24.219.168 - 2026-08-15 16:24:31cloudlinux2 fail2ban: 2026-08-15 16:25:35,604 fail2ban.actions [1695]: NOTICE [plesk-modsecurity] Unban 213.139.223.69cloudlinux2 fail2ban: 2026-08-15 16:25:36,217 fail2ban.actions [1695]: NOTICE [plesk-modsecurity] Unban 212.81.37.21cloudlinux2 fail2ban: 2026-08-15 16:25:44,055 fail2ban.actions [1695]: NOTICE [plesk-modsecurity] Unban 193.31.103.174cloudlinux2 fail2ban: 2026-08-15 16:25:41,439 fail2ban.actions [1695]: NOTICE [plesk-modsecurity] Unban 193.31.101.144cloudlinux2 fail2ban: 2026-08-15 16:26:05,294 fail2ban.actions [1695]: NOTICE [plesk-modsecurity] Unban 193.31.101.49cloudlinux2 fail2ban: 2026-08-15 16:26:13,315 fail2ban.actions [1695]: NOTICE [plesk-modsecurity] Unban 46.161.44.62cloudlinux2 fail2ban: 2026-08-15 16:27:34,023 fail2ban.actions [1695]: NOTICE [plesk-modsecurity] Unban 193.31.101.198c
show less
Web App Attack
Anonymous
2026-08-07 08:32:57
(3 weeks ago)
(mod_security) mod_security triggered on hostname [redacted])
SQL Injection
Anonymous
2026-08-04 14:38:11
(3 weeks ago)
193.124.179.244 - - [04/Aug/2026:16:38:11 +0200] "GET /.env.production HTTP/1.1" 403 124 "-" "python ...
show more
193.124.179.244 - - [04/Aug/2026:16:38:11 +0200] "GET /.env.production HTTP/1.1" 403 124 "-" "python-httpx/0.28.1"
193.124.179.244 - - [04/Aug/2026:16:38:11 +0200] "GET /.env.ci HTTP/1.1" 403 124 "-" "python-httpx/0.28.1"
193.124.179.244 - - [04/Aug/2026:16:38:11 +0200] "GET /.env.staging HTTP/1.1" 403 124 "-" "python-httpx/0.28.1"
193.124.179.244 - - [04/Aug/2026:16:38:11 +0200] "GET /.env.demo HTTP/1.1" 403 124 "-" "python-httpx/0.28.1"
193.124.179.244 - - [04/Aug/2026:16:38:11 +0200] "GET /.env.preview HTTP/1.1" 403 124 "-" "python-httpx/0.28.1"
193.124.179.244 - - [04/Aug/2026:16:38:11 +0200] "GET /.env.dist HTTP/1.1" 403 124 "-" "python-httpx/0.28.1"
193.124.179.244 - - [04/Aug/2026:16:38:11 +0200] "GET /.env HTTP/1.1" 403 124 "-" "python-httpx/0.28.1"
193.124.179.244 - - [04/Aug/2026:16:38:11 +0200] "GET /.env.save HTTP/1.1" 403 124 "-" "python-httpx/0.28.1"
193.124.179.244 - - [04/Aug/2026:16:38:11 +0200] "GET /.env.prod HTTP/1.1" 403 124 "-" "python-httpx/0.28.1"
193.124.179.24
...
show less
Bad Web Bot
Web App Attack
🇵🇱
Budyn
2026-08-03 10:51:18
(3 weeks ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit Block. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: definitelynotahoneypot.online | URI: /.env | UA: python-httpx/0.28.1 | BODY: [Empty / GET Request]
show less
Hacking
Web App Attack
🇵🇱
Budyn
2026-08-01 22:41:55
(4 weeks ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit Block. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: budyn.xyz | URI: /.env | UA: python-httpx/0.28.1 | BODY: [Empty / GET Request]
show less
Hacking
Web App Attack
🇵🇱
Budyn
2026-07-31 18:06:12
(4 weeks ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit Block. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: goblinpot.site | URI: /.env | UA: python-httpx/0.28.1 | BODY: [Empty / GET Request]
show less
Hacking
Web App Attack
🇮🇱
spd.co.il
2026-06-21 08:02:27
(2 months ago)
Web application attack detected
Hacking
Web App Attack
🇧🇪
madeit
2026-06-19 09:16:59
(2 months ago)
Web App Attack
🇺🇸
mnsf
2026-06-12 15:05:49
(2 months ago)
Abuse Detected (30)
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-06-12 04:18:26
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 193.124.179.244 (free.ihor-hosting.ru): 1 in th ...
show more
(mod_security) mod_security (id:210492) triggered by 193.124.179.244 (free.ihor-hosting.ru): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 12 00:18:19.400814 2026] [security2:error] [pid 6822:tid 6822] [client 193.124.179.244:51571] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "prsresume.com"] [uri "/.env.bak"] [unique_id "aiuIi_7YUPtr9kYDS9AjwwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-06-11 13:35:44
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 193.124.179.244 (free.ihor-hosting.ru): 1 in th ...
show more
(mod_security) mod_security (id:210492) triggered by 193.124.179.244 (free.ihor-hosting.ru): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 11 09:35:36.980279 2026] [security2:error] [pid 20289:tid 20289] [client 193.124.179.244:37413] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "alrightletsgo.com"] [uri "/.env"] [unique_id "aiq5qFyyZ-0Q-oftAPJVZAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-09 19:27:30
(2 months ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH