๐บ๐ธ
SodaAudit.app
2026-09-19 07:06:34
(1 day ago)
[sodaaudit.app] Web app attack. Timestamp: 2026-09-19T03:15:27.000Z. 1 probe events, 1 distinct path ...
show more
[sodaaudit.app] Web app attack. Timestamp: 2026-09-19T03:15:27.000Z. 1 probe events, 1 distinct path(s). Paths (payload): /.env
show less
Web App Attack
๐ฎ๐ณ
evicky2002
2026-09-19 06:00:05
(1 day ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐ฉ๐ช
Viveronese
2026-09-19 04:59:46
(1 day ago)
HTTP vulnerability scanning
Web App Attack
๐ซ๐ท
arsonist
2026-09-19 04:55:56
(1 day ago)
[fail2ban]
2026-09-19T04:55:56.119030+00:00 arson caddy[1890453]: {"level":"info","ts":1789793756.11 ...
show more
[fail2ban]
2026-09-19T04:55:56.119030+00:00 arson caddy[1890453]: {"level":"info","ts":1789793756.1190035,"logger":"http.log.access.default","msg":"handled request","request":{"remote_ip":"196.206.65.140","remote_port":"41758","client_ip":"196.206.65.140","proto":"HTTP/1.1","method":"GET","host":"possum.city","uri":"/.env","headers":{"Accept":["*/*"]},"tls":{"resumed":false,"version":772,"cipher_suite":4865,"proto":"","server_name":"possum.city","ech":false}},"bytes_read":0,"user_id":"","duration":0.000060013,"size":7,"status":418,"resp_headers":{"Server":["Caddy"],"Alt-Svc":["h3=\":443\"; ma=2592000"],"Content-Type":["text/plain; charset=utf-8"]}}
...
show less
Bad Web Bot
๐ง๐ช
taivas.nl
2026-09-19 04:32:58
(1 day ago)
Many_bad_calls
Web App Attack
๐จ๐ญ
lufi
2026-09-19 04:10:23
(1 day ago)
2026-09-19 06:10:22 196.206.65.140: blacklistedPath: /.env
...
Web Spam
Brute-Force
Hacking
Web App Attack
๐ฌ๐ง
foxxelabs
2026-09-19 04:08:32
(1 day ago)
Automated report from FoxxeLabs Sentinel. Path probed: /.env | Project: taca | Reason(s): Known expl ...
show more
Automated report from FoxxeLabs Sentinel. Path probed: /.env | Project: taca | Reason(s): Known exploit path: /.env; AbuseIPDB score: 100/100 | User-Agent: none
show less
Web App Attack
๐ฒ๐ฝ
octageeks.com
2026-09-19 04:07:59
(1 day ago)
Wordpress malicious attack:[octablocked]
Web App Attack
๐ต๐พ
armandosaucedo.me
2026-09-19 03:43:37
(1 day ago)
Threat Intelligence via ARMTI, Web Attack: GET /.env
Web App Attack
๐ซ๐ท
Baking333
2026-09-19 03:31:44
(1 day ago)
[redacted] 196.206.65.140 - - [19/Sep/2026:04:31:42 +0100] "GET /.env HTTP/1.1" 302 6798 0/39072 "-" ...
show more
[redacted] 196.206.65.140 - - [19/Sep/2026:04:31:42 +0100] "GET /.env HTTP/1.1" 302 6798 0/39072 "-" "-" 443 [redacted] 196.206.65.140 - - [19/Sep/2026:04:31:42 +0100] "GET / HTTP/1.1" 200 12749 0/95361 "https://[redacted]/.env" "-" 443
show less
Bad Web Bot
Web App Attack
Anonymous
2026-09-19 03:07:03
(1 day ago)
Automated web scanner. Requested suspicious paths: /.env. UTC: 2026-09-19 02:13:55.
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-19 02:49:44
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 196.206.65.140 (adsl196-140-65-206-196.adsl196- ...
show more
(mod_security) mod_security (id:210492) triggered by 196.206.65.140 (adsl196-140-65-206-196.adsl196-3.iam.net.ma): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 18 22:49:39.534779 2026] [security2:error] [pid 19688:tid 19688] [client 196.206.65.140:47024] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "aicoursefactory.com"] [uri "/.env"] [unique_id "aq34Q9Z8Algc01UsewA0zgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Tilellit.PRO
2026-09-19 02:35:57
(1 day ago)
Malicious web traffic detected by CrowdSec
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-19 02:21:51
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 196.206.65.140 (adsl196-140-65-206-196.adsl196- ...
show more
(mod_security) mod_security (id:210492) triggered by 196.206.65.140 (adsl196-140-65-206-196.adsl196-3.iam.net.ma): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 18 22:21:44.134533 2026] [security2:error] [pid 21558:tid 21558] [client 196.206.65.140:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.grainavi.com"] [uri "/.env"] [unique_id "aq3xuNcNFXoAC_q7wF1_kwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-19 02:21:33
(1 day ago)
[UserAgent] Suspicious User-Agent: Empty User-Agent header | [PathScanning] Path scanning/probing de ...
show more
[UserAgent] Suspicious User-Agent: Empty User-Agent header | [PathScanning] Path scanning/probing detected: Sensitive file access: environment file (path: /.env) | [ConfigAccess] Configuration file access attempt: Config file access attempt: .env; Environment configuration file (path: /.env)
show less
Port Scan
Hacking
Bad Web Bot
Web App Attack