๐บ๐ฆ
URAN Publishing Service
2026-09-01 20:21:36
(20 minutes ago)
[01/Sep/2026:23:21:36 +0300] -- 196.65.151.171 Ban reason: Scanner [SENSITIVE_FILES] | Request: HEAD ...
show more
[01/Sep/2026:23:21:36 +0300] -- 196.65.151.171 Ban reason: Scanner [SENSITIVE_FILES] | Request: HEAD /.env HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐ซ๐ท
omartin
2026-09-01 20:18:43
(23 minutes ago)
Critical Vulnerability Scan detected
Hacking
Brute-Force
Exploited Host
Web App Attack
๐ฉ๐ช
Gwyneth Llewelyn
2026-09-01 20:15:38
(26 minutes ago)
2026/09/01 21:15:35 [error] 380594#380594: *2141457 access forbidden by rule, client: 196.65.151.171 ...
show more
2026/09/01 21:15:35 [error] 380594#380594: *2141457 access forbidden by rule, client: 196.65.151.171, server: apcoelho.pt, request: "GET /.env HTTP/2.0", host: "apcoelho.pt"
196.65.151.171 - - [01/Sep/2026:21:15:35 +0100] "GET /.env HTTP/2.0" 403 1045 "-" "-"
2026/09/01 21:15:36 [error] 380594#380594: *2141457 access forbidden by rule, client: 196.65.151.171, server: apcoelho.pt, request: "GET /.env HTTP/2.0", host: "apcoelho.pt"
show less
Brute-Force
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-09-01 20:06:13
(36 minutes ago)
Try to access /.env
Web App Attack
Anonymous
2026-09-01 19:57:35
(44 minutes ago)
196.65.151.171 - - [01/Sep/2026:19:57:35 +0000] "GET /.env HTTP/2.0" 403 146 "-" "-" "196.65.151.17 ...
show more
196.65.151.171 - - [01/Sep/2026:19:57:35 +0000] "GET /.env HTTP/2.0" 403 146 "-" "-" "196.65.151.171" "-"
...
show less
Web App Attack
๐จ๐ฆ
aks4226
2026-09-01 19:54:06
(48 minutes ago)
Bot search, attacking common web applications.
Web App Attack
๐ณ๐ด
Abuse Buster
2026-09-01 19:02:12
(1 hour ago)
196.65.151.171 - - [01/Sep/2026:21:02:05 +0200] "HEAD /.env HTTP/1.1" 404 0 "-" "-"
196.65.151.171 - ...
show more
196.65.151.171 - - [01/Sep/2026:21:02:05 +0200] "HEAD /.env HTTP/1.1" 404 0 "-" "-"
196.65.151.171 - - [01/Sep/2026:21:02:09 +0200] "GET /.env HTTP/1.1" 404 22 "-" "-"
...
show less
Web App Attack
๐ฆ๐บ
rubixstudios
2026-09-01 18:53:02
(1 hour ago)
Excessive HTTP requests consistent with automated attack behaviour detected by Imunify360
DDoS Attack
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 18:30:06
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 196.65.151.171 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 196.65.151.171 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 14:30:00.376271 2026] [security2:error] [pid 26472:tid 26472] [client 196.65.151.171:60330] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "training.oxfordgliding.com"] [uri "/.env"] [unique_id "apcZqNyrsfBcb1lbUZ1TPgAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ต๐ฑ
Budyn
2026-09-01 18:27:17
(2 hours ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: idp.astropot.space | URI: /.env | UA: Unknown User-Agent | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 18:12:38
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 196.65.151.171 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 196.65.151.171 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 14:12:31.308939 2026] [security2:error] [pid 15411:tid 15411] [client 196.65.151.171:45986] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mytemp.info.joshuashands.org"] [uri "/.env"] [unique_id "apcVj3A5AC18sqCbUAYBSQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-01 18:12:02
(2 hours ago)
Web probing (2 hits in 24h) on heemkundesjin.nl: sensitive-path scans and/or 404 bursts. Reported by ...
show more
Web probing (2 hits in 24h) on heemkundesjin.nl: sensitive-path scans and/or 404 bursts. Reported by CRMON.
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 16:28:38
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 196.65.151.171 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 196.65.151.171 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 12:28:30.857328 2026] [security2:error] [pid 27081:tid 27108] [client 196.65.151.171:49152] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.northmiamichamber.org"] [uri "/.env"] [unique_id "apb9LthXESsNEkeLDZQmyAAAAFQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 16:10:57
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 196.65.151.171 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 196.65.151.171 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 12:10:51.698589 2026] [security2:error] [pid 31527:tid 31527] [client 196.65.151.171:49086] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wp.yeungshk.com"] [uri "/.env"] [unique_id "apb5C54bx81KGfHVyhGEJQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 14:56:03
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 196.65.151.171 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 196.65.151.171 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 10:55:56.577750 2026] [security2:error] [pid 1624:tid 1688] [client 196.65.151.171:60598] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "isolomon.healthcare.isolomon.ai"] [uri "/.env"] [unique_id "apbnfFRblctnz_ngpDMUIQAAAJg"]
show less
Brute-Force
Bad Web Bot
Web App Attack