๐ฉ๐ช
niedson
2026-08-24 18:30:02
(56 minutes ago)
Automated honeypot trigger: scanner probing decoy admin/credential paths (e.g. /wp-admin, /phpmyadmi ...
show more
Automated honeypot trigger: scanner probing decoy admin/credential paths (e.g. /wp-admin, /phpmyadmin). Request dropped (HTTP 444) and source IP firewalled. Reported automatically.
show less
Port Scan
Web App Attack
๐ซ๐ท
Baking333
2026-08-24 17:14:13
(2 hours ago)
[redacted] 198.71.52.116 - - [24/Aug/2026:18:14:10 +0100] "GET /.env HTTP/2.0" 301 291 "-" "python-r ...
show more
[redacted] 198.71.52.116 - - [24/Aug/2026:18:14:10 +0100] "GET /.env HTTP/2.0" 301 291 "-" "python-requests/2.32.4" [redacted] 198.71.52.116 - - [24/Aug/2026:18:14:11 +0100] "GET /fr/.env/ HTTP/2.0" 404 34627 "-" "python-requests/2.32.4"
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
conseilgouz
2026-08-24 17:13:28
(2 hours ago)
gie-17 : Block hidden directories=>/.env(/)
Hacking
๐ฉ๐ช
Gwyneth Llewelyn
2026-08-24 15:56:27
(3 hours ago)
2026/08/24 16:56:24 [error] 380594#380594: *284551 access forbidden by rule, client: 198.71.52.116, ...
show more
2026/08/24 16:56:24 [error] 380594#380594: *284551 access forbidden by rule, client: 198.71.52.116, server: operadotejo.org, request: "GET /.env HTTP/2.0", host: "operadotejo.org"
198.71.52.116 - - [24/Aug/2026:16:56:24 +0100] "GET /.env HTTP/2.0" 403 95 "-" "python-requests/2.32.4"
2026/08/24 16:56:24 [error] 380594#380594: *284551 access forbidden by rule, client: 198.71.52.116, server: operadotejo.org, request: "GET /.env HTTP/2.0", host: "operadotejo.org"
show less
Brute-Force
Web App Attack
๐ฉ๐ช
hidemail.app
2026-08-24 14:22:16
(5 hours ago)
Automated scan for exposed config/secret files and known web exploits (e.g. /.env, RCE probes); auto ...
show more
Automated scan for exposed config/secret files and known web exploits (e.g. /.env, RCE probes); auto-banned by fail2ban.
show less
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-24 14:13:28
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 198.71.52.116 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 198.71.52.116 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 10:13:20.735240 2026] [security2:error] [pid 25759:tid 25759] [client 198.71.52.116:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mindmaterial.io"] [uri "/.env"] [unique_id "aoxRgFO3KWMT6mBjmZsRnQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
dtorrer
2026-08-24 05:07:00
(14 hours ago)
General vulnerability scan.
Port Scan
๐บ๐ธ
TPI-Abuse
2026-08-24 04:46:14
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 198.71.52.116 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 198.71.52.116 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 00:46:10.085059 2026] [security2:error] [pid 17877:tid 17877] [client 198.71.52.116:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "eddysgroup.com"] [uri "/.env"] [unique_id "aovMkvDSCOi-rr4HiH2xcAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
Rauno Asp
2026-08-24 04:43:35
(14 hours ago)
Automated .env credentials scanning attempt detected by honeypot on elbasanapartments.al
Web App Attack
Anonymous
2026-08-24 04:26:49
(14 hours ago)
http scanning for .env files
...
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-24 04:03:29
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 198.71.52.116 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 198.71.52.116 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 00:03:25.132998 2026] [security2:error] [pid 15615:tid 15615] [client 198.71.52.116:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "atlascoombs.com"] [uri "/.env"] [unique_id "aovCjV7MW2iHE28LafTtogAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
Anytech
2026-08-24 03:01:31
(16 hours ago)
Blocked by Conn-Monitor: http-bad-user-agent
Web App Attack
Bad Web Bot
๐ช๐ธ
el-brujo
2026-08-24 02:55:12
(16 hours ago)
24/Aug/2026:04:55:11.907842 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client ...
show more
24/Aug/2026:04:55:11.907842 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 198.71.52.116] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "125"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "hostench.eu"] [uri "/.env"] [unique_id "aouyjwWK73UB_acpfMjY8gABJm0"]
...
show less
Hacking
Web App Attack
๐ฉ๐ช
tall1oN
2026-08-23 18:35:01
(1 day ago)
198.71.52.116 - - [23/Aug/2026:20:33:14 +0200] "GET /.env HTTP/1.1" 200 303104 "-" "python-requests/ ...
show more
198.71.52.116 - - [23/Aug/2026:20:33:14 +0200] "GET /.env HTTP/1.1" 200 303104 "-" "python-requests/2.32.4" "plutoz.de"
198.71.52.116 - - [23/Aug/2026:20:35:00 +0200] "GET /.env HTTP/1.1" 200 110592 "-" "python-requests/2.32.4" "plutoz.de"
...
show less
Web App Attack
Port Scan
Hacking
Anonymous
2026-08-23 15:53:02
(1 day ago)
Bot / scanning and/or hacking attempts: GET /.env HTTP/1.1
Hacking
Web App Attack