๐ซ๐ท
SpaceHost-Server
2026-09-22 22:21:33
(1 day ago)
Brute-Force
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-09-22 22:06:19
(1 day ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-21.
show less
Web App Attack
SSH
Hacking
๐ซ๐ท
SpaceHost-Server
2026-09-21 22:19:41
(2 days ago)
Brute-Force
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-09-21 22:02:34
(2 days ago)
Auto-ban: >3000 req/min op 2026-09-21
Web App Attack
SSH
Hacking
๐ซ๐ฎ
inlink.ltd
2026-09-21 21:06:42
(2 days ago)
dot file probe
Web App Attack
๐ฌ๐ง
Aetherweb Ark
2026-09-21 20:34:55
(2 days ago)
(mod_security) mod_security (id:949110) triggered by 201.238.124.65 (TT/Trinidad and Tobago/-): N in ...
show more
(mod_security) mod_security (id:949110) triggered by 201.238.124.65 (TT/Trinidad and Tobago/-): N in the last X secs
show less
Web App Attack
๐ซ๐ท
arsonist
2026-09-21 20:30:54
(2 days ago)
[fail2ban]
2026-09-21T20:30:53.827072+00:00 arson caddy[1890453]: {"level":"info","ts":1790022653.82 ...
show more
[fail2ban]
2026-09-21T20:30:53.827072+00:00 arson caddy[1890453]: {"level":"info","ts":1790022653.8270414,"logger":"http.log.access.default","msg":"handled request","request":{"remote_ip":"201.238.124.65","remote_port":"47684","client_ip":"201.238.124.65","proto":"HTTP/1.1","method":"GET","host":"bot.furtress.tf","uri":"/core/.env","headers":{"Accept-Encoding":["gzip, deflate"],"User-Agent":["Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"],"Accept":["*/*"]},"tls":{"resumed":false,"version":772,"cipher_suite":4865,"proto":"http/1.1","server_name":"bot.furtress.tf","ech":false}},"bytes_read":0,"user_id":"","duration":0.000081303,"size":7,"status":418,"resp_headers":{"Server":["Caddy"],"Alt-Svc":["h3=\":443\"; ma=2592000"],"Content-Type":["text/plain; charset=utf-8"]}}
...
show less
Bad Web Bot
๐ซ๐ท
Baking333
2026-09-21 20:10:22
(2 days ago)
[redacted] 201.238.124.65 - - [21/Sep/2026:21:10:21 +0100] "GET /.[redacted] HTTP/1.1" 302 6773 0/22 ...
show more
[redacted] 201.238.124.65 - - [21/Sep/2026:21:10:21 +0100] "GET /.[redacted] HTTP/1.1" 302 6773 0/225053 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36" 443 [redacted] 201.238.124.65 - - [21/Sep/2026:21:10:21 +0100] "GET /.[redacted] HTTP/1.1" 302 6773 0/182639 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36" 443
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 19:48:53
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 201.238.124.65 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 201.238.124.65 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 15:48:47.940008 2026] [security2:error] [pid 27489:tid 27489] [client 201.238.124.65:50616] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "birdlovesfish.com"] [uri "/.env.production"] [unique_id "arGKHxUJQx8EG9hmpjPpYQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 19:30:54
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 201.238.124.65 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 201.238.124.65 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 15:30:50.280186 2026] [security2:error] [pid 16974:tid 16974] [client 201.238.124.65:42230] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bordwell.com"] [uri "/app/.env"] [unique_id "arGF6nX14UixMrcMlaKnFQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-21 19:28:38
(2 days ago)
"GET /.env.bak HTTP/1.1"
Hacking
Web App Attack
๐ซ๐ฎ
paissangroup
2026-09-21 19:23:09
(2 days ago)
Multiple WAF Violations
Web App Attack
๐ฉ๐ช
macrob
2026-09-21 18:49:55
(2 days ago)
2026/09/21 18:49:52 [error] 1144017#1144017: *22465114 access forbidden by rule, client: 201.238.124 ...
show more
2026/09/21 18:49:52 [error] 1144017#1144017: *22465114 access forbidden by rule, client: 201.238.124.65, server: binixo.kz, request: "GET /core/.env HTTP/1.1", host: "binixo.kz"
2026/09/21 18:49:53 [error] 1144019#1144019: *22465157 access forbidden by rule, client: 201.238.124.65, server: binixo.kz, request: "GET /api/.env HTTP/1.1", host: "binixo.kz"
2026/09/21 18:49:53 [error] 1144018#1144018: *22465174 access forbidden by rule, client: 201.238.124.65, server: binixo.kz, request: "GET /backend/.env HTTP/1.1", host: "binixo.kz"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 18:40:21
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 201.238.124.65 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 201.238.124.65 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 14:40:15.743303 2026] [security2:error] [pid 32272:tid 32272] [client 201.238.124.65:46034] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "binglawoffice.com"] [uri "/.env.local"] [unique_id "arF6D1KL9vkyPlxYQ31FNQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-21 18:30:03
(2 days ago)
CrowdSec decision: crowdsecurity/http-sensitive-files (origin: crowdsec)
Web App Attack