๐ฌ๐ง
Artelis
2026-07-20 20:17:50
(3 days ago)
209.127.35.100 - - [20/Jul/2026:20:16:44 +0000] "GET /production/.env HTTP/1.1" 404 548 "-" "Mozilla ...
show more
209.127.35.100 - - [20/Jul/2026:20:16:44 +0000] "GET /production/.env HTTP/1.1" 404 548 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/143.0.0.0 Safari/537.36"
209.127.35.100 - - [20/Jul/2026:20:16:49 +0000] "GET /application/.env HTTP/1.1" 404 548 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/143.0.0.0 Safari/537.36"
209.127.35.100 - - [20/Jul/2026:20:16:56 +0000] "GET /prod/.env HTTP/1.1" 404 548 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/143.0.0.0 Safari/537.36"
209.127.35.100 - - [20/Jul/2026:20:17:06 +0000] "GET /beta/.env HTTP/1.1" 404 548 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/143.0.0.0 Safari/537.36"
209.127.35.100 - - [20/Jul/2026:20:17:09 +0000] "GET /admin/.env HTTP/1.1" 404 548 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/143.0.0.0 S
...
show less
Web App Attack
๐ฎ๐ณ
dineshskt4all
2026-07-20 20:14:19
(3 days ago)
[Mon Jul 20 20:14:17.579689 2026] [proxy_fcgi:error] [pid 3594130:tid 129856046098112] [client 209.1 ...
show more
[Mon Jul 20 20:14:17.579689 2026] [proxy_fcgi:error] [pid 3594130:tid 129856046098112] [client 209.127.35.100:0] AH01071: Got error 'Primary script unknown'
...
show less
Brute-Force
Anonymous
2026-07-20 19:17:11
(3 days ago)
209.127.35.100 - - [21/Jul/2026:03:17:10 +0800] "GET /.env HTTP/1.1" 404 196 "-" "Mozilla/5.0 (Windo ...
show more
209.127.35.100 - - [21/Jul/2026:03:17:10 +0800] "GET /.env HTTP/1.1" 404 196 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/143.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
๐ฌ๐ง
Aetherweb Ark
2026-07-20 18:01:28
(3 days ago)
(mod_security) mod_security (id:949110) triggered by 209.127.35.100 (CA/Canada/-): N in the last X s ...
show more
(mod_security) mod_security (id:949110) triggered by 209.127.35.100 (CA/Canada/-): N in the last X secs
show less
Web App Attack
๐บ๐ธ
agenciahypelab.com.br
2026-07-20 17:21:05
(3 days ago)
WordPress login brute-force detectado e bloqueado pelo CSF/LFD. Trigger: LF_TRIGGER
Brute-Force
SSH
Anonymous
2026-07-20 17:07:29
(3 days ago)
2026/07/20 07:15:01 [error] 1459#1459: *28670 access forbidden by rule, client: 209.127.35.100, serv ...
show more
2026/07/20 07:15:01 [error] 1459#1459: *28670 access forbidden by rule, client: 209.127.35.100, server: blog.sorotop.com.br, request: "GET //.env HTTP/1.1", host: "blog.sorotop.com.br"
2026/07/20 13:23:37 [error] 1460#1460: *32058 access forbidden by rule, client: 209.127.35.100, server: n8n.sorotop.com.br, request: "GET //.env HTTP/1.1", host: "n8n.sorotop.com.br"
2026/07/20 14:07:26 [error] 1462#1462: *32506 access forbidden by rule, client: 209.127.35.100, server: novo.temcomercio.com.br, request: "GET //.env HTTP/1.1", host: "novo.temcomercio.com.br"
...
show less
Port Scan
Anonymous
2026-07-20 16:32:18
(3 days ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
๐ง๐ท
dominioz
2026-07-20 16:03:54
(3 days ago)
2026-07-20 15:50:30 GET /.env - - 209.127.35.100 HTTP/1.1 Go-http-client/1.1 - 301 461
2026-07-20 16 ...
show more
2026-07-20 15:50:30 GET /.env - - 209.127.35.100 HTTP/1.1 Go-http-client/1.1 - 301 461
2026-07-20 16:03:43 GET /.env - - 209.127.35.100 HTTP/1.1 Go-http-client/1.1 - 301 461
...
show less
Web App Attack
๐บ๐ธ
IndigoRidge
2026-07-20 15:50:45
(3 days ago)
209.127.35.100 - - [20/Jul/2026:11:50:30 -0400] "GET /.env HTTP/1.0" 403 5486 "-" "Mozilla/5.0 (Wind ...
show more
209.127.35.100 - - [20/Jul/2026:11:50:30 -0400] "GET /.env HTTP/1.0" 403 5486 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/143.0.0.0 Safari/537.36"
209.127.35.100 - - [20/Jul/2026:11:50:35 -0400] "GET /config/.env HTTP/1.0" 403 5486 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/143.0.0.0 Safari/537.36"
209.127.35.100 - - [20/Jul/2026:11:50:45 -0400] "GET /production/.env HTTP/1.0" 403 5486 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/143.0.0.0 Safari/537.36"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-20 15:10:45
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 209.127.35.100 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 209.127.35.100 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 11:10:41.067330 2026] [security2:error] [pid 14330:tid 14330] [client 209.127.35.100:49548] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ashburnp.us"] [uri "/.env"] [unique_id "al46cbUX0jGrq_T2L9fjMAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
cwytech
2026-07-20 14:28:20
(3 days ago)
Fleet-wide ban from the Ghostfleet ๐ป. Triggered by scenario: cwy/tpot-http-sensitive-files.
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-20 13:43:12
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 209.127.35.100 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 209.127.35.100 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 09:43:06.250284 2026] [security2:error] [pid 32062:tid 32179] [client 209.127.35.100:50512] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "test.giere.us"] [uri "/.env"] [unique_id "al4l6v5iGbEglQSy20_9NgAAAZY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-20 13:17:12
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 209.127.35.100 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 209.127.35.100 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 09:17:03.949255 2026] [security2:error] [pid 18740:tid 18740] [client 209.127.35.100:56327] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "penjoki.us"] [uri "/.env"] [unique_id "al4fz5XjkyQaaYII_eYUuAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-07-20 13:10:01
(3 days ago)
Web attack/malicious scanning detected
Web App Attack
๐ง๐ท
vfAcceloReporter
2026-07-20 12:40:24
(3 days ago)
209.127.35.100 - - [20/Jul/2026:09:40:24 -0300] "GET //.env HTTP/1.1" 301 169 "-" "Go-http-client/1. ...
show more
209.127.35.100 - - [20/Jul/2026:09:40:24 -0300] "GET //.env HTTP/1.1" 301 169 "-" "Go-http-client/1.1"
...
show less
Brute-Force
Web App Attack
Exploited Host