Anonymous
2026-08-14 05:25:25
(1 week ago)
[BestVouchers.net] Honeypot trap triggered | Path: /.env | Time: 2026-08-14T05:25:25.678Z | UA: Mozi ...
show more
[BestVouchers.net] Honeypot trap triggered | Path: /.env | Time: 2026-08-14T05:25:25.678Z | UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0 | Action: Automatically blocked for 24h and reported
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-14 04:05:44
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 209.87.162.222 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 209.87.162.222 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 14 00:05:37.601506 2026] [security2:error] [pid 26507:tid 26507] [client 209.87.162.222:60901] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.stbms.com"] [uri "/.env"] [unique_id "an6UETLTCO53ZN_H5Zfl0wAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-14 02:59:42
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 209.87.162.222 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 209.87.162.222 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 13 22:59:34.977044 2026] [security2:error] [pid 31055:tid 31055] [client 209.87.162.222:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pixacast.com"] [uri "/.env"] [unique_id "an6Elh_tX80yZ1fXK5tiDgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ท
Halux
2026-08-14 02:39:06
(1 week ago)
209.87.162.222 Probing protected path or service
Web App Attack
Anonymous
2026-08-14 02:34:28
(1 week ago)
http scanning for .env files
...
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-14 01:18:34
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 209.87.162.222 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 209.87.162.222 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 13 21:18:26.870999 2026] [security2:error] [pid 848278:tid 848278] [client 209.87.162.222:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mcbrude.com"] [uri "/.env"] [unique_id "an5s4kgtPhojcswsaji92gAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-14 00:59:11
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 209.87.162.222 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 209.87.162.222 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 13 20:59:03.099814 2026] [security2:error] [pid 3475321:tid 3475321] [client 209.87.162.222:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mindmaterial.io"] [uri "/.env"] [unique_id "an5oV3hgMkTDXM5fD2xoTAAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-08-14 00:18:20
(1 week ago)
Web attack/malicious scanning detected
Web App Attack
๐ฉ๐ช
Ba-Yu
2026-08-14 00:01:33
(1 week ago)
General hacking/exploits/scanning
Web Spam
Hacking
Brute-Force
Exploited Host
Web App Attack
๐ฌ๐ง
retrokitty.net
2026-08-13 23:49:09
(1 week ago)
209.87.162.222 - - [13/Aug/2026:23:49:08 +0000] "GET /.env HTTP/1.1" 503 23478 "-" "Mozilla/5.0 (Mac ...
show more
209.87.162.222 - - [13/Aug/2026:23:49:08 +0000] "GET /.env HTTP/1.1" 503 23478 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0"
...
show less
Web App Attack
๐บ๐ธ
SLSLLC
2026-08-13 23:45:17
(1 week ago)
209.87.162.222 - - [13/Aug/2026:23:45:16 +0000] "GET /.env HTTP/2.0" 403 1927 "-" "Mozilla/5.0 (Maci ...
show more
209.87.162.222 - - [13/Aug/2026:23:45:16 +0000] "GET /.env HTTP/2.0" 403 1927 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0"
...
show less
Brute-Force
Web App Attack
๐ฉ๐ช
ketovoila.pl
2026-08-13 23:42:54
(1 week ago)
ketovoila.pl web app secret/repository scan: hits=1; unique_paths=1; sample_paths=/.env; UA="Mozilla ...
show more
ketovoila.pl web app secret/repository scan: hits=1; unique_paths=1; sample_paths=/.env; UA="Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0"; window=2026-08-13T23:42:54Z..2026-08-13T23:42:54Z
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
MyGlobalFlowers
2026-08-13 22:53:09
(1 week ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-13 22:49:55
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 209.87.162.222 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 209.87.162.222 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 13 18:49:49.197558 2026] [security2:error] [pid 3739160:tid 3739160] [client 209.87.162.222:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cloudex.click"] [uri "/.env"] [unique_id "an5KDdMpWdhXrKBco0vNbgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-13 22:35:02
(1 week ago)
suspicious request in access.log
Web App Attack