🇺🇸
wbsouza
2026-09-12 03:36:20
(1 day ago)
CrowdSec: infra/bad-path-probe — automated firewall drops on self-hosted IDS sensor
Hacking
🇺🇸
SLSLLC
2026-09-11 16:02:30
(1 day ago)
209.87.167.190 - - [11/Sep/2026:16:02:29 +0000] "GET /.env HTTP/1.1" 403 2113 "-" "Mozilla/5.0 (Maci ...
show more
209.87.167.190 - - [11/Sep/2026:16:02:29 +0000] "GET /.env HTTP/1.1" 403 2113 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0"
...
show less
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 16:00:19
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 209.87.167.190 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 209.87.167.190 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 12:00:13.057105 2026] [security2:error] [pid 5542:tid 5580] [client 209.87.167.190:21615] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.docdalton.com"] [uri "/.env"] [unique_id "aqQljdQu3Ff9ZK7A7tq0XwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
ambor
2026-09-11 15:54:44
(1 day ago)
Honeypot triggered: /.env on ifebridge.com. User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15 ...
show more
Honeypot triggered: /.env on ifebridge.com. User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0. Method: GET
show less
Web App Attack
🇳🇱
Alt255
2026-09-11 15:09:55
(1 day ago)
209.87.167.190 - - [11/Sep/2026:17:09:55 +0200] "GET /.env HTTP/1.1" 403 8106 "-" "Mozilla/5.0 (Maci ...
show more
209.87.167.190 - - [11/Sep/2026:17:09:55 +0200] "GET /.env HTTP/1.1" 403 8106 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0"
...
show less
Bad Web Bot
Web App Attack
🇬🇧
foxxelabs
2026-09-11 15:07:26
(1 day ago)
Automated report from FoxxeLabs Sentinel. Path probed: /.env | Project: anseo | Reason(s): Known exp ...
show more
Automated report from FoxxeLabs Sentinel. Path probed: /.env | Project: anseo | Reason(s): Known exploit path: /.env; AbuseIPDB score: 100/100 | User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0
show less
Web App Attack
🇺🇸
Charlesiv
2026-09-11 14:49:42
(1 day ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
ASN: 396356 (Latitude.sh)
Pro ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
ASN: 396356 (Latitude.sh)
Protocol: HTTP/1.1 (GET method)
Endpoint: /.env
Timestamp: 2026-09-11T14:06:20Z
Ray ID: a3973b80cc7e4692
UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0
show less
Bad Web Bot
🇺🇸
LotPhantom
2026-09-11 14:41:32
(1 day ago)
2026/09/11 14:41:32 [error] 1909160#1909160: *4116 access forbidden by rule, client: 209.87.167.190, ...
show more
2026/09/11 14:41:32 [error] 1909160#1909160: *4116 access forbidden by rule, client: 209.87.167.190, server: wynnesmiles.com, request: "GET /.env HTTP/1.1", host: "wynnesmiles.com"
...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 14:26:44
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 209.87.167.190 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 209.87.167.190 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 10:26:37.923853 2026] [security2:error] [pid 28526:tid 28526] [client 209.87.167.190:53409] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.vincetronics.com"] [uri "/google0e1ebbf943a1894d.html/.env"] [unique_id "aqQPnUdxjdodTlX2_bZadQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
BlueWire Hosting
2026-09-11 13:42:59
(2 days ago)
High-confidence malicious configuration/VCS probe
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 12:54:53
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 209.87.167.190 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 209.87.167.190 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 08:54:47.822030 2026] [security2:error] [pid 11369:tid 11369] [client 209.87.167.190:36701] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "stbms.com"] [uri "/.env"] [unique_id "aqP6F7C_Agg1Kd7mcDw6AAAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
interbiznw.com
2026-09-11 12:25:05
(2 days ago)
fail2ban-ban
Hacking
Brute-Force
Exploited Host
Web App Attack
🇺🇸
mnsf
2026-09-11 12:05:22
(2 days ago)
Abuse Detected (9)
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 12:03:53
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 209.87.167.190 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 209.87.167.190 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 08:03:49.102444 2026] [security2:error] [pid 8405:tid 8405] [client 209.87.167.190:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "antitribu.com"] [uri "/.env"] [unique_id "aqPuJYIj5B6dkUt5EmhbFAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 11:26:33
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 209.87.167.190 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 209.87.167.190 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 07:26:26.753607 2026] [security2:error] [pid 11214:tid 11214] [client 209.87.167.190:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "aslanhan.com"] [uri "/.env"] [unique_id "aqPlYhpw52JFFx8ZIajtLAAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack