๐ซ๐ฎ
Rauno Asp
2026-09-02 03:58:42
(6 hours ago)
Automated .env credentials scanning attempt detected by honeypot on elbasanapartments.al
Web App Attack
๐ซ๐ฎ
Rauno Asp
2026-08-27 03:35:08
(6 days ago)
Automated .env credentials scanning attempt detected by honeypot on elbasanapartments.al
Web App Attack
๐ซ๐ฎ
Rauno Asp
2026-08-22 01:00:46
(1 week ago)
Automated .env credentials scanning attempt detected by honeypot on elbasanapartments.al
Web App Attack
๐ฎ๐น
CoreTech srl
2026-08-11 17:48:56
(3 weeks ago)
cloudlinux2 fail2ban: 2026-08-11 19:44:15,588 fail2ban.filter [1708]: INFO [plesk-wordpre ...
show more
cloudlinux2 fail2ban: 2026-08-11 19:44:15,588 fail2ban.filter [1708]: INFO [plesk-wordpress] Found 108.179.253.165 - 2026-08-11 19:44:15cloudlinux2 fail2ban: 2026-08-11 19:45:01,289 fail2ban.filter [1708]: INFO [plesk-modsecurity] Found 49.37.152.138 - 2026-08-11 19:45:00cloudlinux2 fail2ban: 2026-08-11 19:45:25,332 fail2ban.filter [1708]: INFO [plesk-modsecurity] Found 34.23.58.46 - 2026-08-11 19:45:25cloudlinux2 fail2ban: 2026-08-11 19:45:25,341 fail2ban.filter [1708]: INFO [plesk-modsecurity] Found 34.23.58.46 - 2026-08-11 19:45:25cloudlinux2 fail2ban: 2026-08-11 19:45:28,487 fail2ban.filter [1708]: INFO [plesk-modsecurity] Found 34.23.58.46 - 2026-08-11 19:45:28cloudlinux2 fail2ban: 2026-08-11 19:45:28,578 fail2ban.filter [1708]: INFO [recidive] Found 34.23.58.46 - 2026-08-11 19:45:28cloudlinux2 fail2ban: 2026-08-11 19:45:28,567 fail2ban.actions [1708]: NOTICE [plesk-modsecurity] Ban 34.23.58.46cloudlinux2 fail2ban: 2026-08-11 19:45
show less
Web App Attack
๐ซ๐ฎ
Rauno Asp
2026-08-11 03:12:45
(3 weeks ago)
Automated .env credentials scanning attempt detected by honeypot on elbasanapartments.al
Web App Attack
๐ซ๐ฎ
Rauno Asp
2026-08-08 01:00:29
(3 weeks ago)
Automated .env credentials scanning attempt detected by honeypot on elbasanapartments.al
Web App Attack
๐ฎ๐ณ
evicky2002
2026-08-06 06:00:01
(3 weeks ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐ซ๐ฎ
Rauno Asp
2026-08-06 03:45:20
(3 weeks ago)
Automated .env credentials scanning attempt detected by honeypot on elbasanapartments.al
Web App Attack
๐ซ๐ท
mail.avx.gr
2026-08-05 20:51:47
(3 weeks ago)
Plesk Fail2Ban jail: Plesk-Web-Exploits. Evidence: 209.87.167.249 - - [04/Aug/2026:17:35:58 +0300] " ...
show more
Plesk Fail2Ban jail: Plesk-Web-Exploits. Evidence: 209.87.167.249 - - [04/Aug/2026:17:35:58 +0300] "GET /.env HTTP/1.1" 301 162 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0"
show less
Web App Attack
Anonymous
2026-08-05 04:31:57
(4 weeks ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
๐ต๐ฑ
Budyn
2026-08-04 20:36:52
(4 weeks ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit Block. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: budyn.ovh | URI: /.env | UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0 | BODY: [Empty / GET Request]
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-04 20:30:54
(4 weeks ago)
(mod_security) mod_security (id:210492) triggered by 209.87.167.249 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 209.87.167.249 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 04 16:30:48.359026 2026] [security2:error] [pid 1207953:tid 1207953] [client 209.87.167.249:64575] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "1healthplace.com"] [uri "/.env"] [unique_id "anJL-Ob5PtV14SlEbZ_CgwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-04 19:47:06
(4 weeks ago)
(mod_security) mod_security (id:210492) triggered by 209.87.167.249 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 209.87.167.249 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 04 15:47:00.248786 2026] [security2:error] [pid 2198974:tid 2198974] [client 209.87.167.249:35887] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pcsyportatiles.com"] [uri "/.env"] [unique_id "anJBtLJ3TDYfDtHhzM55YQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
CoreTech srl
2026-08-04 18:31:35
(4 weeks ago)
cloudlinux2 fail2ban: 2026-08-04 19:37:41,158 fail2ban.actions [1468]: NOTICE [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-08-04 19:37:41,158 fail2ban.actions [1468]: NOTICE [plesk-modsecurity] Unban 209.87.167.249cloudlinux2 fail2ban: 2026-08-04 19:37:57,558 fail2ban.filter [1468]: INFO [plesk-modsecurity] Found 209.87.167.249 - 2026-08-04 19:37:57cloudlinux2 fail2ban: 2026-08-04 19:37:54,159 fail2ban.filter [1468]: INFO [plesk-modsecurity] Found 209.87.167.249 - 2026-08-04 19:37:54cloudlinux2 fail2ban: 2026-08-04 19:38:00,705 fail2ban.filter [1468]: INFO [plesk-modsecurity] Found 209.87.167.249 - 2026-08-04 19:38:00cloudlinux2 fail2ban: 2026-08-04 19:38:01,200 fail2ban.filter [1468]: INFO [recidive] Found 209.87.167.249 - 2026-08-04 19:38:01cloudlinux2 fail2ban: 2026-08-04 19:38:01,194 fail2ban.actions [1468]: NOTICE [plesk-modsecurity] Ban 209.87.167.249cloudlinux2 fail2ban: 2026-08-04 19:38:18,434 fail2ban.filter [1468]: INFO [recidive] Found 46.232.235.6 - 2026-08-04 19:38:18cloudlinux2 fail2ban: 2026-08-04 19:38:17,833 fail2ban
show less
Brute-Force
๐ฌ๐ง
thetomtaylor.co.uk
2026-08-04 16:07:02
(4 weeks ago)
Fail2Ban - [WEB]Custom exploit pattern detected on customexploits ... [ice01,ice02,wa01,wa02]
Hacking
Brute-Force
Bad Web Bot
Web App Attack