🇮🇹
CoreTech srl
2026-08-04 18:31:35
(1 month ago)
cloudlinux2 fail2ban: 2026-08-04 19:37:41,158 fail2ban.actions [1468]: NOTICE [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-08-04 19:37:41,158 fail2ban.actions [1468]: NOTICE [plesk-modsecurity] Unban 209.87.167.249cloudlinux2 fail2ban: 2026-08-04 19:37:57,558 fail2ban.filter [1468]: INFO [plesk-modsecurity] Found 209.87.167.249 - 2026-08-04 19:37:57cloudlinux2 fail2ban: 2026-08-04 19:37:54,159 fail2ban.filter [1468]: INFO [plesk-modsecurity] Found 209.87.167.249 - 2026-08-04 19:37:54cloudlinux2 fail2ban: 2026-08-04 19:38:00,705 fail2ban.filter [1468]: INFO [plesk-modsecurity] Found 209.87.167.249 - 2026-08-04 19:38:00cloudlinux2 fail2ban: 2026-08-04 19:38:01,200 fail2ban.filter [1468]: INFO [recidive] Found 209.87.167.249 - 2026-08-04 19:38:01cloudlinux2 fail2ban: 2026-08-04 19:38:01,194 fail2ban.actions [1468]: NOTICE [plesk-modsecurity] Ban 209.87.167.249cloudlinux2 fail2ban: 2026-08-04 19:38:18,434 fail2ban.filter [1468]: INFO [recidive] Found 46.232.235.6 - 2026-08-04 19:38:18cloudlinux2 fail2ban: 2026-08-04 19:38:17,833 fail2ban
show less
Brute-Force
🇬🇧
thetomtaylor.co.uk
2026-08-04 16:07:02
(1 month ago)
Fail2Ban - [WEB]Custom exploit pattern detected on customexploits ... [ice01,ice02,wa01,wa02]
Hacking
Brute-Force
Bad Web Bot
Web App Attack
🇷🇺
DZBOT
2026-08-04 15:44:34
(1 month ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
🇺🇸
Omega Threat-ID
2026-08-04 15:31:38
(1 month ago)
Omega Point Threat ID honeypot sensor observed: abuse-reported
Port Scan
🇳🇱
e.fierstra
2026-08-04 15:03:42
(1 month ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
Anonymous
2026-08-04 15:00:08
(1 month ago)
Bot / scanning and/or hacking attempts: GET /.env HTTP/1.1
Hacking
Web App Attack
Anonymous
2026-08-04 14:44:07
(1 month ago)
Automatically blocked after 1 security event. Observed sensitive configuration-file probes. Source: ...
show more
Automatically blocked after 1 security event. Observed sensitive configuration-file probes. Source: Cloudflare security controls.
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-08-04 14:38:40
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 209.87.167.249 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 209.87.167.249 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 04 10:38:34.802471 2026] [security2:error] [pid 1372463:tid 1372463] [client 209.87.167.249:65121] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "techlinks.com"] [uri "/.env"] [unique_id "anH5aoFpd8iv3x0AqyVoBAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
mail.avx.gr
2026-08-04 14:35:58
(1 month ago)
Plesk Fail2Ban jail: Plesk-Web-Exploits. Evidence: 209.87.167.249 - - [04/Aug/2026:17:35:58 +0300] " ...
show more
Plesk Fail2Ban jail: Plesk-Web-Exploits. Evidence: 209.87.167.249 - - [04/Aug/2026:17:35:58 +0300] "GET /.env HTTP/1.1" 301 162 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0"
show less
Web App Attack
🇺🇸
ArturShelby
2026-08-04 13:59:33
(1 month ago)
Critical file access: /.env
Web App Attack
Anonymous
2026-08-04 13:57:02
(1 month ago)
Unauthorized SSH login attempts
Brute-Force
SSH
🇺🇸
TPI-Abuse
2026-08-04 13:55:13
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 209.87.167.249 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 209.87.167.249 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 04 09:55:08.099646 2026] [security2:error] [pid 105088:tid 105088] [client 209.87.167.249:36675] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "agupgrade.net"] [uri "/.env"] [unique_id "anHvPEuPycORdSKklbpQSQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇴
jad-abuse
2026-08-04 13:28:28
(1 month ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: env_probe ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: env_probe. Observed by 1 sensor(s); 3 hits.
show less
Web App Attack
🇺🇸
SLSLLC
2026-08-04 13:19:46
(1 month ago)
209.87.167.249 - - [04/Aug/2026:13:19:46 +0000] "GET /.env HTTP/2.0" 403 1927 "-" "Mozilla/5.0 (Maci ...
show more
209.87.167.249 - - [04/Aug/2026:13:19:46 +0000] "GET /.env HTTP/2.0" 403 1927 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0"
...
show less
Brute-Force
Web App Attack
Anonymous
2026-07-29 07:00:00
(1 month ago)
Apache probe; attempts=1434; exact paths: /.env | /.env/ | /.env?page=.env | /.env?page=.env&page=.e ...
show more
Apache probe; attempts=1434; exact paths: /.env | /.env/ | /.env?page=.env | /.env?page=.env&page=.env | //wp/.env | /bg/.env | /bg/.env/ | /cs/.env | /cs/.env/ | /ro/.env | /ro/.env/ | /sk/.env | /sk/.env/ | /wp/.env
show less
Web App Attack