๐ณ๐ฑ
e.fierstra
2026-09-26 02:11:42
(15 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-26 01:57:27
(16 hours ago)
[ti-17al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-17al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 2a02:4780:63:4df::1 - - [26/Sep/2026:03:57:13 +0200] "GET /.env.txt HTTP/1.1" 301 549 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
๐จ๐ฆ
Anytech
2026-09-25 21:21:51
(20 hours ago)
Blocked by Conn-Monitor: env-probing
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-25 20:55:16
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:63:4df::1 (srv1488650.hstgr.cloud): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:63:4df::1 (srv1488650.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 25 16:55:09.950568 2026] [security2:error] [pid 30058:tid 30058] [client 2a02:4780:63:4df::1:33598] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bacona.org"] [uri "/.env.txt"] [unique_id "arbfrQdL5cQuBgo4vc2MCgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-25 16:05:52
(1 day ago)
2a02:4780:63:4df::1 - - [25/Sep/2026:16:05:49 +0000] "GET / HTTP/1.1" 302 427 "-" "Mozilla/5.0 (Wind ...
show more
2a02:4780:63:4df::1 - - [25/Sep/2026:16:05:49 +0000] "GET / HTTP/1.1" 302 427 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
2a02:4780:63:4df::1 - - [25/Sep/2026:16:05:51 +0000] "GET /pathscan-5541973e3892-nope.env HTTP/1.1" 302 487 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
2a02:4780:63:4df::1 - - [25/Sep/2026:16:05:51 +0000] "GET /pathscan-5541973e3892-nope.env HTTP/1.1" 404 2934 "http://www.simon.butcher.name/pathscan-5541973e3892-nope.env" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
2a02:4780:63:4df::1 - - [25/Sep/2026:16:05:52 +0000] "GET /.env.txt HTTP/1.1" 302 443 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
2a02:4780:63:4df::1 - - [25/Sep/2026:16:05:52 +0000] "GET /.git/config HTTP/1.1" 302 449
...
show less
Bad Web Bot
๐ต๐ฑ
Budyn
2026-09-25 15:04:24
(1 day ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: docker.dont-eat-the-pudding.xyz | URI: /.env.txt | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-25 10:19:43
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:63:4df::1 (srv1488650.hstgr.cloud): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:63:4df::1 (srv1488650.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 25 06:19:38.028729 2026] [security2:error] [pid 5375:tid 5375] [client 2a02:4780:63:4df::1:47058] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "crr-construction.com"] [uri "/wp-config.php.bak"] [unique_id "arZKuiKhFpYvIG-UlM0NxwAAAEM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-25 08:54:19
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:63:4df::1 (srv1488650.hstgr.cloud): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:63:4df::1 (srv1488650.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 25 04:54:14.138262 2026] [security2:error] [pid 11054:tid 11054] [client 2a02:4780:63:4df::1:52818] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "talesofhartwellhouse.com"] [uri "/.env.txt"] [unique_id "arY2thJgOTmavO-uBeKhfwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-25 06:52:45
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:63:4df::1 (srv1488650.hstgr.cloud): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:63:4df::1 (srv1488650.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 25 02:52:41.970144 2026] [security2:error] [pid 17804:tid 17804] [client 2a02:4780:63:4df::1:45700] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wmodradio.com"] [uri "/.env.txt"] [unique_id "arYaOfChe-o7ap8VFx0Q_wAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-25 04:47:32
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:63:4df::1 (srv1488650.hstgr.cloud): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:63:4df::1 (srv1488650.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 25 00:47:27.959888 2026] [security2:error] [pid 27566:tid 27566] [client 2a02:4780:63:4df::1:47934] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "laurenglor.today"] [uri "/.env.txt"] [unique_id "arX83__DU4xNmzf4e_JngAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Catalin Negru
2026-09-25 00:02:23
(1 day ago)
Recidive ban by fail2ban on server.blackbit.ro
Brute-Force
๐ต๐ฑ
Budyn
2026-09-24 23:32:07
(1 day ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: kibana.budyn.top | URI: /.env.dev | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 21:15:20
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:63:4df::1 (srv1488650.hstgr.cloud): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:63:4df::1 (srv1488650.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 17:15:14.600932 2026] [security2:error] [pid 27917:tid 27917] [client 2a02:4780:63:4df::1:50172] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "itsopossum.flyingdodostudio.com"] [uri "/.env.txt"] [unique_id "arWS4hNuFxuRzQ4W6fne9QAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 20:38:18
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:63:4df::1 (srv1488650.hstgr.cloud): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:63:4df::1 (srv1488650.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 16:38:14.769635 2026] [security2:error] [pid 15945:tid 15945] [client 2a02:4780:63:4df::1:57300] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "michaelholdawayvideos.info"] [uri "/.env.txt"] [unique_id "arWKNuzPu2NaSGhEUtUfQAAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 19:39:35
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:63:4df::1 (srv1488650.hstgr.cloud): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:63:4df::1 (srv1488650.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 15:39:28.742602 2026] [security2:error] [pid 6432:tid 6432] [client 2a02:4780:63:4df::1:49204] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "barnesandbrower.com"] [uri "/.env.txt"] [unique_id "arV8cP4b-pNaGEEFy-xPqwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack