๐บ๐ธ
TPI-Abuse
2026-09-20 18:56:19
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:66:3b4f::1 (srv818723.hstgr.cloud): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:66:3b4f::1 (srv818723.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 14:56:15.333826 2026] [security2:error] [pid 9565:tid 9565] [client 2a02:4780:66:3b4f::1:57764] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mrflatpeople.com"] [uri "/.git/config"] [unique_id "arAsT4tffWcZ_qONo6pVxwAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-09-20 16:17:32
(3 hours ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.env.txt | 2026-09-20 16:17 UTC
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 03:24:36
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:66:3b4f::1 (srv818723.hstgr.cloud): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:66:3b4f::1 (srv818723.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 23:24:31.433457 2026] [security2:error] [pid 23660:tid 23660] [client 2a02:4780:66:3b4f::1:52826] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lindamsweeney.com"] [uri "/.git/config"] [unique_id "aq9R70ctjDe8Ov29WFEsnwAAACg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-19 23:37:05
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:66:3b4f::1 (srv818723.hstgr.cloud): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:66:3b4f::1 (srv818723.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 19:36:57.734389 2026] [security2:error] [pid 15241:tid 15241] [client 2a02:4780:66:3b4f::1:38262] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "canarysuites.com"] [uri "/.env.txt"] [unique_id "aq8cmRztguT7lGTBf0kRegAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
tecnoacquisti.com
2026-09-19 22:13:19
(22 hours ago)
PrestaShop Security Module: suspicious probe path detected (/.env)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-19 17:35:47
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:66:3b4f::1 (srv818723.hstgr.cloud): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:66:3b4f::1 (srv818723.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 13:35:39.727788 2026] [security2:error] [pid 12263:tid 12263] [client 2a02:4780:66:3b4f::1:33390] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "easyweb-publishing.com"] [uri "/.env.txt"] [unique_id "aq7H6ymlHJkqJIp5ZP0POQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-19 10:11:47
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:66:3b4f::1 (srv818723.hstgr.cloud): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:66:3b4f::1 (srv818723.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 06:11:41.533852 2026] [security2:error] [pid 29715:tid 29715] [client 2a02:4780:66:3b4f::1:57608] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "celeritas.borzois.com"] [uri "/.env.txt"] [unique_id "aq5f3SX8aFmTnyktfiaVUgAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ต๐ฑ
Budyn
2026-09-19 07:19:33
(1 day ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: registry.astropot.website | URI: /.env.txt | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-19 00:56:29
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:66:3b4f::1 (srv818723.hstgr.cloud): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:66:3b4f::1 (srv818723.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 18 20:56:23.039415 2026] [security2:error] [pid 5987:tid 5987] [client 2a02:4780:66:3b4f::1:50684] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.radioairplay.joebankx.com"] [uri "/.env.txt"] [unique_id "aq3dt_LND7D1XQ-R7pAF9gAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-18 04:56:14
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:66:3b4f::1 (srv818723.hstgr.cloud): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:66:3b4f::1 (srv818723.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 18 00:56:09.234133 2026] [security2:error] [pid 13066:tid 13066] [client 2a02:4780:66:3b4f::1:40072] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.bamedica.com"] [uri "/wp-config.php.bak"] [unique_id "aqzEacB9ispfdta8pjCtNAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-17 23:59:48
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:66:3b4f::1 (srv818723.hstgr.cloud): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:66:3b4f::1 (srv818723.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 19:59:43.734219 2026] [security2:error] [pid 24407:tid 24407] [client 2a02:4780:66:3b4f::1:41722] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bizecomm.com"] [uri "/.env.txt"] [unique_id "aqx-79rXCOfeY1bg1q4G8wAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-17 11:36:27
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:66:3b4f::1 (srv818723.hstgr.cloud): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:66:3b4f::1 (srv818723.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 07:36:23.140435 2026] [security2:error] [pid 7971:tid 7971] [client 2a02:4780:66:3b4f::1:37494] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.xgoga.elpais.mx"] [uri "/.env.txt"] [unique_id "aqvQtyeUZjeaAHjOd8L-6wAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-17 10:52:40
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:66:3b4f::1 (srv818723.hstgr.cloud): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:66:3b4f::1 (srv818723.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 06:52:37.158701 2026] [security2:error] [pid 18872:tid 18872] [client 2a02:4780:66:3b4f::1:55364] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.editions.click.dandemonium.net"] [uri "/.env.txt"] [unique_id "aqvGdQjANUib-rPSyESWwgAAACc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ต๐ฑ
Budyn
2026-09-17 10:21:30
(3 days ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: metrics.astropot.tech | URI: /.git/config | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
๐ต๐ฑ
wielorzeczownik
2026-09-17 07:54:30
(3 days ago)
5 failed attempts
2026-09-17 09:52:44 GET /.env -> 404
2026-09-17 09:52:46 GET /.env.bak -> 404 ...
show more
5 failed attempts
2026-09-17 09:52:44 GET /.env -> 404
2026-09-17 09:52:46 GET /.env.bak -> 404
2026-09-17 09:54:07 GET /.env.swp -> 404
2026-09-17 09:54:17 GET /.env.txt -> 404
2026-09-17 09:54:30 GET /.git/config -> 404
show less
Web App Attack
Hacking