Anonymous
2026-09-09 23:52:20
(8 hours ago)
"GET /.env HTTP/1.1"
Hacking
Web App Attack
🇩🇪
todix
2026-09-09 16:32:26
(15 hours ago)
Web App Attack Exploid from 34.58.212.118
Web App Attack
🇨🇦
polycoda
2026-09-09 15:45:40
(16 hours ago)
AutoBlock: 🎯 Vulnerability Scanner (Non Decay-Based)
Hacking
Web App Attack
🇮🇹
CoreTech srl
2026-09-09 15:28:56
(16 hours ago)
cloudlinux2 fail2ban: 2026-09-09 17:25:20,531 fail2ban.filter [1892]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-09-09 17:25:20,531 fail2ban.filter [1892]: INFO [plesk-modsecurity] Found 5.31.189.102 - 2026-09-09 17:25:20cloudlinux2 fail2ban: 2026-09-09 17:25:33,774 fail2ban.filter [1892]: INFO [plesk-wordpress] Found 193.56.116.244 - 2026-09-09 17:25:33cloudlinux2 fail2ban: 2026-09-09 17:25:29,544 fail2ban.filter [1892]: INFO [plesk-wordpress] Found 193.56.116.244 - 2026-09-09 17:25:29cloudlinux2 fail2ban: 2026-09-09 17:26:24,989 fail2ban.filter [1892]: INFO [plesk-modsecurity] Found 34.58.212.118 - 2026-09-09 17:26:24cloudlinux2 fail2ban: 2026-09-09 17:26:43,523 fail2ban.actions [1892]: NOTICE [plesk-modsecurity] Unban 123.253.180.101cloudlinux2 fail2ban: 2026-09-09 17:26:50,965 fail2ban.filter [1892]: INFO [plesk-wordpress] Found 173.239.211.25 - 2026-09-09 17:26:50cloudlinux2 fail2ban: 2026-09-09 17:26:51,499 fail2ban.actions [1892]: NOTICE [plesk-wordpress] Unban 173.239.211.33cloudlinux2 fail2ban: 2026-09-09 17:26:46,
show less
Web App Attack
🇬🇧
thetomtaylor.co.uk
2026-09-09 15:08:01
(16 hours ago)
Fail2Ban - [WEB]Custom exploit pattern detected on customexploits ... [ice01,ice02,wa01,wa02]
Hacking
Brute-Force
Bad Web Bot
Web App Attack
🇦🇺
A.i.D.A.N.N
2026-09-09 14:20:00
(17 hours ago)
A.i.D.A.N.N: Anomaly Detected - Signature match Web Service - Web application attack detected
Web App Attack
🇸🇬
anotherwatcher
2026-09-09 13:40:15
(18 hours ago)
bad bot
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-09 13:38:39
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.58.212.118 (118.212.58.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.58.212.118 (118.212.58.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 09:38:34.018561 2026] [security2:error] [pid 22911:tid 22911] [client 34.58.212.118:61748] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "citywidereo.com"] [uri "/.env"] [unique_id "aqFhWg82xHatI3lCgCK3MQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
sdos.es
2026-09-09 13:34:49
(18 hours ago)
"Restricted File Access Attempt - Matched Data: /.env found within REQUEST_FILENAME: /.env"
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 13:03:32
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.58.212.118 (118.212.58.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.58.212.118 (118.212.58.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 09:03:28.478300 2026] [security2:error] [pid 15471:tid 15471] [client 34.58.212.118:51132] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "buynorthwest.com"] [uri "/.env"] [unique_id "aqFZIEWl8bzpWSddv-LdogAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
kosada.com
2026-09-09 12:59:47
(19 hours ago)
Repeated requests for suspicious nonexistent URLs, for example: /.env (HTTP/1.1 port 443, user agent ...
show more
Repeated requests for suspicious nonexistent URLs, for example: /.env (HTTP/1.1 port 443, user agent: "python-requests/2.34.2")
show less
Web App Attack
Anonymous
2026-09-09 12:33:04
(19 hours ago)
Web App Attack
Brute-Force
Exploited Host
Web App Attack
🇩🇪
Vegascosmetics
2026-09-09 12:29:51
(19 hours ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after sensitive config/credentials exposure ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after sensitive config/credentials exposure probe. Evidence: AttackPattern: /\.env (Match: /.env)
show less
Hacking
Brute-Force
Web App Attack
🇿🇦
conure.sh
2026-09-09 12:16:11
(19 hours ago)
csagent: score 20.0: secrets grab x2; 2 domain(s) in 0s
Web App Attack
🇫🇷
spot
2026-09-09 12:10:39
(19 hours ago)
34.58.212.118 - - [09/Sep/2026:13:10:39 +0100] "GET /.env HTTP/1.1" 301 594 "-" "python-requests/2.3 ...
show more
34.58.212.118 - - [09/Sep/2026:13:10:39 +0100] "GET /.env HTTP/1.1" 301 594 "-" "python-requests/2.34.2"
...
show less
Web App Attack
VPN IP