๐ณ๐ฑ
Savvii
2026-06-15 15:26:20
(2 hours ago)
20 attempts against mh-misbehave-ban on ricardo-dev
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Savvii
2026-06-15 13:57:10
(3 hours ago)
20 attempts against mh-misbehave-ban on lime
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-06-15 10:11:34
(7 hours ago)
Excessive multi-domain requests
Brute-Force
๐ซ๐ท
phoenix1jl96
2026-06-15 10:02:05
(7 hours ago)
2026/06/15 12:01:34 [error] 5455#5455: *33650 open() "/home/user-data/www/default/mailer/sendgrid.en ...
show more
2026/06/15 12:01:34 [error] 5455#5455: *33650 open() "/home/user-data/www/default/mailer/sendgrid.env" failed (2: No such file or directory), client: 35.190.187.26, server: box.ledemon.us, request: "GET /mailer/sendgrid.env HTTP/1.1", host: "info.d216-cloud-backup.direct.quickconnect.to"
2026/06/15 12:01:34 [error] 5455#5455: *33653 open() "/usr/local/lib/roundcubemail/sendgrid.env" failed (2: No such file or directory), client: 35.190.187.26, server: box.ledemon.us, request: "GET /mail/sendgrid.env HTTP/1.1", host: "info.d216-cloud-backup.direct.quickconnect.to"
...
show less
DNS Compromise
DNS Poisoning
DDoS Attack
Ping of Death
Web Spam
Email Spam
Blog Spam
Port Scan
Hacking
Brute-Force
Bad Web Bot
SSH
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-15 09:05:34
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.190.187.26 (26.187.190.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.190.187.26 (26.187.190.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 05:05:26.577530 2026] [security2:error] [pid 28308:tid 28308] [client 35.190.187.26:47250] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "vycestudiojuridico.cl"] [uri "/.env"] [unique_id "ai_AVngMdPJrIxtAGBSHxgAAAGM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-15 06:37:20
(10 hours ago)
Multiple web server 400 error codes from same source ip
Web App Attack
๐ฌ๐ง
consul.to
2026-06-15 06:10:54
(11 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐ซ๐ท
Octopuce
2026-06-15 04:20:33
(13 hours ago)
Aggressive web search of vulnerable pages: /services/backend/.env /api/backend/.env /web/.env /servi ...
show more
Aggressive web search of vulnerable pages: /services/backend/.env /api/backend/.env /web/.env /services/auth/.env /sendgrid/.env ...
show less
Web App Attack
๐ฉ๐ช
BlueWire Hosting
2026-06-15 02:20:43
(15 hours ago)
Bad bot ignoring robot.txt
Bad Web Bot
๐ง๐พ
lns.bz
2026-06-15 00:01:37
(17 hours ago)
.env scanning [BY]
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-14 23:35:46
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.190.187.26 (26.187.190.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.190.187.26 (26.187.190.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 19:35:40.956631 2026] [security2:error] [pid 27142:tid 27142] [client 35.190.187.26:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.cloudex.click"] [uri "/.env.testing"] [unique_id "ai86zIsNDdcZhUOEkJaqKQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐พ
lns.bz
2026-06-14 13:51:28
(1 day ago)
Too many 404 requests [BY]
Web App Attack
๐บ๐ธ
lime
2026-06-14 12:33:06
(1 day ago)
35.190.187.26 - - [14/Jun/2026:12:33:05 +0000] "GET /.env.preprod HTTP/1.1" 404 4236 "-" "Googlebot- ...
show more
35.190.187.26 - - [14/Jun/2026:12:33:05 +0000] "GET /.env.preprod HTTP/1.1" 404 4236 "-" "Googlebot-News"
show less
Hacking
Web App Attack
๐ฎ๐น
VHosting
2026-06-14 06:20:03
(1 day ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-14 05:56:57
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.190.187.26 (26.187.190.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.190.187.26 (26.187.190.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 01:56:53.516513 2026] [security2:error] [pid 23292:tid 23292] [client 35.190.187.26:41482] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "drjasonkolber.com"] [uri "/.env.dist"] [unique_id "ai5CpdkXKyK8W_6320-ABwAAAHc"]
show less
Brute-Force
Bad Web Bot
Web App Attack