๐บ๐ธ
craudiovizai
2026-09-30 18:31:04
(1 hour ago)
Automated honeypot detection. blocked ip against a Next.js application. Paths: /.env. Blocked at the ...
show more
Automated honeypot detection. blocked ip against a Next.js application. Paths: /.env. Blocked at the edge.
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-30 13:56:06
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 41.143.167.29 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 41.143.167.29 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 09:56:02.744061 2026] [security2:error] [pid 306:tid 306] [client 41.143.167.29:52172] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "yaseminelhan.com"] [uri "/.env"] [unique_id "ar0U8u-353cuRR0XCqA2NAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 13:37:44
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 41.143.167.29 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 41.143.167.29 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 09:37:39.727141 2026] [security2:error] [pid 7688:tid 7695] [client 41.143.167.29:60824] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "annie-interface.org"] [uri "/.env"] [unique_id "ar0Qo7elAtFaQpwdQ63A7QAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
sibahota
2026-09-30 13:18:28
(6 hours ago)
41.143.167.29 - - [30/Sep/2026:13:18:24 +0000] nidandiagnostic.com "GET /.env HTTP/1.1" 403 37 0.000 ...
show more
41.143.167.29 - - [30/Sep/2026:13:18:24 +0000] nidandiagnostic.com "GET /.env HTTP/1.1" 403 37 0.000 "-" "-" - - - "http://nidandiagnostic.com"
...
show less
Web App Attack
Brute-Force
๐จ๐ฟ
akac
2026-09-30 13:03:11
(6 hours ago)
Web vulnerability scanning: HTTP/1.1 GET /.env
Hacking
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 12:13:00
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 41.143.167.29 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 41.143.167.29 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 08:12:54.969476 2026] [security2:error] [pid 18377:tid 18377] [client 41.143.167.29:57408] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.training.oxfordgliding.com"] [uri "/.env"] [unique_id "arz8xmuk4ZmLlsFwp60i8AAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Swiptly
2026-09-30 11:57:26
(8 hours ago)
Bot scanning for environment files .env .env/\*
...
Web App Attack
๐ซ๐ท
pm33
2026-09-30 11:49:36
(8 hours ago)
Probing for resource vulnerabilities HTTP(S)
Web App Attack
Anonymous
2026-09-30 11:47:11
(8 hours ago)
41.143.167.29 - - [30/Sep/2026:08:47:09 -0300] "GET /.env HTTP/1.1" 403 1810 "-" "-"
41.143.167.29 - ...
show more
41.143.167.29 - - [30/Sep/2026:08:47:09 -0300] "GET /.env HTTP/1.1" 403 1810 "-" "-"
41.143.167.29 - - [30/Sep/2026:08:47:09 -0300] "GET /.env HTTP/1.1" 403 1810 "-" "-"
...
show less
Port Scan
๐ฉ๐ช
XICTRON
2026-09-30 11:40:08
(8 hours ago)
ModSecurity rule violation detected by Fail2Ban
Web App Attack
๐บ๐ธ
maxasp.net
2026-09-30 11:25:02
(8 hours ago)
Inc-HTTP-Safe Reject, collection = Risk Profile; Attack Var: IP Address; Attack Data: High Abuse Sco ...
show more
Inc-HTTP-Safe Reject, collection = Risk Profile; Attack Var: IP Address; Attack Data: High Abuse Score (reason code 13); Abuse Score: 100; Usage Type: Fixed Line ISP; ip attacks: 1; subnet attacks: 1
show less
SQL Injection
๐ฌ๐ง
kie
2026-09-30 11:20:31
(8 hours ago)
30-09-2026:11:20:01UTC [Nginx Web Server] Suspicious web request: path:/.env (2 request(s)).
Bad Web Bot
Web App Attack
Anonymous
2026-09-30 10:54:11
(9 hours ago)
41.143.167.29 - - [30/Sep/2026:12:54:10 +0200] "GET /.env HTTP/1.1" 301 169 "-" "-"
Web App Attack
๐ฉ๐ช
Gwyneth Llewelyn
2026-09-30 10:38:11
(9 hours ago)
41.143.167.29 - - [30/Sep/2026:11:38:08 +0100] "GET /.env HTTP/2.0" 301 162 "-" "-"
2026/09/30 11:38 ...
show more
41.143.167.29 - - [30/Sep/2026:11:38:08 +0100] "GET /.env HTTP/2.0" 301 162 "-" "-"
2026/09/30 11:38:10 [error] 3532286#3532286: *1463003 access forbidden by rule, client: 41.143.167.29, server: mar.pt, request: "GET /.env HTTP/2.0", host: "mar.pt", referrer: "https://www.mar.pt/.env"
41.143.167.29 - - [30/Sep/2026:11:38:10 +0100] "GET /.env HTTP/2.0" 403 1045 "https://www.mar.pt/.env" "-"
show less
Brute-Force
Web App Attack
Anonymous
2026-09-30 10:27:20
(9 hours ago)
Web App Attack
Brute-Force
Exploited Host
Web App Attack