🇫🇮
geot
2026-08-26 13:04:01
(3 days ago)
GET /public/.env HTTP/1.1
Hacking
Web App Attack
🇹🇷
oalver
2026-08-25 21:13:30
(3 days ago)
Detected by SiberKapan threat intelligence platform (siberkapan.org). Attack types: nginx_path_signa ...
show more
Detected by SiberKapan threat intelligence platform (siberkapan.org). Attack types: nginx_path_signature. Sources: nginx. Details: path_signature: request to /wp-content/.env (HTTP 301). First seen: 2026-08-25. Risk score: 30/100.
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-08-25 19:02:37
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 45.132.227.200 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 45.132.227.200 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 15:02:10.581223 2026] [security2:error] [pid 32356:tid 32356] [client 45.132.227.200:23433] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.244"] [uri "/backend/.env"] [unique_id "ao3mstyfhRTE7JEJJC-oVgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-25 13:04:57
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 45.132.227.200 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 45.132.227.200 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 09:04:12.898968 2026] [security2:error] [pid 22139:tid 22139] [client 45.132.227.200:38887] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.30"] [uri "/library/.env"] [unique_id "ao2SzGYB6YPf4h7t8fU9MQAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
big-cloud.nl
2026-08-25 13:01:15
(4 days ago)
Try to access /storage/.env
Web App Attack
🇩🇪
Holger
2026-08-25 12:54:58
(4 days ago)
URL probing: GET /new/.env
Web App Attack
🇺🇸
TPI-Abuse
2026-08-25 11:43:42
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 45.132.227.200 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 45.132.227.200 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 07:43:35.054709 2026] [security2:error] [pid 18985:tid 18985] [client 45.132.227.200:58569] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.122"] [uri "/local/.env"] [unique_id "ao1_560KN_lUNdPmrZk9QwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
CoreTech srl
2026-08-22 02:43:56
(1 week ago)
cloudlinux2 fail2ban: 2026-08-22 04:38:48,005 fail2ban.filter [1480]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-08-22 04:38:48,005 fail2ban.filter [1480]: INFO [plesk-modsecurity] Found 172.71.141.98 - 2026-08-22 04:38:47cloudlinux2 fail2ban: 2026-08-22 04:38:47,992 fail2ban.filter [1480]: INFO [plesk-modsecurity] Found 172.71.141.98 - 2026-08-22 04:38:47cloudlinux2 fail2ban: 2026-08-22 04:39:16,351 fail2ban.filter [1480]: INFO [plesk-modsecurity] Found 172.68.174.56 - 2026-08-22 04:39:15cloudlinux2 fail2ban: 2026-08-22 04:39:16,364 fail2ban.filter [1480]: INFO [plesk-modsecurity] Found 172.68.174.200 - 2026-08-22 04:39:15cloudlinux2 fail2ban: 2026-08-22 04:39:29,710 fail2ban.filter [1480]: INFO [plesk-wordpress] Found 45.132.227.200 - 2026-08-22 04:39:29cloudlinux2 fail2ban: 2026-08-22 04:40:41,290 fail2ban.filter [1480]: INFO [plesk-modsecurity] Found 172.68.174.105 - 2026-08-22 04:40:41cloudlinux2 fail2ban: 2026-08-22 04:40:41,278 fail2ban.filter [1480]: INFO [plesk-modsecurity] Found 172.68.174.105 - 2026-08-22 0
show less
Web App Attack
🇺🇸
lostswordfish.com
2026-08-21 10:48:04
(1 week ago)
Wordfence waf block on registrymatters
Web App Attack
🇧🇪
brechtr
2026-08-19 08:11:24
(1 week ago)
[Press84-BanHammer] bad username — Sourced from: brechtryckaert.com — Request: POST /wp-login.php
Brute-Force
🇩🇪
neckaralb-admin.de
2026-08-16 06:06:42
(1 week ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
🇬🇧
thetomtaylor.co.uk
2026-08-16 02:07:01
(1 week ago)
Fail2Ban - [NGINX]WordPress Logins Sniffings on nginx-wordpress-sniffer ... [ice01,wa01,wa02]
Bad Web Bot
Web App Attack
🇮🇹
CoreTech srl
2026-08-16 01:48:56
(1 week ago)
cloudlinux2 fail2ban: 2026-08-16 03:43:49,798 fail2ban.filter [1695]: INFO [plesk-wordpre ...
show more
cloudlinux2 fail2ban: 2026-08-16 03:43:49,798 fail2ban.filter [1695]: INFO [plesk-wordpress] Found 45.132.227.200 - 2026-08-16 03:43:49cloudlinux2 fail2ban: 2026-08-16 03:43:49,698 fail2ban.filter [1695]: INFO [plesk-wordpress] Found 185.251.19.60 - 2026-08-16 03:43:49cloudlinux2 fail2ban: 2026-08-16 03:45:08,212 fail2ban.filter [1695]: INFO [plesk-modsecurity] Found 145.79.152.225 - 2026-08-16 03:45:08cloudlinux2 fail2ban: 2026-08-16 03:45:43,947 fail2ban.filter [1695]: INFO [plesk-wordpress] Found 216.24.219.77 - 2026-08-16 03:45:43cloudlinux2 fail2ban: 2026-08-16 03:46:19,629 fail2ban.filter [1695]: INFO [plesk-modsecurity] Found 143.44.193.176 - 2026-08-16 03:46:19cloudlinux2 fail2ban: 2026-08-16 03:46:52,328 fail2ban.filter [1695]: INFO [plesk-modsecurity] Found 143.44.193.176 - 2026-08-16 03:46:51cloudlinux2 fail2ban: 2026-08-16 03:46:49,614 fail2ban.filter [1695]: INFO [plesk-modsecurity] Found 34.13.255.129 - 2026-08-16 03:46
show less
Web App Attack
🇬🇧
thetomtaylor.co.uk
2026-08-16 01:08:01
(1 week ago)
Fail2Ban - [NGINX]WordPress Logins Sniffings on nginx-wordpress-sniffer ... [ice02,mx02]
Bad Web Bot
Web App Attack
🇲🇹
Malta
2026-08-16 00:34:38
(1 week ago)
45.132.227.200 - - [16/Aug/2026:02:34:37 +0200] "POST /wp-login.php HTTP/1.1" "Mozilla/5.0 (Windows ...
show more
45.132.227.200 - - [16/Aug/2026:02:34:37 +0200] "POST /wp-login.php HTTP/1.1" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 Chrome/129.0.0.0 Safari/537.36"
show less
Hacking
Web App Attack