๐ฉ๐ช
iRaphi05
2026-08-23 10:30:59
(1 hour ago)
Honeypot detection: GET request on /local/.env | User-Agent: Mozilla/5.0 (Windows NT 6.1) AppleWebKi ...
show more
Honeypot detection: GET request on /local/.env | User-Agent: Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36
show less
Hacking
Web App Attack
Anonymous
2026-08-23 10:19:04
(1 hour ago)
Bot / scanning and/or hacking attempts: POST /wp-login.php HTTP/1.1
Hacking
Web App Attack
๐บ๐ธ
azminawwar
2026-08-23 06:05:42
(5 hours ago)
[45.132.227.67] triggered by honeypot on port [80], Timestamp [2026-08-23T06:05:41Z]METHOD=GET PATH= ...
show more
[45.132.227.67] triggered by honeypot on port [80], Timestamp [2026-08-23T06:05:41Z]METHOD=GET PATH=/local/.env HTTP=HTTP/1.1 UA="Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Ch
show less
Port Scan
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-23 03:53:34
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 45.132.227.67 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 45.132.227.67 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 23:53:15.629244 2026] [security2:error] [pid 30741:tid 30741] [client 45.132.227.67:20181] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.142"] [uri "/.env"] [unique_id "aopuqxs7kV7bwidWzSA8bQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-22 12:31:46
(23 hours ago)
Web App Attack
Brute-Force
Exploited Host
Web App Attack
๐ซ๐ฎ
geot
2026-08-22 09:57:21
(1 day ago)
GET /<<removed>>.com/.env HTTP/1.1
Hacking
Web App Attack
๐ฉ๐ช
neckaralb-admin.de
2026-08-21 20:20:42
(1 day ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
๐ซ๐ฎ
YF
2026-08-21 18:00:59
(1 day ago)
WordPress author enumeration
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-21 16:42:52
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 45.132.227.67 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 45.132.227.67 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 12:42:38.962612 2026] [security2:error] [pid 27091:tid 27095] [client 45.132.227.67:30747] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.128"] [uri "/library/.env"] [unique_id "aoh__qeNnIy05WQEjciSHwAAAUI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-21 15:57:18
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 45.132.227.67 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 45.132.227.67 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 11:56:58.957451 2026] [security2:error] [pid 3908:tid 3908] [client 45.132.227.67:59023] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.194"] [uri "/api/.env"] [unique_id "aoh1SqoBWrHg0aZ9rB9fngAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-21 15:27:56
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 45.132.227.67 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 45.132.227.67 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 11:27:51.171733 2026] [security2:error] [pid 31615:tid 31615] [client 45.132.227.67:23183] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.215"] [uri "/wp-admin/.env"] [unique_id "aohud2ADqjFX9sLUblQTIQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
ipblock.com
2026-08-21 15:03:00
(1 day ago)
Exploit request, vulnerability scanner.
Hacking
Bad Web Bot
Web App Attack
๐จ๐ญ
Zdenฤk Svancar
2026-08-21 12:08:02
(1 day ago)
45.132.227.67 - - [21/Aug/2026:12:08:00 +0000] "GET /src/.env HTTP/1.1" 404 181 "-" "Mozilla/5.0 (Wi ...
show more
45.132.227.67 - - [21/Aug/2026:12:08:00 +0000] "GET /src/.env HTTP/1.1" 404 181 "-" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36"
45.132.227.67 - - [21/Aug/2026:12:08:01 +0000] "GET /base/.env HTTP/1.1" 404 181 "-" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36"
...
show less
Port Scan
Bad Web Bot
Web App Attack
๐ฆ๐บ
afleventoffice.com.au
2026-08-21 09:39:14
(2 days ago)
GET /wp-login.php HTTP/1.1
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-21 09:17:22
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 45.132.227.67 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 45.132.227.67 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 05:17:05.789934 2026] [security2:error] [pid 20787:tid 20787] [client 45.132.227.67:46711] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.166"] [uri "/cgi-bin/.env"] [unique_id "aogXkZZysTDeD0xrnvDRYgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack