🇩🇪
langenkamp-media
2026-08-29 08:00:12
(9 hours ago)
Fail2Ban: Banned from jail nginx-nohome on 3dausdu.de
Web App Attack
🇺🇸
TPI-Abuse
2026-08-29 07:59:49
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 45.61.162.170 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 45.61.162.170 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 03:59:46.257769 2026] [security2:error] [pid 19685:tid 19685] [client 45.61.162.170:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hvacs-aircon.com"] [uri "/.env"] [unique_id "apKRck3-K4iBJgQm33WPxQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇪🇸
el-brujo
2026-08-29 07:38:13
(9 hours ago)
Cloudflare WAF: Request Path: /.env Request Query: Host: ns2.elhacker.net userAgent: Mozilla/5.0 (M ...
show more
Cloudflare WAF: Request Path: /.env Request Query: Host: ns2.elhacker.net userAgent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0 Action: block Source: firewallManaged ASN Description: RouterHosting LLC Country: US Method: GET Timestamp: 2026-08-29T07:38:13Z ruleId: 23548ee2b36547a1be09bb2c0550c529. Report generated by Cloudflare-WAF-to-AbuseIPDB.
show less
Hacking
SQL Injection
Web App Attack
🇺🇸
TPI-Abuse
2026-08-29 07:05:21
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 45.61.162.170 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 45.61.162.170 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 03:05:13.678945 2026] [security2:error] [pid 2588:tid 2588] [client 45.61.162.170:49839] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "huntingforebears.com"] [uri "/.env"] [unique_id "apKEqamFhdC0bb95GiBwXQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-29 07:04:12
(10 hours ago)
Fail2Ban triggered
Web App Attack
🇩🇪
conseilgouz
2026-08-29 06:34:29
(10 hours ago)
mae-17 : Block hidden directories=>/.env(/)
Hacking
🇮🇹
CoreTech srl
2026-08-29 06:34:00
(10 hours ago)
cloudlinux2 fail2ban: 2026-08-29 08:29:23,576 fail2ban.filter [1478]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-08-29 08:29:23,576 fail2ban.filter [1478]: INFO [plesk-modsecurity] Found 122.183.33.103 - 2026-08-29 08:29:23cloudlinux2 fail2ban: 2026-08-29 08:29:18,588 fail2ban.filter [1478]: INFO [plesk-modsecurity] Found 45.61.162.170 - 2026-08-29 08:29:18cloudlinux2 fail2ban: 2026-08-29 08:29:21,965 fail2ban.filter [1478]: INFO [plesk-modsecurity] Found 45.61.162.170 - 2026-08-29 08:29:21cloudlinux2 fail2ban: 2026-08-29 08:29:25,465 fail2ban.filter [1478]: INFO [plesk-modsecurity] Found 45.61.162.170 - 2026-08-29 08:29:25cloudlinux2 fail2ban: 2026-08-29 08:29:25,910 fail2ban.filter [1478]: INFO [recidive] Found 45.61.162.170 - 2026-08-29 08:29:25cloudlinux2 fail2ban: 2026-08-29 08:29:25,904 fail2ban.actions [1478]: NOTICE [plesk-modsecurity] Ban 45.61.162.170cloudlinux2 fail2ban: 2026-08-29 08:29:36,131 fail2ban.actions [1478]: NOTICE [plesk-modsecurity] Unban 103.18.15.232cloudlinux2 fail2ban: 2026-08-29 08:29:55,051 fai
show less
Brute-Force
Anonymous
2026-08-29 06:24:46
(10 hours ago)
Scraping for .env file
Web App Attack
🇩🇪
conseilgouz
2026-08-29 06:05:59
(11 hours ago)
gie-17 : Block hidden directories=>/.env(/)
Hacking
🇺🇸
TPI-Abuse
2026-08-29 06:03:56
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 45.61.162.170 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 45.61.162.170 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 02:03:48.597531 2026] [security2:error] [pid 4088:tid 4088] [client 45.61.162.170:50738] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nearbyxm.com"] [uri "/.env"] [unique_id "apJ2RB8mNTxFFG20fcivwgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-29 05:54:10
(11 hours ago)
path attack /.env
Web App Attack
🇺🇸
SLSLLC
2026-08-29 05:48:55
(11 hours ago)
45.61.162.170 - - [29/Aug/2026:05:48:54 +0000] "GET /.env HTTP/2.0" 403 1927 "-" "Mozilla/5.0 (Macin ...
show more
45.61.162.170 - - [29/Aug/2026:05:48:54 +0000] "GET /.env HTTP/2.0" 403 1927 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0"
...
show less
Brute-Force
Web App Attack
🇩🇪
BlueWire Hosting
2026-08-29 05:14:14
(11 hours ago)
High-confidence malicious configuration/VCS probe
Web App Attack
🇺🇸
TPI-Abuse
2026-08-29 05:12:00
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 45.61.162.170 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 45.61.162.170 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 01:11:52.156575 2026] [security2:error] [pid 32077:tid 32077] [client 45.61.162.170:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail-pmg.com"] [uri "/.env"] [unique_id "apJqGJJt4TUUkJcxt5DJuwAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
LRob
2026-08-29 05:07:58
(12 hours ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.env | 2026-08-29 05:07 UTC
show less
Hacking
Web App Attack