Anonymous
2026-09-15 06:40:34
(9 hours ago)
"GET /.env HTTP/1.1"
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-15 03:39:29
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 64.113.5.165 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 64.113.5.165 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 23:39:26.517508 2026] [security2:error] [pid 25993:tid 26154] [client 64.113.5.165:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mindgardens.com"] [uri "/.env"] [unique_id "aqi97lDYCNBNph-TfiUYmAAAAZY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-15 03:38:06
(12 hours ago)
Malicious activity detected by fail2ban (jail=honeypot)
Hacking
Web App Attack
🇺🇸
wbsouza
2026-09-15 03:25:54
(12 hours ago)
CrowdSec: infra/bad-path-probe — automated firewall drops on self-hosted IDS sensor
Hacking
🇨🇭
YF
2026-09-15 03:00:44
(12 hours ago)
Distributed subnet attack — coordinated scanning from multiple IPs in the same /24
DDoS Attack
Web App Attack
🇺🇸
Victor López
2026-09-15 02:41:20
(13 hours ago)
desdeotramirada.com 64.113.5.165 - - [14/Sep/2026:21:40:08 -0500] "GET /.env HTTP/1.1" 404 5421 "-" ...
show more
desdeotramirada.com 64.113.5.165 - - [14/Sep/2026:21:40:08 -0500] "GET /.env HTTP/1.1" 404 5421 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0" -
empresarioexpress.com 64.113.5.165 - - [14/Sep/2026:21:40:33 -0500] "GET /.env HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0" -
valquintero.com.co 64.113.5.165 - - [14/Sep/2026:21:41:19 -0500] "GET /.env HTTP/1.1" 404 6203 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0" -
...
show less
Hacking
Web App Attack
Anonymous
2026-09-15 02:05:03
(13 hours ago)
suspicious request in access.log
Web App Attack
🇳🇱
Alt255
2026-09-15 01:51:21
(14 hours ago)
[ti-11al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-11al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 64.113.5.165 - - [15/Sep/2026:03:51:21 +0200] "GET /.env HTTP/1.1" 301 491 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0"
...
show less
Bad Web Bot
Web App Attack
Anonymous
2026-09-15 01:46:37
(14 hours ago)
fail2ban: apache-secrets-scan jail (1 hits in 2419200s) on skipper
Web App Attack
Hacking
🇺🇸
Mundo Bueno
2026-09-15 01:29:51
(14 hours ago)
[ISILIA Protection v2.1] Tentative d'accès: /.env | Pays: US | UA: Mozilla/5.0 (Macintosh; Intel Mac ...
show more
[ISILIA Protection v2.1] Tentative d'accès: /.env | Pays: US | UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0
show less
Hacking
Web App Attack
🇩🇪
big-cloud.nl
2026-09-15 01:28:51
(14 hours ago)
Try to access /.env
Web App Attack
🇺🇸
TPI-Abuse
2026-09-15 01:15:05
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 64.113.5.165 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 64.113.5.165 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 21:15:00.811395 2026] [security2:error] [pid 11140:tid 11140] [client 64.113.5.165:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "uwsvita.org"] [uri "/.env"] [unique_id "aqicFAQKBhY88gN5HrP7fQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
tr1n
2026-09-15 00:58:30
(14 hours ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action: MANAGED_CHALLENGE | ASN: 212238 (Datacamp ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action: MANAGED_CHALLENGE | ASN: 212238 (Datacamp Limited) | Protocol: HTTP/1.1 (GET) | Endpoint: /.env | Timestamp: 2026-09-15T00:58:30Z | UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0
show less
Bad Web Bot
🇺🇸
its101
2026-09-15 00:50:07
(15 hours ago)
Automated detection by LockdownAccess security system. Attack type(s): env_grab. Reason: Nginx: env_ ...
show more
Automated detection by LockdownAccess security system. Attack type(s): env_grab. Reason: Nginx: env_grab attack. Path targeted: unknown. Blocked in Cloudflare.
show less
Web App Attack
🇩🇪
lolyay
2026-09-15 00:46:06
(15 hours ago)
64.113.5.165 - - [15/Sep/2026:00:46:01 +0000] "GET /.env HTTP/1.1" 200 4 "-" "Mozilla/5.0 (Macintosh ...
show more
64.113.5.165 - - [15/Sep/2026:00:46:01 +0000] "GET /.env HTTP/1.1" 200 4 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0"
64.113.5.165 - - [15/Sep/2026:00:46:04 +0000] "GET /.env HTTP/1.1" 200 4 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0"
...
show less
Web App Attack
Bad Web Bot