๐ฎ๐ฑ
spd.co.il
2026-09-14 15:02:15
(1 week ago)
Web application attack detected
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-13 11:49:51
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 64.225.98.245 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 64.225.98.245 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 07:49:43.813156 2026] [security2:error] [pid 8854:tid 8854] [client 64.225.98.245:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "swarnar.com"] [uri "/.env"] [unique_id "aqaN17-f-ztVQaTlN0e54AAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
swalluw
2026-09-13 10:36:35
(1 week ago)
Web vulnerability scanning: request for /.env (HTTP 404, GET) at 2026-09-13T10:36:35+00:00 - exploit ...
show more
Web vulnerability scanning: request for /.env (HTTP 404, GET) at 2026-09-13T10:36:35+00:00 - exploit probe, no legitimate use
show less
Bad Web Bot
Web App Attack
๐ซ๐ท
ecode hosting
2026-09-13 08:33:04
(1 week ago)
Domain : ecode.com.tr
Rule : env
2026-09-13 08:30:56 10.100.1.20 GET /.env - 443 - 162.158.19.179 HT ...
show more
Domain : ecode.com.tr
Rule : env
2026-09-13 08:30:56 10.100.1.20 GET /.env - 443 - 162.158.19.179 HTTP/2 python-requests/2.34.2 - ecode.com.tr 301 0 0 152 554 141 - 64.225.98.245
show less
Hacking
SQL Injection
๐ฎ๐ณ
evicky2002
2026-09-13 06:00:01
(1 week ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐จ๐ฟ
akac
2026-09-13 05:08:23
(1 week ago)
Web vulnerability scanning: HTTP/1.1 GET /.env
Hacking
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
jebla.ch
2026-09-13 04:33:31
(1 week ago)
Busted by the WatchPost edge sentinel: this host was probing web-app endpoints for a way in. Blocked ...
show more
Busted by the WatchPost edge sentinel: this host was probing web-app endpoints for a way in. Blocked at the edge, logged, and shared with the community. Last seen 2026-09-13 04:29 UTC.
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-13 03:56:18
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 64.225.98.245 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 64.225.98.245 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 23:56:10.326987 2026] [security2:error] [pid 3653:tid 3653] [client 64.225.98.245:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "perl-photo.com"] [uri "/.env"] [unique_id "aqYe2gea_l47k8zRlMzoBwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ท๐บ
DZBOT
2026-09-13 01:26:40
(1 week ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-12 23:18:59
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 64.225.98.245 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 64.225.98.245 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 19:18:51.260249 2026] [security2:error] [pid 18299:tid 18299] [client 64.225.98.245:64328] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rnance.com"] [uri "/.env"] [unique_id "aqXd23RQ4fPnJ7cuuowOngAAACQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
thieuleu
2026-09-12 22:34:29
(1 week ago)
Unauthorized connection attempt blocked by firewall policy. Web application hardening active.
Bad Web Bot
๐ฌ๐ง
Smish
2026-09-12 22:22:19
(1 week ago)
HONEYPOT HIT --> Fail2ban time=1789251738 log=2026-09-12T23:22:18+01:00 ip=64.225.98.245 host=as2106 ...
show more
HONEYPOT HIT --> Fail2ban time=1789251738 log=2026-09-12T23:22:18+01:00 ip=64.225.98.245 host=as210667.net method=GET uri="/.env" status=404 ua="python-requests/2.34.2" ref="-" rid=1775ceb005abf00e64d84c988184f695
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-12 19:50:28
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 64.225.98.245 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 64.225.98.245 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 15:50:20.622064 2026] [security2:error] [pid 25254:tid 25254] [client 64.225.98.245:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.wiszen.org"] [uri "/.env"] [unique_id "aqWs_KuVsszm100iJnVSlAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-12 19:46:08
(1 week ago)
64.225.98.245 - - [12/Sep/2026:21:46:08 +0200] "GET /.env HTTP/1.1" 301 169 "-" "python-requests/2.3 ...
show more
64.225.98.245 - - [12/Sep/2026:21:46:08 +0200] "GET /.env HTTP/1.1" 301 169 "-" "python-requests/2.34.2"
show less
Web App Attack
๐ฉ๐ช
Starburst SysOp Team
2026-09-12 16:49:16
(1 week ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-nue6-2)
Hacking
Web App Attack