๐ฎ๐ณ
evicky2002
2026-09-15 06:00:01
(1 day ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐ณ๐ฑ
homeshowdomain.nl
2026-09-14 21:59:23
(1 day ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-13.
show less
Web App Attack
SSH
Hacking
Anonymous
2026-09-14 16:33:24
(1 day ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
Anonymous
2026-09-14 13:45:09
(2 days ago)
Observed scanned 1 known-sensitive endpoint(s), e.g.: /.env
Bad Web Bot
Web App Attack
๐ฉ๐ช
Gwyneth Llewelyn
2026-09-14 10:58:30
(2 days ago)
72.9.243.164 - - [14/Sep/2026:11:58:28 +0100] "GET /.env HTTP/1.1" 301 162 "-" "Mozilla/5.0 (Macinto ...
show more
72.9.243.164 - - [14/Sep/2026:11:58:28 +0100] "GET /.env HTTP/1.1" 301 162 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0"
2026/09/14 11:58:28 [error] 2229833#2229833: *815230 access forbidden by rule, client: 72.9.243.164, server: getasecondlife.net, request: "GET /.env HTTP/1.1", host: "getasecondlife.net"
72.9.243.164 - - [14/Sep/2026:11:58:28 +0100] "GET /.env HTTP/1.1" 403 1178 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0"
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-14 10:24:40
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 72.9.243.164 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 72.9.243.164 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 06:24:36.995662 2026] [security2:error] [pid 17467:tid 17467] [client 72.9.243.164:42753] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "stbms.com"] [uri "/.env"] [unique_id "aqfLZC4EqVqBL-2COjVP6QAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-14 08:05:47
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 72.9.243.164 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 72.9.243.164 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 04:05:43.248806 2026] [security2:error] [pid 26776:tid 26865] [client 72.9.243.164:64653] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sunshinepumpers.com"] [uri "/.env"] [unique_id "aqeq19qafzVAVBum0EKcVAAAAMM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
interbiznw.com
2026-09-14 08:05:03
(2 days ago)
malicious-web-requests-vulnerability-scanning
Hacking
Brute-Force
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-14 07:15:17
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 72.9.243.164 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 72.9.243.164 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 03:15:11.930707 2026] [security2:error] [pid 18308:tid 18376] [client 72.9.243.164:45495] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "peluqueriabuhos.com"] [uri "/.env"] [unique_id "aqee_-sVSqA530F4nz1mOAAAAgY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-14 04:26:43
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 72.9.243.164 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 72.9.243.164 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 00:26:35.167032 2026] [security2:error] [pid 23498:tid 23498] [client 72.9.243.164:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "globetechsecurities.com"] [uri "/.env"] [unique_id "aqd3e0Ci8yqFqtRS8UrR7QAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Baking333
2026-09-14 04:21:22
(2 days ago)
[redacted] 72.9.243.164 - - [14/Sep/2026:05:07:08 +0100] "GET /.env HTTP/1.1" 302 6758 0/185659 "-" ...
show more
[redacted] 72.9.243.164 - - [14/Sep/2026:05:07:08 +0100] "GET /.env HTTP/1.1" 302 6758 0/185659 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0" [redacted] 72.9.243.164 - - [14/Sep/2026:05:21:21 +0100] "GET /.env HTTP/1.1" 302 6773 0/36819 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0"
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-14 04:20:34
(2 days ago)
[ti-24al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-24al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 72.9.243.164 - - [14/Sep/2026:06:20:34 +0200] "GET /.env HTTP/2.0" 403 138 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-14 03:48:20
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 72.9.243.164 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 72.9.243.164 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 23:48:14.202076 2026] [security2:error] [pid 9973:tid 9973] [client 72.9.243.164:56425] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sicktrax.com"] [uri "/.env"] [unique_id "aqdufl30wETe2k-Kp9_G9AAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2026-09-14 03:31:34
(2 days ago)
355 requests with url.path *.env
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-14 03:25:45
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 72.9.243.164 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 72.9.243.164 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 23:25:39.857534 2026] [security2:error] [pid 16322:tid 16322] [client 72.9.243.164:54051] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.vincetronics.com"] [uri "/google0e1ebbf943a1894d.html/.env"] [unique_id "aqdpMz_gr-52JcssbfOAwgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack