๐ฏ๐ต
VXG-NET
2026-09-19 12:27:41
(4 hours ago)
port=80, indicator_type=info-leak
Hacking
๐บ๐ธ
Rip
2026-09-19 10:27:06
(6 hours ago)
Restricted File Access Attempts
Port Scan
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-19 09:35:06
(7 hours ago)
[ti-01ov] Web exploit scanning: 1 suspicious requests detected by fail2ban jail <name>. Example: 79. ...
show more
[ti-01ov] Web exploit scanning: 1 suspicious requests detected by fail2ban jail <name>. Example: 79.108.166.138 - - \[19/Sep/2026:11:34:59 +0200\] "GET /.env HTTP/1.1" 301 570 "-" "Mozilla/5.0 \(Linux\; U\; Android 4.4.2\; en-US\; HM NOTE 1W Build/KOT49H\) AppleWebKit/534.30 \(KHTML, like Gecko\) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30"
...
show less
Bad Web Bot
Web App Attack
Anonymous
2026-09-19 08:49:03
(8 hours ago)
Bot / scanning and/or hacking attempts: GET /.env HTTP/1.1, POST / HTTP/1.1, GET / HTTP/1.1
Hacking
Web App Attack
๐บ๐ธ
SX Communications
2026-09-19 08:46:43
(8 hours ago)
Blocked abusive HTTP application-layer DoS / botnet traffic from 79.108.166.138: traffic from this a ...
show more
Blocked abusive HTTP application-layer DoS / botnet traffic from 79.108.166.138: traffic from this address continues high-cost dynamic page and feed requests at abusive rates via TCP/HTTPS despite edge block responses. Likely compromised end-user host.
show less
DDoS Attack
Bad Web Bot
Exploited Host
๐จ๐ญ
SOC [GOLINE SA]
2026-09-19 07:51:27
(9 hours ago)
FortiGate IPS: AndroxGh0st.Malware (severity high)
Hacking
๐ฉ๐ช
Lino Project
2026-09-19 07:21:02
(9 hours ago)
79.108.166.138 - - [19/Sep/2026:09:20:59 +0200] "GET /.env HTTP/1.1" 301 780 "-" "Mozilla/5.0 (Linux ...
show more
79.108.166.138 - - [19/Sep/2026:09:20:59 +0200] "GET /.env HTTP/1.1" 301 780 "-" "Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
voormedia
2026-09-19 06:52:13
(10 hours ago)
Accessed trap at '/.env'
Web App Attack
๐บ๐ธ
Lee Daniel
2026-09-19 06:29:42
(10 hours ago)
79.108.166.138 - - [19/Sep/2026:02:29:42 -0400] "GET /.env HTTP/1.1" 403 6257 "-" "Mozilla/5.0 (Linu ...
show more
79.108.166.138 - - [19/Sep/2026:02:29:42 -0400] "GET /.env HTTP/1.1" 403 6257 "-" "Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30"
...
show less
DDoS Attack
Web Spam
Email Spam
Port Scan
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-19 05:49:14
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 79.108.166.138 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 79.108.166.138 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 01:49:10.604017 2026] [security2:error] [pid 5120:tid 5151] [client 79.108.166.138:63282] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "adultbaja.com"] [uri "/.env"] [unique_id "aq4iVmcp1XZUy1JYzBSsywAAAMI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-19 05:12:32
(11 hours ago)
[cb-07al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[cb-07al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 79.108.166.138 - - [19/Sep/2026:07:12:20 +0200] "GET /.env HTTP/1.1" 301 489 "-" "Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-19 05:03:30
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 79.108.166.138 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 79.108.166.138 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 01:03:26.695137 2026] [security2:error] [pid 6466:tid 6466] [client 79.108.166.138:57096] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thebrotherhoodlounge.com"] [uri "/.env"] [unique_id "aq4Xnm0TFgyUouDAJAi9hwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-09-19 04:01:10
(12 hours ago)
[19/Sep/2026:07:01:09 +0300] -- 79.108.166.138 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET ...
show more
[19/Sep/2026:07:01:09 +0300] -- 79.108.166.138 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET /.env HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
nyt
2026-09-19 00:21:10
(16 hours ago)
Sensitive File Probe, Attempt to access sensitive .env file
Web App Attack
๐ฆ๐บ
afleventoffice.com.au
2026-09-18 23:21:31
(17 hours ago)
GET /.env HTTP/1.1
Web App Attack