Anonymous
2026-08-23 19:49:40
(23 hours ago)
$f2bV_matches
Brute-Force
๐ฌ๐ง
thetomtaylor.co.uk
2026-08-22 22:07:01
(1 day ago)
Fail2Ban - [WEB]Custom exploit pattern detected on customexploits ... [ice01,ice02,wa01,wa02]
Hacking
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
hidemail.app
2026-08-22 20:50:14
(1 day ago)
Automated scan for exposed config/secret files and known web exploits (e.g. /.env, RCE probes); auto ...
show more
Automated scan for exposed config/secret files and known web exploits (e.g. /.env, RCE probes); auto-banned by fail2ban.
show less
Web App Attack
Hacking
๐บ๐ธ
interbiznw.com
2026-08-22 20:41:37
(1 day ago)
malicious-web-requests-vulnerability-scanning
Hacking
Brute-Force
Exploited Host
Web App Attack
๐ฎ๐ฉ
origrata
2026-08-22 20:25:33
(1 day ago)
[OGWAF] path_traversal attack blocked | severity: high | GET /.env | UA: Mozilla/5.0 (Macintosh; Int ...
show more
[OGWAF] path_traversal attack blocked | severity: high | GET /.env | UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0
show less
Hacking
Web App Attack
๐ซ๐ท
Baking333
2026-08-22 20:04:54
(1 day ago)
[redacted] 85.121.244.25 - - [22/Aug/2026:21:04:51 +0100] "GET /.env HTTP/2.0" 301 291 "-" "Mozilla/ ...
show more
[redacted] 85.121.244.25 - - [22/Aug/2026:21:04:51 +0100] "GET /.env HTTP/2.0" 301 291 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0" [redacted] 85.121.244.25 - - [22/Aug/2026:21:04:52 +0100] "GET /fr/.env/ HTTP/2.0" 404 34477 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0"
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-22 19:41:34
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 85.121.244.25 (mail.xcetrux.ru): 1 in the last ...
show more
(mod_security) mod_security (id:210492) triggered by 85.121.244.25 (mail.xcetrux.ru): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 15:41:27.459091 2026] [security2:error] [pid 29692:tid 29692] [client 85.121.244.25:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pixacast.com"] [uri "/.env"] [unique_id "aon7ZzIcSLKb-oA7hckGtQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
MyGlobalFlowers
2026-08-22 19:10:44
(2 days ago)
Multiple WAF Violations
Web App Attack
๐ฉ๐ช
BlueWire Hosting
2026-08-22 18:35:26
(2 days ago)
High-confidence malicious configuration/VCS probe
Web App Attack
๐บ๐ธ
Alvino
2026-08-22 18:33:38
(2 days ago)
Blocked due to using a VPN or data center IP with abuse: 75
Web Spam
VPN IP
๐บ๐ธ
TPI-Abuse
2026-08-22 18:13:48
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 85.121.244.25 (mail.xcetrux.ru): 1 in the last ...
show more
(mod_security) mod_security (id:210492) triggered by 85.121.244.25 (mail.xcetrux.ru): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 14:13:42.827388 2026] [security2:error] [pid 8317:tid 8317] [client 85.121.244.25:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "swarnar.com"] [uri "/.env"] [unique_id "aonm1jXDEkLRCpFT1pBAyAAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-21 05:44:40
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 85.121.244.25 (mail.xcetrux.ru): 1 in the last ...
show more
(mod_security) mod_security (id:210492) triggered by 85.121.244.25 (mail.xcetrux.ru): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 01:44:33.572948 2026] [security2:error] [pid 11304:tid 11304] [client 85.121.244.25:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "email.thectegroup.net"] [uri "/.env"] [unique_id "aoflwZFI7yE9IIzHZLREKgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-21 05:23:14
(3 days ago)
$f2bV_matches
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-08-20 00:24:51
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 85.121.244.25 (mail.xcetrux.ru): 1 in the last ...
show more
(mod_security) mod_security (id:210492) triggered by 85.121.244.25 (mail.xcetrux.ru): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 19 20:24:46.944006 2026] [security2:error] [pid 7937:tid 7937] [client 85.121.244.25:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kidswithcamerasmovie.com"] [uri "/.env"] [unique_id "aoZJTn2l2YpoJ-w_m2BligAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Starburst SysOp Team
2026-08-19 23:55:06
(4 days ago)
(mod_security-custom) mod_security (id:210492) triggered by 85.121.244.25 (IT/Italy/Lombardy/Milan/m ...
show more
(mod_security-custom) mod_security (id:210492) triggered by 85.121.244.25 (IT/Italy/Lombardy/Milan/mail.xcetrux.ru/[AS9009 M247]): 1 in the last 3600 secs (0-srv1)
show less
Hacking