Anonymous
2026-07-01 04:38:02
(3 weeks ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
๐ฆ๐บ
screwlooseit.com.au
2026-06-16 10:35:34
(1 month ago)
Blocked by CSF 13 firewall - Rule: config-dotfile
US/United States/bureaucrats-jink.vpsrdns.web-host ...
show more
Blocked by CSF 13 firewall - Rule: config-dotfile
US/United States/bureaucrats-jink.vpsrdns.web-hosting.com
show less
Web App Attack
๐ซ๐ท
โจ
2026-06-16 03:17:09
(1 month ago)
Domain : solobreaks.co.uk
Rule : env
2026-06-16 03:15:13 ***hidden-privacy*** GET /.env - 443 - 159. ...
show more
Domain : solobreaks.co.uk
Rule : env
2026-06-16 03:15:13 ***hidden-privacy*** GET /.env - 443 - 159.198.40.216 HTTP/1.1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/138.0.0.0 Safari/537.36 Edg/138.0.0.0 https://www.solobreaks.co.uk/.env solobreaks.co.uk 404 0 0 51937 252 611 - -
show less
Hacking
SQL Injection
๐ช๐ธ
el-brujo
2026-06-16 02:53:47
(1 month ago)
Cloudflare WAF: Request Path: /.env Request Query: Host: www.elhacker.net userAgent: Mozilla/5.0 (W ...
show more
Cloudflare WAF: Request Path: /.env Request Query: Host: www.elhacker.net userAgent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/138.0.0.0 Safari/537.36 Edg/138.0.0.0 Action: block Source: firewallManaged ASN Description: Namecheap, Inc. Country: US Method: GET Timestamp: 2026-06-16T02:53:47Z ruleId: 23548ee2b36547a1be09bb2c0550c529. Report generated by Cloudflare-WAF-to-AbuseIPDB (https://github.com/MHG-LAB/Cloudflare-WAF-to-AbuseIPDB).
show less
Hacking
SQL Injection
Web App Attack
๐บ๐ธ
kosada.com
2026-06-15 20:42:10
(1 month ago)
Web vulnerability probing: /.env
Web App Attack
๐ง๐ช
voormedia
2026-06-15 18:50:27
(1 month ago)
Accessed trap at '/.env'
Web App Attack
๐บ๐ธ
conrad10781
2026-06-15 17:04:36
(1 month ago)
nginx-dot-env
Web App Attack
๐ฌ๐ง
openstrike.co.uk
2026-06-15 05:13:59
(1 month ago)
3 attacks on env grabbing URLs:
GET /.env HTTP/1.1
Hacking
๐ฉ๐ช
MusicLibrary
2026-06-14 15:31:43
(1 month ago)
Attempted access to sensitive configuration files (.env, .git, etc.)
Bad Web Bot
Web App Attack
๐ฌ๐ง
Aetherweb Ark
2026-06-14 14:56:33
(1 month ago)
(mod_security) mod_security (id:949110) triggered by 159.198.40.216 (US/United States/bureaucrats-ji ...
show more
(mod_security) mod_security (id:949110) triggered by 159.198.40.216 (US/United States/bureaucrats-jink.vpsrdns.web-hosting.com): N in the last X secs
show less
Web App Attack
๐ฉ๐ช
www.Examensfragen.de
2026-06-14 14:16:07
(1 month ago)
Web Spam
Bad Web Bot
Anonymous
2026-06-14 13:53:59
(1 month ago)
Web App Attack
๐ฆ๐บ
paulshipley.com.au
2026-06-14 11:47:31
(1 month ago)
[Sun Jun 14 21:47:30.627149 2026] [security2:error] [pid 911792] [client 159.198.40.216:49352] [clie ...
show more
[Sun Jun 14 21:47:30.627149 2026] [security2:error] [pid 911792] [client 159.198.40.216:49352] [client 159.198.40.216] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "rjryanpartners.com.au"] [uri "/.env"] [unique_id "ai6U0qoS_fBkLBCz5rV2AgAAAAM"], referer: https://www.rjryanpartners.com.au/.env
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-14 11:35:15
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 159.198.40.216 (bureaucrats-jink.vpsrdns.web-ho ...
show more
(mod_security) mod_security (id:210492) triggered by 159.198.40.216 (bureaucrats-jink.vpsrdns.web-hosting.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 07:35:08.696018 2026] [security2:error] [pid 14317:tid 14317] [client 159.198.40.216:56202] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.rentaroller.com.au"] [uri "/.env"] [unique_id "ai6R7FtwhFAYFDN1zHhIrAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
todix
2026-06-14 10:24:38
(1 month ago)
Web App Attack Exploid from 159.198.40.216
Web App Attack