๐ฉ๐ช
hidemail.app
2026-08-24 14:22:16
(1 hour ago)
Automated scan for exposed config/secret files and known web exploits (e.g. /.env, RCE probes); auto ...
show more
Automated scan for exposed config/secret files and known web exploits (e.g. /.env, RCE probes); auto-banned by fail2ban.
show less
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-24 14:13:28
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 198.71.52.116 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 198.71.52.116 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 10:13:20.735240 2026] [security2:error] [pid 25759:tid 25759] [client 198.71.52.116:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mindmaterial.io"] [uri "/.env"] [unique_id "aoxRgFO3KWMT6mBjmZsRnQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
dtorrer
2026-08-24 05:07:00
(10 hours ago)
General vulnerability scan.
Port Scan
๐บ๐ธ
TPI-Abuse
2026-08-24 04:46:14
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 198.71.52.116 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 198.71.52.116 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 00:46:10.085059 2026] [security2:error] [pid 17877:tid 17877] [client 198.71.52.116:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "eddysgroup.com"] [uri "/.env"] [unique_id "aovMkvDSCOi-rr4HiH2xcAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
Rauno Asp
2026-08-24 04:43:35
(10 hours ago)
Automated .env credentials scanning attempt detected by honeypot on elbasanapartments.al
Web App Attack
Anonymous
2026-08-24 04:26:49
(11 hours ago)
http scanning for .env files
...
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-24 04:03:29
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 198.71.52.116 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 198.71.52.116 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 00:03:25.132998 2026] [security2:error] [pid 15615:tid 15615] [client 198.71.52.116:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "atlascoombs.com"] [uri "/.env"] [unique_id "aovCjV7MW2iHE28LafTtogAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
Anytech
2026-08-24 03:01:31
(12 hours ago)
Blocked by Conn-Monitor: http-bad-user-agent
Web App Attack
Bad Web Bot
๐ช๐ธ
el-brujo
2026-08-24 02:55:12
(12 hours ago)
24/Aug/2026:04:55:11.907842 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client ...
show more
24/Aug/2026:04:55:11.907842 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 198.71.52.116] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "125"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "hostench.eu"] [uri "/.env"] [unique_id "aouyjwWK73UB_acpfMjY8gABJm0"]
...
show less
Hacking
Web App Attack
๐ฉ๐ช
tall1oN
2026-08-23 18:35:01
(20 hours ago)
198.71.52.116 - - [23/Aug/2026:20:33:14 +0200] "GET /.env HTTP/1.1" 200 303104 "-" "python-requests/ ...
show more
198.71.52.116 - - [23/Aug/2026:20:33:14 +0200] "GET /.env HTTP/1.1" 200 303104 "-" "python-requests/2.32.4" "plutoz.de"
198.71.52.116 - - [23/Aug/2026:20:35:00 +0200] "GET /.env HTTP/1.1" 200 110592 "-" "python-requests/2.32.4" "plutoz.de"
...
show less
Web App Attack
Port Scan
Hacking
Anonymous
2026-08-23 15:53:02
(23 hours ago)
Bot / scanning and/or hacking attempts: GET /.env HTTP/1.1
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-23 14:18:48
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 198.71.52.116 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 198.71.52.116 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 10:18:42.699200 2026] [security2:error] [pid 14783:tid 14783] [client 198.71.52.116:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "betiqos.com"] [uri "/.env"] [unique_id "aosBQkMEck70YFpItyM33AAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
000rosiu
2026-08-23 09:22:30
(1 day ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action: BLOCK | Protocol: HTTP/1.1 (GET) | Endpoi ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action: BLOCK | Protocol: HTTP/1.1 (GET) | Endpoint: /.env | UA: python-requests/2.32.4 โข Generated by: github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ซ๐ฎ
iamxorum
2026-08-23 07:42:41
(1 day ago)
CrowdSec: custom/insta-ban-probes
Port Scan
Anonymous
2026-08-23 07:34:05
(1 day ago)
198.71.52.116 - - [23/Aug/2026:15:34:05 +0800] "GET /.env HTTP/1.1" 301 239 "-" "python-requests/2.3 ...
show more
198.71.52.116 - - [23/Aug/2026:15:34:05 +0800] "GET /.env HTTP/1.1" 301 239 "-" "python-requests/2.32.4"
...
show less
Bad Web Bot
Web App Attack