๐ซ๐ท
mail.avx.gr
2026-08-05 20:51:47
(1 week ago)
Plesk Fail2Ban jail: Plesk-Web-Exploits. Evidence: 209.87.167.194 - - [02/Aug/2026:02:36:45 +0300] " ...
show more
Plesk Fail2Ban jail: Plesk-Web-Exploits. Evidence: 209.87.167.194 - - [02/Aug/2026:02:36:45 +0300] "GET /.env HTTP/1.1" 301 162 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:122.0) Gecko/20100101 Firefox/122.0"
show less
Web App Attack
๐ฎ๐ณ
evicky2002
2026-08-03 06:00:00
(1 week ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐ฌ๐ง
thetomtaylor.co.uk
2026-08-02 10:07:02
(1 week ago)
Fail2Ban - [NGINX]Malicious request blocked on nginx-444 ... [ice01,ice02,wa01,wa02]
Hacking
Bad Web Bot
๐บ๐ธ
Major Hostility
2026-08-02 08:43:55
(1 week ago)
"GET /.env HTTP/1.1" 404
"GET /.env.example HTTP/1.1" 404
"GET /.env.local HTTP/1.1" 404
Web App Attack
๐ฉ๐ช
LRob
2026-08-02 06:27:42
(1 week ago)
CrowdSec: crowdsecurity/http-sensitive-files | req: /.env.local | 5 distinct paths | UA: Mozilla/5.0 ...
show more
CrowdSec: crowdsecurity/http-sensitive-files | req: /.env.local | 5 distinct paths | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:122.0) Gecko/20100101 Firefox/122.0
show less
Hacking
๐ฉ๐ช
LRob
2026-08-02 05:05:29
(1 week ago)
CrowdSec: crowdsecurity/http-sensitive-files | req: /.env.local | 5 distinct paths | UA: Mozilla/5.0 ...
show more
CrowdSec: crowdsecurity/http-sensitive-files | req: /.env.local | 5 distinct paths | UA: Mozilla/5.0 (AppleWebKit/537.36; KHTML, like Gecko) Chrome/121.0.0.0 Safari/537.36
show less
Hacking
๐ฌ๐ง
PeravixGroup
2026-08-02 04:45:02
(1 week ago)
Imunify360 WAF block (graylisted)
Web App Attack
๐ซ๐ท
mail.avx.gr
2026-08-01 23:36:46
(1 week ago)
Plesk Fail2Ban jail: Plesk-Web-Exploits. Evidence: 209.87.167.194 - - [02/Aug/2026:02:36:45 +0300] " ...
show more
Plesk Fail2Ban jail: Plesk-Web-Exploits. Evidence: 209.87.167.194 - - [02/Aug/2026:02:36:45 +0300] "GET /.env HTTP/1.1" 301 162 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:122.0) Gecko/20100101 Firefox/122.0"
show less
Web App Attack
๐ฉ๐ช
gadix
2026-08-01 22:44:03
(1 week ago)
[02/Aug/2026:00:43:59.426942 +0200] am52rziXdjAhGYgzRdh9XQAAAI0 209.87.167.194 48828 127.0.0.1 7080
...
show more
[02/Aug/2026:00:43:59.426942 +0200] am52rziXdjAhGYgzRdh9XQAAAI0 209.87.167.194 48828 127.0.0.1 7080
[02/Aug/2026:00:44:00.665554 +0200] am52sDiXdjAhGYgzRdh9XgAAAIk 209.87.167.194 48836 127.0.0.1 7080
[02/Aug/2026:00:44:01.716668 +0200] am52sTiXdjAhGYgzRdh9XwAAAII 209.87.167.194 48844 127.0.0.1 7080
...
show less
Web App Attack
Anonymous
2026-08-01 21:40:03
(1 week ago)
suspicious request in access.log
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 21:31:37
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 209.87.167.194 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 209.87.167.194 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 17:31:29.171749 2026] [security2:error] [pid 2861233:tid 2861233] [client 209.87.167.194:55271] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "15cherryavenue.com"] [uri "/.env"] [unique_id "am5lsaGswtOoBrlHNw_ftQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
YF
2026-08-01 20:30:15
(1 week ago)
Environment file probe
Web App Attack
๐ซ๐ท
dynamix
2026-08-01 18:01:27
(1 week ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 17:48:35
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 209.87.167.194 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 209.87.167.194 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 13:48:31.942571 2026] [security2:error] [pid 2576825:tid 2576825] [client 209.87.167.194:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "barryherbach.com"] [uri "/.env"] [unique_id "am4xb7J1AISu6eu6042nyQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 16:56:51
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 209.87.167.194 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 209.87.167.194 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 12:56:47.442574 2026] [security2:error] [pid 1888232:tid 1888232] [client 209.87.167.194:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "antitribu.com"] [uri "/.env"] [unique_id "am4lTwJ9kOGVJaSUUNe2CgAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack