π«π·
SpaceHost-Server
2026-05-22 22:33:39
(1 week ago)
Brute-Force
Web App Attack
π«π·
SpaceHost-Server
2026-05-21 22:32:29
(2 weeks ago)
Brute-Force
Web App Attack
π³π±
homeshowdomain.nl
2026-05-21 21:59:57
(2 weeks ago)
Auto-ban: >3000 req/min op 2026-05-21
Web App Attack
SSH
Hacking
Anonymous
2026-05-21 19:49:59
(2 weeks ago)
Aggressive web scan
Web App Attack
π©πͺ
macrob
2026-05-21 12:20:57
(2 weeks ago)
2026/05/21 12:20:54 [error] 3028040#3028040: *245409447 access forbidden by rule, client: 91.239.78. ...
show more
2026/05/21 12:20:54 [error] 3028040#3028040: *245409447 access forbidden by rule, client: 91.239.78.115, server: binixo.com.ar, request: "GET /.env HTTP/2.0", host: "binixo.com.ar"
2026/05/21 12:20:54 [error] 3028040#3028040: *245409448 access forbidden by rule, client: 91.239.78.115, server: binixo.com.ar, request: "GET /.env.local HTTP/2.0", host: "binixo.com.ar"
2026/05/21 12:20:54 [error] 3028040#3028040: *245409436 access forbidden by rule, client: 91.239.78.115, server: binixo.com.ar, request: "GET /.env.production HTTP/2.0", host: "binixo.com.ar"
...
show less
Web App Attack
π©πͺ
grassau.com
2026-05-21 10:56:06
(2 weeks ago)
(mod_security) mod_security triggered on hostname [redacted] 91.239.78.115 (UA/Ukraine/Kyiv City/Kyi ...
show more
(mod_security) mod_security triggered on hostname [redacted] 91.239.78.115 (UA/Ukraine/Kyiv City/Kyiv/dedicated.vsys.host)
show less
SQL Injection
πΊπΈ
TPI-Abuse
2026-05-21 08:35:09
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 91.239.78.115 (dedicated.vsys.host): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 91.239.78.115 (dedicated.vsys.host): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 21 04:34:56.836632 2026] [security2:error] [pid 28404:tid 28404] [client 91.239.78.115:56851] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "belgiophar.org"] [uri "/.env"] [unique_id "ag7DsHBpzEJMVAiW99BkggAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¦πΊ
Anytech
2026-05-21 06:03:54
(2 weeks ago)
Blocked by Conn-Monitor: Web scanning activity
Hacking
Web App Attack
π«π·
dynamix
2026-05-21 05:30:00
(2 weeks ago)
Multiple WAF Violations
Web App Attack
π«π·
masterguru
2026-05-21 05:21:39
(2 weeks ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-195)
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-05-21 04:26:01
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 91.239.78.115 (dedicated.vsys.host): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 91.239.78.115 (dedicated.vsys.host): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 21 00:25:55.129532 2026] [security2:error] [pid 8634:tid 8634] [client 91.239.78.115:44821] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bacpool.com"] [uri "/.env"] [unique_id "ag6JUwMGgg19XnJN8Cl43gAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π§πͺ
cmbplf
2026-05-21 03:28:46
(2 weeks ago)
199 requests with url.path *.env
Brute-Force
Bad Web Bot
π³π±
homeshowdomain.nl
2026-05-20 22:04:05
(2 weeks ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-05-19.
show less
Web App Attack
SSH
Hacking
π©πͺ
Blexyel
2026-05-20 17:11:33
(2 weeks ago)
91.239.78.115 - - [20/May/2026:19:11:28 +0200] "GET /.git/config HTTP/1.1" 200 2116 "-" "Mozilla/5.0 ...
show more
91.239.78.115 - - [20/May/2026:19:11:28 +0200] "GET /.git/config HTTP/1.1" 200 2116 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"
...
show less
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-05-20 15:42:20
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 91.239.78.115 (dedicated.vsys.host): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 91.239.78.115 (dedicated.vsys.host): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 20 11:42:15.937872 2026] [security2:error] [pid 1511:tid 1511] [client 91.239.78.115:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.forsaleincr.com"] [uri "/.env"] [unique_id "ag3WV0H2qimOWR0CY3gCpAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack