๐ฌ๐ท
mail.avx.gr
2026-08-21 17:37:06
(1 day ago)
Plesk Fail2Ban jail: Plesk-Web-Exploits. Evidence: 94.154.43.60 - - [18/Aug/2026:03:22:52 +0300] "GE ...
show more
Plesk Fail2Ban jail: Plesk-Web-Exploits. Evidence: 94.154.43.60 - - [18/Aug/2026:03:22:52 +0300] "GET /.env HTTP/1.1" 404 808 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Safari/537.36"
show less
Web App Attack
๐จ๐ฆ
csnavarro2020
2026-08-20 17:47:54
(2 days ago)
Automated scan for known vulnerable/nonexistent path: /.env
Web App Attack
Hacking
Anonymous
2026-08-20 17:19:53
(2 days ago)
(caddyscan) Scanner path probe from 94.154.43.60 (NL/The Netherlands/-): 5 in the last 3600 secs; Po ...
show more
(caddyscan) Scanner path probe from 94.154.43.60 (NL/The Netherlands/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 94.154.43.60 - - [20/Aug/2026:16:59:33 +0000] "GET /.env HTTP/1.1"
[REDACTED] 200 2627 94.154.43.60 - - [20/Aug/2026:16:59:53 +0000] "GET /.env HTTP/1.1"
[REDACTED] 200 2627 94.154.43.60 - - [20/Aug/2026:17:02:36 +0000] "GET /.env HTTP/1.1"
[REDACTED] 200 2627 94.154.43.60 - - [20/Aug/2026:17:11:26 +0000] "GET /.env HTTP/1.1"
[REDACTED] 200 2627 94.154.43.60 - - [20/Aug/2026:17:19:50 +0000] "GET /.env HTTP/1.1"
show less
Port Scan
๐ง๐ฌ
pa4080
2026-08-20 17:06:58
(2 days ago)
Detected by ModSecurity. Request URI: /.env
Web App Attack
๐ธ๐ฌ
Shubham Kumar
2026-08-20 16:57:24
(2 days ago)
Repeated scrape-guard abuse (flag #0)
Web App Attack
Anonymous
2026-08-20 15:59:31
(2 days ago)
(caddyscan) Scanner path probe from 94.154.43.60 (NL/The Netherlands/-): 5 in the last 3600 secs; Po ...
show more
(caddyscan) Scanner path probe from 94.154.43.60 (NL/The Netherlands/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 94.154.43.60 - - [20/Aug/2026:15:54:56 +0000] "GET /.env HTTP/1.1"
[REDACTED] 200 2627 94.154.43.60 - - [20/Aug/2026:15:55:16 +0000] "GET /.env HTTP/1.1"
[REDACTED] 200 2627 94.154.43.60 - - [20/Aug/2026:15:56:40 +0000] "GET /.env HTTP/1.1"
[REDACTED] 200 2627 94.154.43.60 - - [20/Aug/2026:15:58:36 +0000] "GET /.env HTTP/1.1"
[REDACTED] 200 2627 94.154.43.60 - - [20/Aug/2026:15:59:26 +0000] "GET /.env HTTP/1.1"
show less
Port Scan
Anonymous
2026-08-20 15:28:06
(2 days ago)
94.154.43.60 - - [20/Aug/2026:15:28:05 +0000] "GET /.env HTTP/1.1" 403 555 "-" "Mozilla/5.0 (Windows ...
show more
94.154.43.60 - - [20/Aug/2026:15:28:05 +0000] "GET /.env HTTP/1.1" 403 555 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Safari/537.36" "-" "newpage.schmittel-it.de"
...
show less
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-20 15:27:28
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 94.154.43.60 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 94.154.43.60 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 20 11:27:20.856864 2026] [security2:error] [pid 5880:tid 5880] [client 94.154.43.60:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.kidswithcamerasmovie.com"] [uri "/.env"] [unique_id "aocc2Jd77MZhtCzQN-41tgAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฏ๐ต
warudora
2026-08-20 15:25:01
(2 days ago)
Automated Honeypot Trap: Attempted to access sensitive path '/.env' on a Flask server.
Hacking
Web App Attack
๐ฉ๐ช
Michel Wijnberg
2026-08-20 15:12:09
(2 days ago)
94.154.43.60 - - [20/Aug/2026:15:12:08 +0000] "GET /.env HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Windows N ...
show more
94.154.43.60 - - [20/Aug/2026:15:12:08 +0000] "GET /.env HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
IVski
2026-08-20 14:57:35
(2 days ago)
IVski WAF | Sensitive file probe - looking for exposed .env
Hacking
Brute-Force
Web App Attack
Anonymous
2026-08-20 14:54:45
(2 days ago)
(caddyscan) Scanner path probe from 94.154.43.60 (NL/The Netherlands/-): 5 in the last 3600 secs; Po ...
show more
(caddyscan) Scanner path probe from 94.154.43.60 (NL/The Netherlands/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 94.154.43.60 - - [20/Aug/2026:13:54:59 +0000] "GET /.env HTTP/1.1"
[REDACTED] 200 2627 94.154.43.60 - - [20/Aug/2026:14:45:12 +0000] "GET /.env HTTP/1.1"
[REDACTED] 200 2627 94.154.43.60 - - [20/Aug/2026:14:45:17 +0000] "GET /.env HTTP/1.1"
[REDACTED] 200 2627 94.154.43.60 - - [20/Aug/2026:14:49:39 +0000] "GET /.env HTTP/1.1"
[REDACTED] 200 2627 94.154.43.60 - - [20/Aug/2026:14:54:43 +0000] "GET /.env HTTP/1.1"
show less
Port Scan
๐บ๐ธ
Aurealize
2026-08-20 14:07:48
(2 days ago)
Automated Sensitive File discovery attempt detected by a Cloudflare WAF custom rule. Path: /.env.
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-20 13:22:59
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 94.154.43.60 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 94.154.43.60 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 20 09:22:53.234718 2026] [security2:error] [pid 32506:tid 32506] [client 94.154.43.60:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.distro.media"] [uri "/.env"] [unique_id "aob_rUl4huuVvjUX6xWTUwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
mravb
2026-08-20 12:35:09
(2 days ago)
94.154.43.60 - - [20/Aug/2026:15:35:09 +0300] "GET /.env HTTP/1.1" 401 574 "-" "Mozilla/5.0 (Windows ...
show more
94.154.43.60 - - [20/Aug/2026:15:35:09 +0300] "GET /.env HTTP/1.1" 401 574 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Safari/537.36"
...
show less
Web App Attack
Hacking