π©πͺ
FeG Deutschland
2026-08-31 16:14:43
(39 minutes ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
π§πͺ
voormedia
2026-08-31 09:00:24
(7 hours ago)
Accessed trap at '/.env'
Web App Attack
Anonymous
2026-08-31 08:42:10
(8 hours ago)
102.209.31.156 - - [31/Aug/2026:08:42:09 +0000] "GET /.env HTTP/1.1" 404 45719 "-" "Mozilla/5.0 (Win ...
show more
102.209.31.156 - - [31/Aug/2026:08:42:09 +0000] "GET /.env HTTP/1.1" 404 45719 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
π΅π±
lns.bz
2026-08-31 08:05:04
(8 hours ago)
Web app attack [PL.Lu]
Exploited Host
Web App Attack
πΊπ¦
URAN Publishing Service
2026-08-31 06:19:27
(10 hours ago)
[31/Aug/2026:09:19:26 +0300] -- 102.209.31.156 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET ...
show more
[31/Aug/2026:09:19:26 +0300] -- 102.209.31.156 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET /.env HTTP/1.1
show less
Bad Web Bot
Web App Attack
πͺπΈ
el-brujo
2026-08-31 06:07:39
(10 hours ago)
31/Aug/2026:08:07:38.477115 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client ...
show more
31/Aug/2026:08:07:38.477115 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 102.209.31.156] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "125"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "parrot.elhacker.net"] [uri "/.env"] [unique_id "apUaKu446lHN1EXVbd-zdQAATjs"]
...
show less
Hacking
Web App Attack
π³π±
homeshowdomain.nl
2026-08-30 22:05:05
(18 hours ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-08-29.
show less
Web App Attack
SSH
Hacking
π©πͺ
www.Examensfragen.de
2026-08-30 21:06:24
(19 hours ago)
Web Spam
Bad Web Bot
πΊπΈ
etu brutus
2026-08-30 19:31:26
(21 hours ago)
102.209.31.156 Blocked by [Attack Vector List]
...
Hacking
Brute-Force
Exploited Host
πΏπ¦
conure.sh
2026-08-30 17:28:56
(23 hours ago)
csagent: score 20.5: secrets grab x2, 404 noise floor x2; 2 domain(s) in 0s
Web App Attack
πΊπΈ
RogueAutomata
2026-08-30 14:23:16
(1 day ago)
Detected malicious request: GET /.env
Detections triggered: Environment/config probe
Web App Attack
π©πͺ
FeG Deutschland
2026-08-30 13:21:13
(1 day ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-30 12:54:23
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 102.209.31.156 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 102.209.31.156 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 30 08:54:17.016469 2026] [security2:error] [pid 9599:tid 9599] [client 102.209.31.156:54970] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.register-yacht-delaware.com"] [uri "/.env"] [unique_id "apQn-UhGb1k8vMTw-GxqTgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-30 10:42:53
(1 day ago)
102.209.31.156 - - [30/Aug/2026:12:42:52 +0200] "GET /.env HTTP/2.0" 403 166 "-" "Mozilla/5.0 (Macin ...
show more
102.209.31.156 - - [30/Aug/2026:12:42:52 +0200] "GET /.env HTTP/2.0" 403 166 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36"
...
show less
Hacking
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-30 05:24:17
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 102.209.31.156 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 102.209.31.156 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 30 01:24:10.824243 2026] [security2:error] [pid 21626:tid 21626] [client 102.209.31.156:56233] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thevenicecafe.com"] [uri "/.env"] [unique_id "apO-emenMtummYAzuiydBAAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack