๐ณ๐ฑ
homeshowdomain.nl
2026-07-31 21:59:19
(3 hours ago)
Auto-ban: >3000 req/min op 2026-07-31
Web App Attack
SSH
Hacking
๐ง๐ช
cmbplf
2026-07-31 17:46:55
(7 hours ago)
450 requests with url.path *.env
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-07-31 17:26:31
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.199.182.104 (104.182.199.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 104.199.182.104 (104.182.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 13:26:28.594767 2026] [security2:error] [pid 705503:tid 705503] [client 104.199.182.104:40986] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cromaki.com"] [uri "/.env"] [unique_id "amzaxNDJJT4Uu9-GWLoVCAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-31 16:44:15
(8 hours ago)
104.199.182.104 - - [31/Jul/2026:18:44:14 +0200] "GET /.env HTTP/1.1" 301 169 "-" "crusader-worker/1 ...
show more
104.199.182.104 - - [31/Jul/2026:18:44:14 +0200] "GET /.env HTTP/1.1" 301 169 "-" "crusader-worker/1.0"
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-31 16:41:26
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.199.182.104 (104.182.199.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 104.199.182.104 (104.182.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 12:41:22.140601 2026] [security2:error] [pid 483815:tid 483815] [client 104.199.182.104:47630] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.test.cms2020.com"] [uri "/.env"] [unique_id "amzQMkpwzsfkuACnNf8yNAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
anon333
2026-07-31 16:06:04
(8 hours ago)
Invalid probes to web server T1206
Hacking
Exploited Host
๐บ๐ธ
TPI-Abuse
2026-07-31 15:31:26
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.199.182.104 (104.182.199.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 104.199.182.104 (104.182.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 11:31:22.642067 2026] [security2:error] [pid 3279637:tid 3279652] [client 104.199.182.104:36654] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "boatservicesgroup.com"] [uri "/.env"] [unique_id "amy_yl68PtKGktM0rV5ggAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-31 15:14:29
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.199.182.104 (104.182.199.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 104.199.182.104 (104.182.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 11:14:24.563829 2026] [security2:error] [pid 3502327:tid 3502327] [client 104.199.182.104:42962] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.sacoriverjazz.arsenaultartistmanagement.com"] [uri "/.env"] [unique_id "amy70H-6WqZvIqJnFYgafAAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-31 14:46:31
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.199.182.104 (104.182.199.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 104.199.182.104 (104.182.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 10:46:27.647825 2026] [security2:error] [pid 859564:tid 859564] [client 104.199.182.104:53670] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.asiancommoditiescorporation.com"] [uri "/.env"] [unique_id "amy1Q0HWhSSWRlAOveZP6gAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฏ๐ต
Valhalla
2026-07-31 14:44:05
(10 hours ago)
/.env
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-31 14:16:17
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.199.182.104 (104.182.199.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 104.199.182.104 (104.182.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 10:16:11.890283 2026] [security2:error] [pid 370974:tid 370974] [client 104.199.182.104:44736] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "templehistorical.org"] [uri "/.env"] [unique_id "amyuKxpYqC-NdlNzRilK7gAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
todix
2026-07-31 13:59:51
(11 hours ago)
Web App Attack Exploid from 104.199.182.104
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-31 13:52:37
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.199.182.104 (104.182.199.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 104.199.182.104 (104.182.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 09:52:30.515776 2026] [security2:error] [pid 7330:tid 7330] [client 104.199.182.104:44992] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ospreylake.org"] [uri "/.env"] [unique_id "amyonqFsJ3TM4WJWY3BvswAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
voormedia
2026-07-31 13:52:24
(11 hours ago)
Accessed trap at '/.env'
Web App Attack
Anonymous
2026-07-31 13:39:40
(11 hours ago)
[ns19.kdns.gr] httpd-config-scan: sites=www.example.com; logs=/var/log/httpd/access_log; samples=/.e ...
show more
[ns19.kdns.gr] httpd-config-scan: sites=www.example.com; logs=/var/log/httpd/access_log; samples=/.env
show less
Hacking
Web App Attack