๐ซ๐ฎ
inlink.ltd
2026-07-29 10:02:34
(12 minutes ago)
dot file probe
Web App Attack
๐ฑ๐ป
garmtech.com
2026-07-29 10:01:03
(14 minutes ago)
IM360 WAF: Direct access to sensitive file or dotfile MV:/.env.production
Web App Attack
๐ซ๐ท
Baking333
2026-07-29 09:59:59
(15 minutes ago)
[redacted] 104.28.240.187 - - [29/Jul/2026:10:59:56 +0100] "HEAD /.[redacted] HTTP/2.0" 301 197 "htt ...
show more
[redacted] 104.28.240.187 - - [29/Jul/2026:10:59:56 +0100] "HEAD /.[redacted] HTTP/2.0" 301 197 "https://[redacted]/.[redacted]" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://[redacted]/[redacted])" [redacted] 104.28.240.187 - - [29/Jul/2026:10:59:56 +0100] "HEAD /.[redacted] HTTP/2.0" 301 145 "https://[redacted]/.[redacted]" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ChatGPT-User/1.0; +https://[redacted]/bot)"
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-29 08:58:45
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 104.28.240.187 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.28.240.187 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 29 04:58:34.513472 2026] [security2:error] [pid 3139092:tid 3139092] [client 104.28.240.187:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "carolinapetportraits.com"] [uri "/.env.old"] [unique_id "amnAuvPG2_QzxCfOfRElMwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-07-29 08:48:47
(1 hour ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 12
Exploited Host
Web App Attack
๐ฟ๐ฆ
conure
2026-07-29 07:56:44
(2 hours ago)
csagent: score 20.0: secrets grab x2; 1 domain(s) in 0s
Web App Attack
Anonymous
2026-07-29 07:53:14
(2 hours ago)
Automated Apache suspicious-path probe detected in last 1m: hits=25; wp-login_hits=0; uniq_paths=13
Web App Attack
Anonymous
2026-07-29 07:53:01
(2 hours ago)
Malicious activity detected
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-29 07:32:55
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.28.240.187 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.28.240.187 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 29 03:32:44.014168 2026] [security2:error] [pid 1225:tid 1225] [client 104.28.240.187:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bridgital.com"] [uri "/.env.save"] [unique_id "ammsnBHvdWCytxhGUjpp3gAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-07-29 07:16:01
(2 hours ago)
Try to access /.git/HEAD
Web App Attack
๐ต๐ฑ
Budyn
2026-07-29 07:06:41
(3 hours ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: URI: /.env.save | UA: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ChatGPT-User/1.0; +https://openai.com/bot) | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
Anonymous
2026-07-29 07:00:00
(3 hours ago)
Automated Apache web application probing in selected 24h window; attempts=398, unique_paths=14, erro ...
show more
Automated Apache web application probing in selected 24h window; attempts=398, unique_paths=14, error_responses=356; targets include WordPress, .env/.git, phpMyAdmin, autodiscover, wpad.dat and related probe paths.
show less
Web App Attack
Anonymous
2026-07-29 07:00:00
(3 hours ago)
Apache probe; attempts=427; exact paths: /.env | /.env.backup | /.env.bak | /.env.development.local ...
show more
Apache probe; attempts=427; exact paths: /.env | /.env.backup | /.env.bak | /.env.development.local | /.env.dist | /.env.local | /.env.old | /.env.production | /.env.production.local | /.env.sample | /.env.save | /.env.test | /.git/HEAD | /.git/config
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-29 06:23:23
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.28.240.187 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.28.240.187 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 29 02:23:08.295288 2026] [security2:error] [pid 2482055:tid 2482072] [client 104.28.240.187:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "casademontemaior.com"] [uri "/.env.bak"] [unique_id "ammcTCskvRzE7VoNNCsBiwAAAQ8"], referer: https://www.google.com/search?q=casademontemaior.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
maxpower
2026-07-29 06:11:36
(4 hours ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 104.28.240.187 (US/United States/-): 1 i ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 104.28.240.187 (US/United States/-): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 104.28.240.187 - - [29/Jul/2026:08:11:35 +0200] "GET /.aws/credentials HTTP/2.0" 500 726 "https://www.google.com/search?q=svm-srl.it" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/135.0.0.0 Safari/537.36" "104.28.240.187" host=svm-srl.it
show less
Port Scan