π¨π
Sophie Nina
2025-12-05 23:00:05
(10 months ago)
Automatically blocked by server
Fraud Orders
πͺπΈ
el-brujo
2025-12-05 21:14:00
(10 months ago)
Cloudflare WAF: Request Path: //.env Request Query: Host: www.elhacker.net userAgent: Go-http-clien ...
show more
Cloudflare WAF: Request Path: //.env Request Query: Host: www.elhacker.net userAgent: Go-http-client/1.1 Action: block Source: firewallManaged ASN Description: AS-COLOCROSSING Country: US Method: GET Timestamp: 2025-12-05T21:14:00Z ruleId: 23548ee2b36547a1be09bb2c0550c529. Report generated by Cloudflare-WAF-to-AbuseIPDB (https://github.com/MHG-LAB/Cloudflare-WAF-to-AbuseIPDB).
show less
Hacking
SQL Injection
Web App Attack
π©πͺ
kommunos
2025-12-05 19:47:01
(10 months ago)
/.env
Web App Attack
πΊπΈ
TPI-Abuse
2025-12-05 18:32:56
(10 months ago)
(mod_security) mod_security (id:210492) triggered by 107.172.44.155 (107-172-44-155-host.colocrossin ...
show more
(mod_security) mod_security (id:210492) triggered by 107.172.44.155 (107-172-44-155-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Dec 05 13:32:49.278773 2025] [security2:error] [pid 7979:tid 7979] [client 107.172.44.155:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "eddysgroup.com"] [uri "/.env"] [unique_id "aTMlUdTZBs7XGSHa-sgDzwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π±π»
garmtech.com
2025-12-05 18:16:28
(10 months ago)
Attempted access to sensitive endpoint (//.env) detected. Automated scan or unauthorized probing.
Web App Attack
πΊπΈ
TPI-Abuse
2025-12-05 17:52:55
(10 months ago)
(mod_security) mod_security (id:210492) triggered by 107.172.44.155 (107-172-44-155-host.colocrossin ...
show more
(mod_security) mod_security (id:210492) triggered by 107.172.44.155 (107-172-44-155-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Dec 05 12:52:47.238682 2025] [security2:error] [pid 6885:tid 6885] [client 107.172.44.155:49360] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.dismain.com"] [uri "/tienda/.env"] [unique_id "aTMb7y_yO6p5FIoSErlksQAAAC8"], referer: http://www.dismain.es//.env
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-12-05 12:22:39
(10 months ago)
(mod_security) mod_security (id:210492) triggered by 107.172.44.155 (107-172-44-155-host.colocrossin ...
show more
(mod_security) mod_security (id:210492) triggered by 107.172.44.155 (107-172-44-155-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Dec 05 07:22:36.699462 2025] [security2:error] [pid 22750:tid 22750] [client 107.172.44.155:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nyemdr-online.com"] [uri "/.env"] [unique_id "aTLOjMtRi9o2N9KC4eceZAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π·πΊ
DZBOT
2025-12-05 12:02:01
(10 months ago)
Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
πΊπΈ
dtorrer
2025-12-05 11:41:51
(10 months ago)
General vulnerability scan.
Port Scan
π§πͺ
cmbplf
2025-12-05 00:29:28
(10 months ago)
463 requests with url.path *.env
Brute-Force
Bad Web Bot
πΊπΈ
TPI-Abuse
2025-12-05 00:19:36
(10 months ago)
(mod_security) mod_security (id:210492) triggered by 107.172.44.155 (107-172-44-155-host.colocrossin ...
show more
(mod_security) mod_security (id:210492) triggered by 107.172.44.155 (107-172-44-155-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Dec 04 19:19:28.989875 2025] [security2:error] [pid 2075:tid 2075] [client 107.172.44.155:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pixacast.com"] [uri "/.env"] [unique_id "aTIlEN_V-2EC7SGPeywasQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¬π§
Swiptly
2025-12-04 23:36:44
(10 months ago)
Bot scanning for environment files .env .env/\*
...
Web App Attack
πΊπΈ
myagent.site
2025-12-04 23:33:24
(10 months ago)
Blocking for trying to access an exploit file: //.env
Hacking
π³π±
homeshowdomain.nl
2025-12-04 22:59:13
(10 months ago)
Auto-ban: >3000 req/min op 2025-12-04
Hacking
Web App Attack
SSH
πΊπΈ
TPI-Abuse
2025-12-04 22:37:17
(10 months ago)
(mod_security) mod_security (id:210492) triggered by 107.172.44.155 (107-172-44-155-host.colocrossin ...
show more
(mod_security) mod_security (id:210492) triggered by 107.172.44.155 (107-172-44-155-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Dec 04 17:37:10.047563 2025] [security2:error] [pid 10153:tid 10153] [client 107.172.44.155:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.sportsbookcommission.com"] [uri "/.env"] [unique_id "aTINFuUn3unz0stuVV8JagAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack