🇫🇷
Octopuce
2026-09-04 03:39:48
(4 hours ago)
Aggressive web search of vulnerable pages: /phpinfo.php /info.php /frontend/.env /server/.env /wp-co ...
show more
Aggressive web search of vulnerable pages: /phpinfo.php /info.php /frontend/.env /server/.env /wp-content/.env /admin/.env ...
show less
Web App Attack
🇬🇧
blik2108
2026-09-03 21:23:02
(10 hours ago)
119.235.214.121 - - [03/Sep/2026:21:22:42 +0000] "GET /phpinfo.php HTTP/1.1" 301 169 "-" "Mozilla/5. ...
show more
119.235.214.121 - - [03/Sep/2026:21:22:42 +0000] "GET /phpinfo.php HTTP/1.1" 301 169 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0 Safari/537.36" "-"
119.235.214.121 - - [03/Sep/2026:21:22:42 +0000] "GET /phpinfo HTTP/1.1" 404 3431 "http://solentyachtcharter.com/phpinfo" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0 Safari/537.36" "-"
119.235.214.121 - - [03/Sep/2026:21:22:44 +0000] "GET /phpinfo.php HTTP/1.1" 404 3431 "http://solentyachtcharter.com/phpinfo.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0 Safari/537.36" "-"
119.235.214.121 - - [03/Sep/2026:21:22:51 +0000] "GET /.env HTTP/1.1" 301 169 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0 Safari/537.36" "-"
119.235.214.121 - - [03/Sep/2026:21:22:51 +0000] "GET /.env.development HTTP/1.1" 404 3431 "http://solentyachtcharter.com
...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-03 21:10:13
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 119.235.214.121 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 119.235.214.121 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 17:09:56.650139 2026] [security2:error] [pid 15838:tid 15838] [client 119.235.214.121:34775] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "eventsetcinc.com"] [uri "/api/.env"] [unique_id "apniJN3qsz1RGpRb2qIlGQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇿🇦
conure.sh
2026-09-03 12:11:18
(20 hours ago)
csagent: score 20.0: secrets grab x2; 1 domain(s) in 0s
Web App Attack
🇳🇱
e.fierstra
2026-09-02 13:48:44
(1 day ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-02 13:46:01
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 119.235.214.121 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 119.235.214.121 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 09:45:43.258874 2026] [security2:error] [pid 619:tid 619] [client 119.235.214.121:5626] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "emmtrucking.com"] [uri "/config/.env.production"] [unique_id "apgohyudcEKPpsP9AcGoIAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
LRob
2026-09-02 13:37:27
(1 day ago)
Enumerating paths that do not exist (scanning) | method: GET | path: /info.php | ua: Mozilla/5.0 (Wi ...
show more
Enumerating paths that do not exist (scanning) | method: GET | path: /info.php | ua: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0 Safari/537.36 | 2026-09-02 13:37 UTC
show less
Port Scan
Web App Attack
🇩🇪
big-cloud.nl
2026-09-02 13:02:37
(1 day ago)
Try to access /.env
Web App Attack
🇺🇸
nyt
2026-09-02 12:53:20
(1 day ago)
Sensitive File Probe
Web App Attack
🇿🇦
conure.sh
2026-09-02 12:34:43
(1 day ago)
csagent: score 20.3: secrets grab x2, 404 noise floor x2; 1 domain(s) in 3s
Web App Attack
Anonymous
2026-09-02 11:09:32
(1 day ago)
Web App Attack
Brute-Force
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2026-09-02 10:46:14
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 119.235.214.121 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 119.235.214.121 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 06:45:58.364679 2026] [security2:error] [pid 30761:tid 30761] [client 119.235.214.121:34590] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tgcindustrial.com"] [uri "/docker/.env"] [unique_id "apf-ZrETJCkM8ICkG61-5wAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-02 07:36:40
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 119.235.214.121 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 119.235.214.121 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 03:36:26.391894 2026] [security2:error] [pid 12736:tid 12758] [client 119.235.214.121:34564] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gotogps.com"] [uri "/api/.env.local"] [unique_id "apfR-rTQe7b0xaoUZU94ZwAAAVI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
dynamix
2026-09-02 04:05:05
(2 days ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2026-09-02 03:43:56
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 119.235.214.121 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 119.235.214.121 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 23:43:50.296663 2026] [security2:error] [pid 12959:tid 12959] [client 119.235.214.121:12242] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cgautomatizacion.com"] [uri "/server/.env"] [unique_id "apebdl719-QFJWYrDmwqJwAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack