๐จ๐ญ
4server
2026-09-01 12:57:42
(53 minutes ago)
[TueSep0114:57:36.4887152026][security2:error][pid3359314:tid3359406][client129.212.235.63:0]ModSecu ...
show more
[TueSep0114:57:36.4887152026][security2:error][pid3359314:tid3359406][client129.212.235.63:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".env\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"610\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"whatsdecor.ch\"][uri\"/.env\"][unique_id\"apbLwPkGhTosraTB9GlUswAAAYI\"]
show less
Hacking
Web App Attack
๐ฉ๐ช
LRob
2026-09-01 00:35:29
(13 hours ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.env (+1 more) | 2026-09-01 00:35 UTC
show less
Hacking
Web App Attack
๐ฉ๐ช
outputblog.de
2026-08-31 15:04:37
(22 hours ago)
apache-wp-probephp
Port Scan
Hacking
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-08-31 07:16:58
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 129.212.235.63 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 129.212.235.63 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 03:16:50.608205 2026] [security2:error] [pid 23043:tid 23043] [client 129.212.235.63:52288] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.bickleton.org"] [uri "/.env"] [unique_id "apUqYkd5__nV41I2fIL6hgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-31 05:06:56
(1 day ago)
[da.kdns.gr] httpd-config-scan: sites=www.webfly.gr; logs=/var/log/httpd/domains/webfly.gr.log; samp ...
show more
[da.kdns.gr] httpd-config-scan: sites=www.webfly.gr; logs=/var/log/httpd/domains/webfly.gr.log; samples=/.env | /vendor/.env | /storage/.env
show less
Hacking
Web App Attack
๐ฉ๐ช
yvoictra
2026-08-30 22:37:07
(1 day ago)
Bloqueado automรกticamente por CrowdSec. Escenario: crowdsecurity/http-sensitive-files
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-30 20:15:33
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 129.212.235.63 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 129.212.235.63 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 30 16:15:26.503834 2026] [security2:error] [pid 27737:tid 27737] [client 129.212.235.63:51738] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.brianwhitty.com"] [uri "/.env"] [unique_id "apSPXlGgtuF6Rg99IX4lQQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-30 18:18:06
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 129.212.235.63 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 129.212.235.63 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 30 14:17:57.943422 2026] [security2:error] [pid 22217:tid 22217] [client 129.212.235.63:57016] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.rochesterhistorical.org"] [uri "/.env"] [unique_id "apRz1dldpdjd4HpywWM8kwAAAAE"], referer: https://google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Gwyneth Llewelyn
2026-08-30 16:41:40
(1 day ago)
2026/08/30 17:41:38 [error] 380594#380594: *1624583 access forbidden by rule, client: 129.212.235.63 ...
show more
2026/08/30 17:41:38 [error] 380594#380594: *1624583 access forbidden by rule, client: 129.212.235.63, server: betatechnologies.info, request: "GET /.env HTTP/2.0", host: "betatechnologies.info"
129.212.235.63 - - [30/Aug/2026:17:41:38 +0100] "GET /.env HTTP/2.0" 403 1045 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.67 Safari/537.36"
2026/08/30 17:41:39 [error] 380594#380594: *1624588 access forbidden by rule, client: 129.212.235.63, server: betatechnologies.info, request: "GET /vendor/.env HTTP/2.0", host: "betatechnologies.info", referrer: "https://google.com"
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-30 13:55:46
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 129.212.235.63 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 129.212.235.63 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 30 09:55:40.099199 2026] [security2:error] [pid 21254:tid 21266] [client 129.212.235.63:58673] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "conservativelabor.com"] [uri "/.env"] [unique_id "apQ2XGcgh2Bxd9hfwJRd4AAAAEU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-30 12:52:43
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 129.212.235.63 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 129.212.235.63 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 30 08:52:39.809669 2026] [security2:error] [pid 2278992:tid 2278997] [client 129.212.235.63:59338] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "condo.management"] [uri "/.env"] [unique_id "apQnlxsQqq80vuDctK6cGwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-30 07:31:52
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 129.212.235.63 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 129.212.235.63 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 30 03:31:48.582019 2026] [security2:error] [pid 13260:tid 13260] [client 129.212.235.63:62542] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.anus.net"] [uri "/.env"] [unique_id "apPcZMf7W-Hl_hN0G-aNJwAAAAM"], referer: https://google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
aranguren.org
2026-08-30 06:08:26
(2 days ago)
129.212.235.63 - - [30/Aug/2026:16:08:25 +1000] "GET /.env HTTP/1.1" 404 1102 "https://google.com" " ...
show more
129.212.235.63 - - [30/Aug/2026:16:08:25 +1000] "GET /.env HTTP/1.1" 404 1102 "https://google.com" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/68.0.3440.75 Safari/537.36"
129.212.235.63 - - [30/Aug/2026:16:08:25 +1000] "GET /vendor/.env HTTP/1.1" 404 981 "-" "Mozilla/5.0 (Windows NT 6.2) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/64.0.3282.167 Safari/537.36"
129.212.235.63 - - [30/Aug/2026:16:08:25 +1000] "GET /storage/.env HTTP/1.1" 404 1102 "https://google.com" "Mozilla/5.0 (Windows NT 6.3) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/68.0.3440.91 Safari/537.36"
129.212.235.63 - - [30/Aug/2026:16:08:25 +1000] "GET /public/.env HTTP/1.1" 404 1102 "https://google.com" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/65.0.3325.162 Safari/537.36"
129.212.235.63 - - [30/Aug/2026:16:08:25 +1000] "GET /api/.env HTTP/1.1" 404 1102 "https://google.com" "Mozilla/5.0 (Windows NT 6.2; Win64; x64) AppleWebKit/
...
show less
Bad Web Bot
๐ช๐ธ
alferez
2026-08-30 05:42:51
(2 days ago)
Searching .(env|sql|zip|tar|rar) files
Hacking
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-30 02:56:05
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 129.212.235.63 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 129.212.235.63 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 22:55:59.271305 2026] [security2:error] [pid 6647:tid 6647] [client 129.212.235.63:61041] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.ucommsi.com"] [uri "/.env"] [unique_id "apObv-Epw_AMYk_Zw2lxkgAAAA4"], referer: https://google.com
show less
Brute-Force
Bad Web Bot
Web App Attack