🇫🇷
JPPO
2026-09-06 08:02:05
(6 hours ago)
20 hits : GET /.env or GET //.env with or without prefix /api,/config ...
Web App Attack
🇺🇸
LSPCCU
2026-09-06 06:51:26
(7 hours ago)
TSEC Honeypot Network report. Threat score: 71/100. Categories: DDoS Attack, Port Scan, Hacking, Bru ...
show more
TSEC Honeypot Network report. Threat score: 71/100. Categories: DDoS Attack, Port Scan, Hacking, Brute-Force, Web App Attack, SSH. Honeypot: h0neytr4p. Context: 136.107.127.200 classified as botnet node participating in coordinated attack campaigns (high confidence).
show less
DDoS Attack
Port Scan
Hacking
Brute-Force
Web App Attack
SSH
Anonymous
2026-09-06 06:31:54
(7 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
🇮🇹
madaello
2026-09-06 06:01:06
(8 hours ago)
136.107.127.200 - - [06/Sep/2026:08:01:06 +0200] "GET /.env HTTP/1.1" 301 575 "-" "crusader-worker/1 ...
show more
136.107.127.200 - - [06/Sep/2026:08:01:06 +0200] "GET /.env HTTP/1.1" 301 575 "-" "crusader-worker/1.0"
136.107.127.200 - - [06/Sep/2026:08:01:06 +0200] "GET /.env.local HTTP/1.1" 301 587 "-" "crusader-worker/1.0"
136.107.127.200 - - [06/Sep/2026:08:01:06 +0200] "GET /.env.prod HTTP/1.1" 301 585 "-" "crusader-worker/1.0"
136.107.127.200 - - [06/Sep/2026:08:01:06 +0200] "GET /actuator/env HTTP/1.1" 301 591 "-" "crusader-worker/1.0"
...
show less
Hacking
🇺🇸
aks4226
2026-09-06 05:39:53
(8 hours ago)
Attacking common web applications. (n01)
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 03:49:36
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.107.127.200 (200.127.107.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 136.107.127.200 (200.127.107.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:49:30.622345 2026] [security2:error] [pid 26204:tid 26217] [client 136.107.127.200:59454] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.securitymediaservices.com"] [uri "/.env.prod"] [unique_id "apziytBbnM4DZJ7oJiN7sAAAAQo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 02:57:07
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.107.127.200 (200.127.107.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 136.107.127.200 (200.127.107.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:57:02.372956 2026] [security2:error] [pid 24555:tid 24555] [client 136.107.127.200:57798] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.alphacom.us"] [uri "/.env.prod"] [unique_id "apzWfohvZRJkdjo6Rz8WtAAAAEE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-06 02:56:27
(11 hours ago)
Blocked by ModSec and CSF
Port Scan
🇫🇷
✨
2026-09-06 02:49:07
(11 hours ago)
Domain : turtletrac.com
Rule : hack
2026-09-06 02:47:42 ***hidden-privacy*** GET /.env.bak - 443 - 1 ...
show more
Domain : turtletrac.com
Rule : hack
2026-09-06 02:47:42 ***hidden-privacy*** GET /.env.bak - 443 - 136.107.127.200 HTTP/1.1 crusader-worker/1.0 - turtletrac.com 403 503 5 12787 94 77 - -
show less
Hacking
SQL Injection
Brute-Force
Anonymous
2026-09-06 02:46:12
(11 hours ago)
[osotir.org] httpd-config-scan: sites=www.agonistes.gr; logs=/var/log/httpd/domains/agonistes.gr.log ...
show more
[osotir.org] httpd-config-scan: sites=www.agonistes.gr; logs=/var/log/httpd/domains/agonistes.gr.log; samples=/actuator/env | /wp-config.php~ | /.env.bak
show less
Hacking
Web App Attack
🇺🇸
Lea
2026-09-06 02:44:24
(11 hours ago)
Malicious web probe detected on bearstool.com: 136.107.127.200 - - [05/Sep/2026:22:44:23 -0400] "GET ...
show more
Malicious web probe detected on bearstool.com: 136.107.127.200 - - [05/Sep/2026:22:44:23 -0400] "GET /.env.backup HTTP/1.1" 444 0 "-" "crusader-worker/1.0"
show less
Bad Web Bot
Web App Attack
Anonymous
2026-09-06 02:35:04
(11 hours ago)
suspicious request in access.log
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-06 02:28:24
(11 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇫🇷
thilo
2026-09-06 02:23:10
(11 hours ago)
Probe for vulnerabilities. Path attempted: /.env.save
Web App Attack
🇩🇪
FD-IX
2026-09-06 01:09:45
(13 hours ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack