Anonymous
2026-08-28 07:23:23
(3 minutes ago)
Blocked by ModSec and CSF
Port Scan
๐ฉ๐ช
Holger
2026-08-28 06:59:16
(27 minutes ago)
Bruteforce WebAttack
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 06:30:09
(56 minutes ago)
(mod_security) mod_security (id:210492) triggered by 136.110.98.31 (31.98.110.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.110.98.31 (31.98.110.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 02:30:01.121276 2026] [security2:error] [pid 3979:tid 3979] [client 136.110.98.31:56456] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.evolute.io"] [uri "/@fs/root/.env"] [unique_id "apEq6Xkswh2djKXKu_EVcwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
openstrike.co.uk
2026-08-28 05:14:36
(2 hours ago)
126 attacks on env grabbing URLs, config grabbing URLs (type 2), password grabbing URLs, VC URLs, PH ...
show more
126 attacks on env grabbing URLs, config grabbing URLs (type 2), password grabbing URLs, VC URLs, PHP URLs:
GET /.env.docker HTTP/1.1
GET /config/application.yml HTTP/1.1
GET /root/.aws/credentials HTTP/1.1
GET /.git/config HTTP/1.1
GET /i.php HTTP/1.1
show less
Hacking
Web App Attack
๐ฉ๐ช
macrob
2026-08-28 05:07:40
(2 hours ago)
2026/08/28 05:07:39 [error] 3240431#3240431: *528797203 access forbidden by rule, client: 136.110.98 ...
show more
2026/08/28 05:07:39 [error] 3240431#3240431: *528797203 access forbidden by rule, client: 136.110.98.31, server: binixo.ph, request: "GET /@fs/root/.env?raw?? HTTP/1.1", host: "binixo.ph"
2026/08/28 05:07:39 [error] 3240431#3240431: *528797206 access forbidden by rule, client: 136.110.98.31, server: binixo.ph, request: "GET /@fs/src/.env?raw?? HTTP/1.1", host: "binixo.ph"
2026/08/28 05:07:39 [error] 3240431#3240431: *528797207 access forbidden by rule, client: 136.110.98.31, server: binixo.ph, request: "GET /@fs/.env?raw?? HTTP/1.1", host: "binixo.ph"
...
show less
Web App Attack
Anonymous
2026-08-28 04:13:43
(3 hours ago)
136.110.98.31 - - [28/Aug/2026:06:13:40 +0200] "GET /frontend/.env HTTP/1.1" 404 7148 "-" "Mozilla/5 ...
show more
136.110.98.31 - - [28/Aug/2026:06:13:40 +0200] "GET /frontend/.env HTTP/1.1" 404 7148 "-" "Mozilla/5.0 (Linux; Android 14; Pixel 8) AppleWebKit/537.36 (KHTML, like Gecko; compatible; Google-Extended/1.0; +http://www.google.com/bot.html) Chrome/128.0.7119.212 Mobile Safari/537.36"
...
show less
Brute-Force
Web App Attack
๐ณ๐ฑ
middelkoopcc
2026-08-28 04:03:00
(3 hours ago)
2026-08-28 06:01:16 AH10244: invalid URI path (/@fs/../../.env?raw??) && 2026-08-28 06:01:32 AH10244 ...
show more
2026-08-28 06:01:16 AH10244: invalid URI path (/@fs/../../.env?raw??) && 2026-08-28 06:01:32 AH10244: invalid URI path (/@fs/../../../../../proc/self/environ?raw??) && 2026-08-28 06:01:32 AH10244: invalid URI path (/@fs/../../../../../app/.env?raw??) && 121 more within 20 minutes
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 03:37:20
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.110.98.31 (31.98.110.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.110.98.31 (31.98.110.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 23:37:16.302211 2026] [security2:error] [pid 4226:tid 4226] [client 136.110.98.31:5464] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "caferutadelaseda.com"] [uri "/@fs/.env"] [unique_id "apECbBUU5t9MWy0NVH-8dgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-28 03:04:12
(4 hours ago)
Bot / seems abusive / Apache connections: 53
DDoS Attack
Web Spam
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 02:52:11
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.110.98.31 (31.98.110.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.110.98.31 (31.98.110.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 22:52:06.068638 2026] [security2:error] [pid 27613:tid 27613] [client 136.110.98.31:62112] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.calogerolawfirm.com"] [uri "/@fs/.env"] [unique_id "apD31t09Phvh9SGu6K5TogAAADM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-28 02:50:29
(4 hours ago)
Multiple web server 400 error codes from same source ip
Web App Attack
๐ซ๐ท
Octopuce
2026-08-28 02:44:33
(4 hours ago)
Aggressive web search of vulnerable pages: /_nuxt/../.env /backend/.env /assets../.env /v1/.env /app ...
show more
Aggressive web search of vulnerable pages: /_nuxt/../.env /backend/.env /assets../.env /v1/.env /app/.env ...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 02:25:26
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.110.98.31 (31.98.110.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.110.98.31 (31.98.110.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 22:25:19.659400 2026] [security2:error] [pid 25964:tid 25964] [client 136.110.98.31:28170] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.epicjellyfish.com"] [uri "/@fs/root/.env"] [unique_id "apDxj0Q0U_EBdmNBD35MngAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-28 02:16:12
(5 hours ago)
[ns3.backorder.gr] httpd-config-scan: sites=www.gosolar.gr; logs=/var/log/httpd/access_log,/var/log/ ...
show more
[ns3.backorder.gr] httpd-config-scan: sites=www.gosolar.gr; logs=/var/log/httpd/access_log,/var/log/httpd/domains/gosolar.gr.log; samples=/@fs/src/.env?raw?? | /@fs/../.env?raw?? | /@fs/root/.aws/credentials?raw??
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 02:09:25
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.110.98.31 (31.98.110.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.110.98.31 (31.98.110.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 22:09:19.162037 2026] [security2:error] [pid 25085:tid 25085] [client 136.110.98.31:8480] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.theknowledgemaster.com"] [uri "/@fs/app/.env"] [unique_id "apDtz4b_otvgUL6XCr-GNQAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack