๐ณ๐ฑ
homeshowdomain.nl
2026-08-01 21:59:43
(8 hours ago)
Auto-ban: >3000 req/min op 2026-08-01
Web App Attack
SSH
Hacking
๐จ๐ญ
leo1305
2026-08-01 17:03:47
(13 hours ago)
CrowdSec detection | scenario: http-sensitive-files
Web App Attack
Exploited Host
๐ซ๐ฎ
mnazibo
2026-08-01 17:00:09
(13 hours ago)
Date: 01/Aug/2026 19:42:00 | Reported IP: 136.85.27.203 mod_security | id: 930130 | SG/group.my_doma ...
show more
Date: 01/Aug/2026 19:42:00 | Reported IP: 136.85.27.203 mod_security | id: 930130 | SG/group.my_domain/- | Connections: 8 | Blocked: Permanent Block: [LF_MODSEC] | URIs: /.env.backup; /.env.bak; /.env.dev; /.env.example; /.env.local; /.env.old; /.env.production; /.env.save | Logs: Restricted File Access Attempt
show less
SQL Injection
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-08-01 16:39:19
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.85.27.203 (203.27.85.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.85.27.203 (203.27.85.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 12:39:13.314585 2026] [security2:error] [pid 123528:tid 123528] [client 136.85.27.203:35542] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ferienwohnungen-eva.com.ferienwohnung-buchen.com"] [uri "/.env.save"] [unique_id "am4hMV_G4ZUKMr7nVs-NMAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ท๐บ
DZBOT
2026-08-01 16:00:23
(14 hours ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐บ๐ธ
Lee Daniel
2026-08-01 15:35:46
(14 hours ago)
136.85.27.203 - - [01/Aug/2026:11:35:45 -0400] "GET /.env HTTP/1.1" 403 6290 "-" "crusader-worker/1. ...
show more
136.85.27.203 - - [01/Aug/2026:11:35:45 -0400] "GET /.env HTTP/1.1" 403 6290 "-" "crusader-worker/1.0"
...
show less
DDoS Attack
Web Spam
Email Spam
Port Scan
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
4server
2026-08-01 15:34:56
(15 hours ago)
[SatAug0117:34:52.6359582026][security2:error][pid4050659:tid4050975][client136.85.27.203:0]ModSecur ...
show more
[SatAug0117:34:52.6359582026][security2:error][pid4050659:tid4050975][client136.85.27.203:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".env\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"365\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"bozza.executivekotech.it\"][uri\"/.env.production\"][unique_id\"am4SHHr3wVZM29FXHxD8ugAAARI\"]
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 15:21:25
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.85.27.203 (203.27.85.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.85.27.203 (203.27.85.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 11:21:17.528587 2026] [security2:error] [pid 2875242:tid 2875253] [client 136.85.27.203:48870] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "staging.kettlehill.com"] [uri "/.env.local"] [unique_id "am4O7cbMBn1nErInZotwjAAAAQU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
zynex
2026-08-01 14:33:52
(16 hours ago)
URL Probing: /.env
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 14:20:01
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.85.27.203 (203.27.85.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.85.27.203 (203.27.85.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 10:19:55.300275 2026] [security2:error] [pid 1188360:tid 1188360] [client 136.85.27.203:41554] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "communitybudgetcommittee.epscalltoaction.org"] [uri "/.env.bak"] [unique_id "am4Ai4kSoEnuEvHaUc8xcAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
paissangroup
2026-08-01 14:16:11
(16 hours ago)
Multiple WAF Violations
Web App Attack
๐ซ๐ท
dynamix
2026-08-01 14:05:45
(16 hours ago)
Multiple WAF Violations
Web App Attack
๐ธ๐ช
vaia.cloud
2026-08-01 13:55:04
(16 hours ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
Anonymous
2026-08-01 13:55:04
(16 hours ago)
suspicious request in access.log
Web App Attack
๐ซ๐ท
masterguru
2026-08-01 13:54:22
(16 hours ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-201)
Hacking
Web App Attack