๐ง๐ฌ
fennaronaldo
2026-07-21 14:13:31
(1 hour ago)
WAF block action triggered by rule set "Version Control - Information Disclosure" (1 occurrences obs ...
show more
WAF block action triggered by rule set "Version Control - Information Disclosure" (1 occurrences observed).
show less
Web App Attack
๐บ๐ธ
Rip
2026-07-17 10:37:23
(4 days ago)
Restricted File Access Attempts
Port Scan
Web App Attack
๐ณ๐ฑ
Site.eu
2026-07-17 09:26:05
(4 days ago)
Excessive multi-domain requests
Brute-Force
๐ซ๐ท
breubit
2026-07-17 09:03:32
(4 days ago)
138.124.103.234 - - [17/Jul/2026:11:03:31 +0200] "GET /public/.env HTTP/1.1" 403 4462 "-" "Mozilla/5 ...
show more
138.124.103.234 - - [17/Jul/2026:11:03:31 +0200] "GET /public/.env HTTP/1.1" 403 4462 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.36 (Silvy X Ran; +https://silvyxran.love; +https://silver.inc)"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-17 08:34:50
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 138.124.103.234 (temporarypayment.ptr.network): ...
show more
(mod_security) mod_security (id:210492) triggered by 138.124.103.234 (temporarypayment.ptr.network): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 17 04:34:45.288378 2026] [security2:error] [pid 1807:tid 1807] [client 138.124.103.234:43238] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fivestardrives.truefauxstudio.com"] [uri "/.env"] [unique_id "alnpJTuzFW6JjGyZxUiCwgAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-17 08:06:45
(4 days ago)
(caddyscan) Scanner path probe from 138.124.103.234 (SE/Sweden/temporarypayment.ptr.network): 5 in t ...
show more
(caddyscan) Scanner path probe from 138.124.103.234 (SE/Sweden/temporarypayment.ptr.network): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 138.124.103.234 - - [17/Jul/2026:08:06:43 +0000] "GET /.env HTTP/1.1"
[REDACTED] 200 2627 138.124.103.234 - - [17/Jul/2026:08:06:43 +0000] "GET /.env.local HTTP/1.1"
[REDACTED] 200 2627 138.124.103.234 - - [17/Jul/2026:08:06:44 +0000] "GET /.env.production HTTP/1.1"
[REDACTED] 200 2627 138.124.103.234 - - [17/Jul/2026:08:06:44 +0000] "GET /.env.development HTTP/1.1"
[REDACTED] 200 2627 138.124.103.234 - - [17/Jul/2026:08:06:44 +0000] "GET /.env.dev HTTP/1.1"
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-07-17 08:01:01
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 138.124.103.234 (temporarypayment.ptr.network): ...
show more
(mod_security) mod_security (id:210492) triggered by 138.124.103.234 (temporarypayment.ptr.network): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 17 04:00:53.883088 2026] [security2:error] [pid 8705:tid 8705] [client 138.124.103.234:58732] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "amazinghydraulics.com"] [uri "/.env.sample"] [unique_id "alnhNXPZV6Ne773E0oCnVAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Matthew Ping
2026-07-17 07:45:05
(4 days ago)
ModSecurity rule 949110 triggered on wp3. Web application attack blocked by CSF/LFD.
Web App Attack
Hacking
๐ซ๐ท
Baking333
2026-07-17 07:00:35
(4 days ago)
[redacted] 138.124.103.234 - - [17/Jul/2026:08:00:34 +0100] "GET /src/.env HTTP/1.1" 302 6742 0/6534 ...
show more
[redacted] 138.124.103.234 - - [17/Jul/2026:08:00:34 +0100] "GET /src/.env HTTP/1.1" 302 6742 0/65346 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.36 (Silvy X Ran; +https://[redacted]; +https://[redacted])" [redacted] 138.124.103.234 - - [17/Jul/2026:08:00:34 +0100] "GET /config/.env HTTP/1.1" 302 1499 0/79957 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.36 (Silvy X Ran; +https://[redacted]; +https://[redacted])"
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
iNetWorker
2026-07-17 06:35:05
(4 days ago)
trolling for resource vulnerabilities
Web App Attack
๐ง๐ช
sid3windr
2026-07-17 06:31:53
(4 days ago)
GET /config/secrets.yml (Tarpitted for , wasted 120B)
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-07-17 06:27:10
(4 days ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-07-17 06:02:27
(4 days ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-195)
Hacking
Web App Attack
๐ฎ๐ณ
evicky2002
2026-07-17 06:00:00
(4 days ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
Anonymous
2026-07-17 04:37:35
(4 days ago)
(caddyscan) Scanner path probe from 138.124.103.234 (SE/Sweden/temporarypayment.ptr.network): 5 in t ...
show more
(caddyscan) Scanner path probe from 138.124.103.234 (SE/Sweden/temporarypayment.ptr.network): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 138.124.103.234 - - [17/Jul/2026:04:37:30 +0000] "GET /.env.dist HTTP/1.1"
[REDACTED] 200 2627 138.124.103.234 - - [17/Jul/2026:04:37:30 +0000] "GET /.env.template HTTP/1.1"
[REDACTED] 200 2627 138.124.103.234 - - [17/Jul/2026:04:37:30 +0000] "GET /.env.production.local HTTP/1.1"
[REDACTED] 200 2627 138.124.103.234 - - [17/Jul/2026:04:37:30 +0000] "GET /.env.development.local HTTP/1.1"
[REDACTED] 200 2627 138.124.103.234 - - [17/Jul/2026:04:37:31 +0000] "GET /.env.test.local HTTP/1.1"
show less
Port Scan