Anonymous
2026-10-01 20:25:18
(9 hours ago)
"GET /.env.production HTTP/1.1"
Hacking
Web App Attack
π±πΊ
conseilgouz
2026-10-01 17:57:33
(11 hours ago)
are-17 : Block hidden directories=>/.env.staging(/)
Hacking
πΊπΈ
TPI-Abuse
2026-10-01 09:39:50
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.99.115 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.99.115 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 05:39:41.244354 2026] [security2:error] [pid 13940:tid 13940] [client 141.101.99.115:11581] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pjv.us"] [uri "/.env.staging"] [unique_id "ar4qXbt2qoFYG0vG1yUgcQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π΅π±
TaKeN
2026-10-01 08:20:32
(21 hours ago)
Automated Wazuh observation. Wazuh rule 31151 lvl=10 detected repeated HTTP web application probing ...
show more
Automated Wazuh observation. Wazuh rule 31151 lvl=10 detected repeated HTTP web application probing from this source IP. Observed 1 matching Wazuh alert(s) between 2026-10-01T10:20:32+02:00 and 2026-10-01T10:20:32+02:00.
show less
Web App Attack
Hacking
πΊπΈ
TPI-Abuse
2026-10-01 04:21:12
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 141.101.99.115 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.99.115 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 00:21:07.459976 2026] [security2:error] [pid 30778:tid 30827] [client 141.101.99.115:11673] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bobchaos.com"] [uri "/.env.backup"] [unique_id "ar3fs63Vhw64ApZY_x1uzwAAAU8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
raph
2026-09-30 17:06:25
(1 day ago)
[PROTECTED PATHS] crawler credentials.ini, aws.ini, aws.yml, etc.
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-30 14:22:45
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 141.101.99.115 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.99.115 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 10:22:40.750555 2026] [security2:error] [pid 20217:tid 20217] [client 141.101.99.115:9973] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "offbeatcompassion.com"] [uri "/.env.staging"] [unique_id "ar0bMIB1pUqnfYM2Plho4AAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-30 10:03:19
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 141.101.99.115 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.99.115 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 06:03:12.531718 2026] [security2:error] [pid 17946:tid 17946] [client 141.101.99.115:11108] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "oakvillenaturopathicclinic.com"] [uri "/.env.backup"] [unique_id "arzeYHkhA8qg7suRPLfTTAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-29 22:01:08
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 141.101.99.115 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.99.115 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 18:01:00.131382 2026] [security2:error] [pid 24824:tid 24824] [client 141.101.99.115:11968] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "celebritybikinigossip.com"] [uri "/.svn/entries"] [unique_id "arw1HMq989uTr6lx7bY0ZgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπ¦
URAN Publishing Service
2026-09-29 15:45:20
(2 days ago)
[29/Sep/2026:18:45:20 +0300] -- 141.101.99.115 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET ...
show more
[29/Sep/2026:18:45:20 +0300] -- 141.101.99.115 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET /.env HTTP/1.1
show less
Bad Web Bot
Web App Attack
πΊπΈ
billyw0nka
2026-09-29 11:36:50
(2 days ago)
pattern: .env
Hacking
π©πͺ
Vegascosmetics
2026-09-29 09:43:34
(2 days ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after sensitive config/credentials exposure ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after sensitive config/credentials exposure probe. Evidence: AttackPattern: /\.env (Match: /.env)
show less
Hacking
Brute-Force
Web App Attack
Anonymous
2026-09-28 22:50:05
(3 days ago)
| Suspicious URL access.
Web App Attack
Hacking
SQL Injection
πΊπΈ
TPI-Abuse
2026-09-28 21:53:59
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 141.101.99.115 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.99.115 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 17:53:53.075164 2026] [security2:error] [pid 29012:tid 29012] [client 141.101.99.115:9599] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.peterjohnsonauthor.com"] [uri "/wp-config.php"] [unique_id "arrh8Vjxq5k1U5EHZn1J-gAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-28 14:45:02
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 141.101.99.115 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.99.115 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 10:44:56.429263 2026] [security2:error] [pid 16062:tid 16062] [client 141.101.99.115:11722] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.evannine.com"] [uri "/wp-config.php"] [unique_id "arp9aLkB_7XnzRkmz6M1IwAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack