๐ฉ๐ช
Holger
2026-06-13 12:33:34
(2 months ago)
Bruteforce WebAttack
Brute-Force
Web App Attack
๐ฉ๐ช
Holger
2026-06-11 09:27:16
(2 months ago)
Bruteforce WebAttack
Brute-Force
Web App Attack
๐ฌ๐ง
seniorlinuxadmin
2026-06-08 13:10:44
(2 months ago)
147.79.84.109 - - [08/Jun/2026:14:10:41 +0100] "GET /core/.env HTTP/1.1" 404 158 "-" "Mozilla/5.0 (M ...
show more
147.79.84.109 - - [08/Jun/2026:14:10:41 +0100] "GET /core/.env HTTP/1.1" 404 158 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36"
show less
Port Scan
Web App Attack
๐ฉ๐ช
paissangroup
2026-06-08 12:03:22
(2 months ago)
Multiple WAF Violations
Web App Attack
๐ซ๐ท
masterguru
2026-06-08 09:49:26
(2 months ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-197)
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-08 09:40:16
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 147.79.84.109 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 147.79.84.109 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 05:40:11.938456 2026] [security2:error] [pid 14152:tid 14152] [client 147.79.84.109:24954] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mikeloehr.com"] [uri "/app/.env"] [unique_id "aiaN-xJa5u4Fvcoj4qCJ9AAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-08 08:24:32
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 147.79.84.109 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 147.79.84.109 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 04:24:25.041276 2026] [security2:error] [pid 29628:tid 29628] [client 147.79.84.109:34618] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dance4ovations.com"] [uri "/core/.env"] [unique_id "aiZ8OVndHVYk7VYLp6d8UQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
paulshipley.com.au
2026-06-08 08:24:12
(2 months ago)
[Mon Jun 08 18:24:11.251615 2026] [security2:error] [pid 93584] [client 147.79.84.109:29458] [client ...
show more
[Mon Jun 08 18:24:11.251615 2026] [security2:error] [pid 93584] [client 147.79.84.109:29458] [client 147.79.84.109] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "dance4fitness.com.au"] [uri "/.env"] [unique_id "aiZ8K9AxHsNtDma8OZIxwQAAAF8"]
...
show less
Web App Attack
Anonymous
2026-06-08 06:54:48
(3 months ago)
(caddyscan) Scanner path probe from 147.79.84.109 (BR/Brazil/-): 5 in the last 3600 secs; Ports: *; ...
show more
(caddyscan) Scanner path probe from 147.79.84.109 (BR/Brazil/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 147.79.84.109 - - [08/Jun/2026:06:54:46 +0000] "GET /dev/.env HTTP/1.1"
[REDACTED] 200 2627 147.79.84.109 - - [08/Jun/2026:06:54:46 +0000] "GET /app/.env HTTP/1.1"
[REDACTED] 200 2627 147.79.84.109 - - [08/Jun/2026:06:54:46 +0000] "GET /members/.env HTTP/1.1"
[REDACTED] 200 2627 147.79.84.109 - - [08/Jun/2026:06:54:46 +0000] "GET /.env HTTP/1.1"
[REDACTED] 200 2627 147.79.84.109 - - [08/Jun/2026:06:54:46 +0000] "GET /admin/.env HTTP/1.1"
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-06-08 04:56:14
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 147.79.84.109 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 147.79.84.109 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 00:56:09.814049 2026] [security2:error] [pid 11722:tid 11722] [client 147.79.84.109:63434] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "valueandmeaning.com"] [uri "/core/.env.save"] [unique_id "aiZLaWl4d4HVI82cRB2v6QAAAGk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
paulshipley.com.au
2026-06-08 04:54:57
(3 months ago)
[Mon Jun 08 14:54:55.929486 2026] [security2:error] [pid 68189] [client 147.79.84.109:16618] [client ...
show more
[Mon Jun 08 14:54:55.929486 2026] [security2:error] [pid 68189] [client 147.79.84.109:16618] [client 147.79.84.109] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "valueaddedpromotions.com.au"] [uri "/.env"] [unique_id "aiZLH6C7mk3HpuScdBOhWQAAAD4"]
...
show less
Web App Attack
Anonymous
2026-06-08 04:26:03
(3 months ago)
Bot / scanning and/or hacking attempts: GET /.env.save HTTP/1.1, GET /core/.env HTTP/1.1
Hacking
Web App Attack
๐ฉ๐ช
NewGastroline
2026-06-08 04:11:49
(3 months ago)
Malicious request blocked by CrowdSec on gastro-prod1.boreus.de
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-06-08 00:59:22
(3 months ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-193)
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-07 23:06:21
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 147.79.84.109 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 147.79.84.109 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 07 19:06:16.888744 2026] [security2:error] [pid 30465:tid 30465] [client 147.79.84.109:35728] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hodges-web.com"] [uri "/laravel/.env"] [unique_id "aiX5aFzDma_bcgB2UwswiAAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack