๐ง๐ช
cmbplf
2026-07-31 09:35:01
(1 day ago)
196 requests with url.path *.env
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-07-31 01:12:17
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 149.30.146.82 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 149.30.146.82 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 30 21:12:11.641058 2026] [security2:error] [pid 219010:tid 219010] [client 149.30.146.82:61643] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.ismaelcavazos.com"] [uri "/.env"] [unique_id "amv2az1pRx7PiB8KTK3iSgAAACw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-29 07:00:00
(3 days ago)
Apache probe; attempts=20; exact paths: /.env | /.env/
Web App Attack
Anonymous
2026-07-25 16:32:27
(6 days ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
๐บ๐ธ
TPI-Abuse
2026-07-25 16:23:55
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 149.30.146.82 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 149.30.146.82 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 25 12:23:51.163804 2026] [security2:error] [pid 1263605:tid 1263605] [client 149.30.146.82:57626] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "artspacecleveland.org"] [uri "/.env"] [unique_id "amTjF02jZrh6aRNoG6SfUgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฟ๐ฆ
conure
2026-07-25 12:02:21
(1 week ago)
csagent: score 21.2: 404 noise floor x6, secrets grab x2; 2 domain(s) in 5s
Web App Attack
๐ธ๐ฌ
securejdprop
2026-07-25 04:54:58
(1 week ago)
This IP was detected by CrowdSec triggering crowdsecurity/vpatch-env-access.
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-25 04:47:18
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 149.30.146.82 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 149.30.146.82 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 25 00:47:09.888705 2026] [security2:error] [pid 2025936:tid 2025955] [client 149.30.146.82:6256] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mjkotob.com"] [uri "/.env"] [unique_id "amQ_zf0BFyDe0PVvs9fPHAAAARE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ด
jad-abuse
2026-07-25 04:47:01
(1 week ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: env_probe ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: env_probe. Observed by 1 sensor(s); 8 hits.
show less
Web App Attack
๐บ๐ธ
kosada.com
2026-07-25 04:21:13
(1 week ago)
Web vulnerability probing: /.env
Web App Attack
๐ฑ๐ป
garmtech.com
2026-07-25 03:57:42
(1 week ago)
IM360 WAF: Direct access to sensitive file or dotfile MV:/.env
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 19:43:12
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 149.30.146.82 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 149.30.146.82 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 15:43:05.648156 2026] [security2:error] [pid 3117700:tid 3117700] [client 149.30.146.82:41545] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sharawi-gum.com"] [uri "/.env"] [unique_id "amPASa2ryANUlGSqPyHxNAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ท
setupgr
2026-07-24 19:13:50
(1 week ago)
(mod_security) mod_security (id:9999001) triggered by 149.30.146.82 (PH/Philippines/Calabarzon/Majay ...
show more
(mod_security) mod_security (id:9999001) triggered by 149.30.146.82 (PH/Philippines/Calabarzon/Majayjay/-/[AS134707 RCC-AS-AP RoyalCable Flash]): 1 in the last 86400 secs (CF_ENABLE); Ports: *; Direction: inout; Trigger: LF_MODSEC; Logs: [Fri Jul 24 22:13:47.442811 2026] [security2:error] [pid 351897:tid 352036] [client 149.30.146.82:51511] ModSecurity: Access denied with code 403 (phase 1). Pattern match "^154\\\\.57\\\\.7\\\\.73$" at REQUEST_HEADERS:Host. [file "/etc/apache2/conf.d/modsec/modsec2.user.conf"] [line "155"] [id "9999001"] [msg "Direct incoming request to server shared IP blocked by admin"] [hostname "154.57.7.73"] [uri "/.env"] [unique_id "amO5a65cLIw_LMZ5LK5l4QAAA0M"]
show less
Port Scan
๐ซ๐ฎ
inlink.ltd
2026-07-24 18:42:49
(1 week ago)
dot file probe
Web App Attack
๐ฆ๐บ
paulshipley.com.au
2026-07-24 18:12:46
(1 week ago)
[Sat Jul 25 04:12:44.899109 2026] [security2:error] [pid 623465] [client 149.30.146.82:60480] [clien ...
show more
[Sat Jul 25 04:12:44.899109 2026] [security2:error] [pid 623465] [client 149.30.146.82:60480] [client 149.30.146.82] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "angleseaarthouse.com.au"] [uri "/.env"] [unique_id "amOrHFW0Bc8xpWc3exIOCwAAAAk"]
...
show less
Web App Attack