Anonymous
2026-06-12 11:25:05
(2 hours ago)
Bot / scanning and/or hacking attempts: GET /admin/.env HTTP/1.1
Hacking
Web App Attack
๐ฎ๐น
Inartis
2026-06-12 10:59:22
(2 hours ago)
185.30.32.32 - - [12/Jun/2026:12:59:21 +0200] "GET /.env.save HTTP/1.1" 403 4992 "-" "Mozilla/5.0 (M ...
show more
185.30.32.32 - - [12/Jun/2026:12:59:21 +0200] "GET /.env.save HTTP/1.1" 403 4992 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-06-12 10:31:33
(3 hours ago)
URL file extension is restricted by policy. String match within ".ani/ .asa/ .asax/ .ascx/ .back/ .b ...
show more
URL file extension is restricted by policy. String match within ".ani/ .asa/ .asax/ .ascx/ .back/ .backup/ .bak/ .bck/ .bk/ .bkp/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .cnf/ .com/ .compositefont/ .config/ .conf/ .copy/ .crt/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dist/ .dll/ .dos/ .dpkg-dist/ .drv/ .gadget/ .hta/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .inf/ .ini/ .jks/ .jse/ .key/ .licx/ .lnk/ .log/ .mdb/ .msc/ .ocx/ .old/ .pass/ .pdb/ .pfx/ .pif/ .pem/ .pol/ .prf/ .printer/ .pwd/ .rdb/ .rdp/ .reg/ .resources/ .resx/ .sav/ .save/ .scr/ .sct/ .sh/ .shs/ .sql/ .sqlite/ .sqlite3/ .swap/ .swo/ .swp/ .sys/ .temp/ .tfstate/ .tlb/ .tmp/ .vb/ .vbe/ .vbs/ .vbproj/ .vsdisco/ .vxd/ .webinfo/ .ws/ .wsc/ .wsf/ .wsh/ .xsd/ .xsx/" at TX:extension. (920440-193)
show less
Hacking
Anonymous
2026-06-12 10:10:02
(3 hours ago)
suspicious request in access.log
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-12 09:50:15
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 185.30.32.32 (server32.webgo24.de): 1 in the la ...
show more
(mod_security) mod_security (id:210492) triggered by 185.30.32.32 (server32.webgo24.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 12 05:50:08.758677 2026] [security2:error] [pid 14338:tid 14338] [client 185.30.32.32:47918] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mastersonsmotel.ca"] [uri "/api/.env"] [unique_id "aivWUNoixVvNV_CAdLzK0wAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
zynex
2026-06-12 09:24:46
(4 hours ago)
URL Probing: /.env
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-12 09:15:13
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 185.30.32.32 (server32.webgo24.de): 1 in the la ...
show more
(mod_security) mod_security (id:210492) triggered by 185.30.32.32 (server32.webgo24.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 12 05:15:08.255453 2026] [security2:error] [pid 19722:tid 19722] [client 185.30.32.32:42238] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "smogsandiego.com"] [uri "/api/.env.save"] [unique_id "aivOHKJHSAonRVwtXDRyygAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-12 06:32:08
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 185.30.32.32 (server32.webgo24.de): 1 in the la ...
show more
(mod_security) mod_security (id:210492) triggered by 185.30.32.32 (server32.webgo24.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 12 02:32:00.130581 2026] [security2:error] [pid 12566:tid 12707] [client 185.30.32.32:39012] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "chadcentral.com"] [uri "/api/.env.save"] [unique_id "aiun4FS3zKTtb767TgsNUgAAAdM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-06-12 06:31:02
(7 hours ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-195)
Hacking
Web App Attack
๐ฉ๐ช
4server
2026-06-12 05:55:35
(7 hours ago)
[FriJun1207:55:30.6054132026][security2:error][pid3201500:tid3201612][client185.30.32.32:0]ModSecuri ...
show more
[FriJun1207:55:30.6054132026][security2:error][pid3201500:tid3201612][client185.30.32.32:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"\(\?:\\\\\\\\b\(\?:\\\\\\\\.\(\?:ht\(\?:access\|passwd\|group\)\|www_\?acl\)\|global\\\\\\\\.asa\|httpd\\\\\\\\.conf\|boot\\\\\\\\.ini\|web.config\)\\\\\\\\b\|\(\|\^\|\\\\\\\\.\\\\\\\\.\)/etc/\|/\\\\\\\\.\(\?:history\|bash_history\|sh_history\|env\)\$\)\"atREQUEST_FILENAME.[file\"/etc/apache2/conf.d/modsec_rules/10_asl_rules.conf\"][line\"204\"][id\"390709\"][rev\"30\"][msg\"Atomicorp.comWAFRules:Attempttoaccessprotectedfileremotely\"][data\"/.env\"][severity\"CRITICAL\"][hostname\"cst-ranghetti.ch\"][uri\"/laravel/.env\"][unique_id\"aiufUiSTBBr5W7EQH2MhyAAAAQs\"]
show less
Port Scan
Brute-Force
Web App Attack
๐ท๐บ
DZBOT
2026-06-12 05:49:40
(8 hours ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐ฎ๐ฉ
Burayot
2026-06-12 05:47:16
(8 hours ago)
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 185.30.32.32 (DE/Germany/server32.we ...
show more
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 185.30.32.32 (DE/Germany/server32.webgo24.de): 1 in the last 3600 secs
show less
Web App Attack
๐ง๐ช
cmbplf
2026-06-12 05:38:04
(8 hours ago)
594 requests with url.path *.env
Brute-Force
Bad Web Bot
๐ซ๐ฎ
xyz.rip
2026-06-12 05:29:55
(8 hours ago)
WAF Violation
...
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-12 03:12:31
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 185.30.32.32 (server32.webgo24.de): 1 in the la ...
show more
(mod_security) mod_security (id:210492) triggered by 185.30.32.32 (server32.webgo24.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 11 23:12:26.424764 2026] [security2:error] [pid 10516:tid 10516] [client 185.30.32.32:37066] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gilbertortegajewelry.com"] [uri "/.env.save"] [unique_id "ait5GpgMWX5NVkJYvpRZeQAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack