🇩🇪
YF
2026-08-28 16:00:18
(1 day ago)
Environment file probe
Web App Attack
🇮🇱
spd.co.il
2026-08-20 17:02:02
(1 week ago)
Web application attack detected
Hacking
Web App Attack
🇩🇰
HostingGroup
2026-08-20 03:16:54
(1 week ago)
Automated malicious activity (Honeypot Trap) detected and blocked at the CDN edge by NordicCDN Shiel ...
show more
Automated malicious activity (Honeypot Trap) detected and blocked at the CDN edge by NordicCDN Shield. Offenses: 1. First blocked: 2026-08-20.
show less
Bad Web Bot
Web App Attack
Anonymous
2026-08-13 22:11:01
(2 weeks ago)
193.31.101.57 - - [14/Aug/2026:00:11:00 +0200] "GET /.env.test.local HTTP/1.1" 403 124 "-" "python-h ...
show more
193.31.101.57 - - [14/Aug/2026:00:11:00 +0200] "GET /.env.test.local HTTP/1.1" 403 124 "-" "python-httpx/0.28.1"
193.31.101.57 - - [14/Aug/2026:00:11:00 +0200] "GET /.env.testing HTTP/1.1" 403 124 "-" "python-httpx/0.28.1"
193.31.101.57 - - [14/Aug/2026:00:11:00 +0200] "GET /.env.ci HTTP/1.1" 403 124 "-" "python-httpx/0.28.1"
193.31.101.57 - - [14/Aug/2026:00:11:00 +0200] "GET /.env.dev.local HTTP/1.1" 403 124 "-" "python-httpx/0.28.1"
193.31.101.57 - - [14/Aug/2026:00:11:00 +0200] "GET /.env.staging.local HTTP/1.1" 403 124 "-" "python-httpx/0.28.1"
193.31.101.57 - - [14/Aug/2026:00:11:00 +0200] "GET /.env.staging HTTP/1.1" 403 124 "-" "python-httpx/0.28.1"
193.31.101.57 - - [14/Aug/2026:00:11:00 +0200] "GET /.env.production HTTP/1.1" 403 124 "-" "python-httpx/0.28.1"
193.31.101.57 - - [14/Aug/2026:00:11:00 +0200] "GET /.env.preview HTTP/1.1" 403 124 "-" "python-httpx/0.28.1"
193.31.101.57 - - [14/Aug/2026:00:11:00 +0200] "GET /.env.production.local HTTP/1.1" 403 124 "-" "python-httpx/
...
show less
Bad Web Bot
Web App Attack
🇮🇱
spd.co.il
2026-08-08 08:01:38
(3 weeks ago)
Web application attack detected
Hacking
Web App Attack
🇺🇸
kosada.com
2026-08-01 20:44:17
(4 weeks ago)
Web vulnerability probing: /.env.ci
Web App Attack
🇱🇻
garmtech.com
2026-06-20 14:19:00
(2 months ago)
IM360 WAF: Direct access to sensitive file or dotfile MV:/.env.production
Web App Attack
🇺🇸
TPI-Abuse
2026-06-19 03:59:31
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 193.31.101.57 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 193.31.101.57 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 18 23:59:27.829028 2026] [security2:error] [pid 16819:tid 16819] [client 193.31.101.57:37299] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "honeybeeawareness.com"] [uri "/.env.test.local"] [unique_id "ajS-n56pABZh4ZrhVK8sOAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-06-19 03:05:42
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 193.31.101.57 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 193.31.101.57 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 18 23:05:35.678317 2026] [security2:error] [pid 21763:tid 21795] [client 193.31.101.57:60605] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "southeastseal.com"] [uri "/.env.local"] [unique_id "ajSx_2bHMeDna3DmxslnbQAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇱🇻
garmtech.com
2026-06-18 17:11:49
(2 months ago)
IM360 WAF: Direct access to sensitive file or dotfile MV:/.env.local
Web App Attack
🇺🇸
mnsf
2026-06-14 00:05:45
(2 months ago)
Scanning/Probing (30)
Brute-Force
Web App Attack
🇺🇸
alecj.com
2026-06-12 13:48:49
(2 months ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇺🇸
mnsf
2026-06-06 23:05:29
(2 months ago)
Scanning/Probing (30)
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-06-06 15:17:53
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 193.31.101.57 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 193.31.101.57 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 06 11:17:47.711382 2026] [security2:error] [pid 3007:tid 3007] [client 193.31.101.57:35601] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "controlaltsuccess.com"] [uri "/.env.local"] [unique_id "aiQ6GypekMFVVREfMEEkoQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack