Anonymous
2026-08-26 01:06:02
(1 day ago)
Bot / scanning and/or hacking attempts: GET /.env.php HTTP/1.1
Hacking
Web App Attack
๐บ๐ธ
ANTI SCANNER
2026-08-25 23:09:52
(1 day ago)
Scanner : /.env.save
Web Spam
๐ฉ๐ช
Gwyneth Llewelyn
2026-08-25 20:03:33
(1 day ago)
2026/08/25 21:03:27 [error] 380594#380594: *536601 access forbidden by rule, client: 196.115.28.254, ...
show more
2026/08/25 21:03:27 [error] 380594#380594: *536601 access forbidden by rule, client: 196.115.28.254, server: alzulej.pt, request: "GET /.env HTTP/2.0", host: "alzulej.pt"
196.115.28.254 - - [25/Aug/2026:21:03:27 +0100] "GET /.env HTTP/2.0" 403 1045 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36"
2026/08/25 21:03:31 [error] 380594#380594: *536616 access forbidden by rule, client: 196.115.28.254, server: alzulej.pt, request: "GET /.env HTTP/2.0", host: "alzulej.pt"
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-25 19:10:31
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 196.115.28.254 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 196.115.28.254 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 15:10:26.400147 2026] [security2:error] [pid 5858:tid 5858] [client 196.115.28.254:57354] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "asermaq.cl"] [uri "/.env"] [unique_id "ao3oosc8Ejz7L8gy2Q9n1AAAADQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
elcruzado.es
2026-08-25 18:49:06
(1 day ago)
(mod_security) mod_security triggered on hostname [redacted] 196.115.28.254 (MA/Morocco/-)
SQL Injection
๐ง๐ช
voormedia
2026-08-25 18:29:35
(1 day ago)
Accessed trap at '/.env'
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-25 18:09:04
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 196.115.28.254 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 196.115.28.254 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 14:08:59.724940 2026] [security2:error] [pid 1855:tid 1855] [client 196.115.28.254:46496] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "3rdid7thinf.org"] [uri "/.env"] [unique_id "ao3aO4dlheVIDj8UTN1oIgAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Catalin Negru
2026-08-25 16:39:42
(1 day ago)
Recidive ban by fail2ban on server.blackbit.ro
Brute-Force
๐บ๐ธ
dtorrer
2026-08-25 15:46:19
(1 day ago)
General vulnerability scan.
Port Scan
๐บ๐ธ
TPI-Abuse
2026-08-25 14:24:22
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 196.115.28.254 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 196.115.28.254 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 10:24:18.340624 2026] [security2:error] [pid 15260:tid 15260] [client 196.115.28.254:28699] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "3905ccn.org"] [uri "/.env"] [unique_id "ao2lki0q6QFjtNj4W2DvrwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ท๐ด
clauss
2026-08-25 13:58:56
(1 day ago)
196.115.28.254 - - [25/Aug/2026:16:58:47 +0300] "GET /phpinfo HTTP/2.0" 301 0 "-" "Mozilla/5.0 (Wind ...
show more
196.115.28.254 - - [25/Aug/2026:16:58:47 +0300] "GET /phpinfo HTTP/2.0" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36"
196.115.28.254 - - [25/Aug/2026:16:58:55 +0300] "GET /phpinfo.php HTTP/2.0" 404 20 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36"
...
show less
Web App Attack
๐ซ๐ท
thilo
2026-08-25 12:35:35
(1 day ago)
Probe for vulnerabilities. Path attempted: /.env.save
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-25 12:10:13
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 196.115.28.254 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 196.115.28.254 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 08:10:06.468215 2026] [security2:error] [pid 18385:tid 18385] [client 196.115.28.254:8545] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "34thprs.org"] [uri "/.env"] [unique_id "ao2GHoOb_sSYxl2ldHKucwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
Some Body
2026-08-25 11:29:21
(2 days ago)
Aggressive web scan
Brute-Force
Web App Attack
Anonymous
2026-08-25 09:51:34
(2 days ago)
196.115.28.254 - - [25/Aug/2026:11:50:55 +0200] "GET /.env HTTP/1.1" 402 861 "-" "Mozilla/5.0 (Windo ...
show more
196.115.28.254 - - [25/Aug/2026:11:50:55 +0200] "GET /.env HTTP/1.1" 402 861 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36" ...
show less
Web App Attack