๐ธ๐ช
vaia.cloud
2026-08-28 13:55:03
(5 hours ago)
crowdsecurity/http-probing
Brute-Force
Web App Attack
๐ช๐ธ
elcruzado.es
2026-08-28 13:32:46
(5 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 196.74.180.72 (MA/Morocco/-)
SQL Injection
๐ฉ๐ช
brechtr
2026-08-28 13:22:57
(5 hours ago)
[Press84-BanHammer] 404 flood โ 30 hits in 60s โ Sourced from: www.langsvlaamsewegen.be โ Request: G ...
show more
[Press84-BanHammer] 404 flood โ 30 hits in 60s โ Sourced from: www.langsvlaamsewegen.be โ Request: GET /main/.env
show less
Bad Web Bot
Web App Attack
๐จ๐ญ
zynex
2026-08-28 13:22:40
(5 hours ago)
URL Probing: /assets/.env
Web App Attack
๐ณ๐ฑ
Savvii
2026-08-28 13:13:02
(6 hours ago)
20 attempts against mh-misbehave-ban on pyrus
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
pipeline.es
2026-08-28 13:06:22
(6 hours ago)
Web scanning / probing for vulnerable paths | URL: /.env.php | Evidence: viajesabreu.es 196.74.180.7 ...
show more
Web scanning / probing for vulnerable paths | URL: /.env.php | Evidence: viajesabreu.es 196.74.180.72 - - [28/Aug/2026:15:05:06 +0200] \"GET /.env.php HTTP/1.1\" 404 21791 \"-\" \"Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36\" GEOIP_COUNTRY_CODE=MA | ASN: MT-MPLS | Country: MA
show less
Port Scan
Web App Attack
Anonymous
2026-08-28 12:11:36
(7 hours ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 00:08:30
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 196.74.180.72 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 196.74.180.72 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 20:08:24.625911 2026] [security2:error] [pid 16311:tid 16311] [client 196.74.180.72:61316] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "portalvasco.com"] [uri "/app/.env"] [unique_id "apDReNWAVq4ZjUS0majvzgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
todix
2026-08-28 00:01:03
(19 hours ago)
WebAttack or semilar from 196.74.180.72
Web App Attack
Anonymous
2026-08-28 00:00:09
(19 hours ago)
suspicious request in access.log
Web App Attack
๐ซ๐ท
rellik
2026-08-27 23:35:00
(19 hours ago)
Brute Force Scanning Critical Directories
Hacking
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 23:30:48
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 196.74.180.72 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 196.74.180.72 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 19:30:43.651279 2026] [security2:error] [pid 13367:tid 13367] [client 196.74.180.72:49758] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "infojeffreysbay.com"] [uri "/.env.local"] [unique_id "apDIo1tDn-2NxYqyS9YDIgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-08-27 23:13:46
(20 hours ago)
Try to access /.env
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 22:59:23
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 196.74.180.72 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 196.74.180.72 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 18:59:15.999862 2026] [security2:error] [pid 9508:tid 9508] [client 196.74.180.72:49996] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "laboquimia.es"] [uri "/.env.sample"] [unique_id "apDBQ__VMI-PfIX8BfwygQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 22:26:36
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 196.74.180.72 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 196.74.180.72 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 18:26:31.793218 2026] [security2:error] [pid 18658:tid 18658] [client 196.74.180.72:50876] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "brinkworthmodels.com"] [uri "/app/.env"] [unique_id "apC5l17X4S6ssBY51XCcqAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack