๐ฉ๐ช
Lunix
2026-10-03 14:33:11
(8 hours ago)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-03 09:23:49
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 20.42.98.202 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 20.42.98.202 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 03 05:23:42.450292 2026] [security2:error] [pid 21020:tid 21020] [client 20.42.98.202:51810] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "oualierealty.com"] [uri "/.env"] [unique_id "asDJngPAHOKwg03mpm5d2gAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-03 06:32:48
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 20.42.98.202 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 20.42.98.202 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 03 02:32:43.139396 2026] [security2:error] [pid 6618:tid 6618] [client 20.42.98.202:57002] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "skipspsaexchange.com"] [uri "/.env"] [unique_id "asChixcdf9SAdAGblv1gnQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
raph
2026-10-03 05:57:15
(17 hours ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-03 05:10:58
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 20.42.98.202 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 20.42.98.202 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 03 01:10:55.915887 2026] [security2:error] [pid 10856:tid 10880] [client 20.42.98.202:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ajbruner.com"] [uri "/.env"] [unique_id "asCOX4YHg3PTyiT6dMMKSwAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-10-03 04:02:53
(19 hours ago)
[03/Oct/2026:07:02:53 +0300] -- 20.42.98.202 Ban reason: User-Agent python-requests
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-03 01:24:09
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 20.42.98.202 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 20.42.98.202 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 21:24:04.291190 2026] [security2:error] [pid 25239:tid 25239] [client 20.42.98.202:55239] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "universitydental.org"] [uri "/.env"] [unique_id "asBZNNLISD4AkreWFSJ-HAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-03 01:13:35
(22 hours ago)
Web App Attack
Brute-Force
Exploited Host
Web App Attack
๐ณ๐ฑ
mieg
2026-10-03 01:06:56
(22 hours ago)
Web vulnerability probing
Brute-Force
Web App Attack
Anonymous
2026-10-02 23:38:02
(23 hours ago)
Bot / scanning and/or hacking attempts: GET /.env.prod HTTP/1.1, GET /.env.development HTTP/1.1
Hacking
Web App Attack
๐ฉ๐ช
mzaiser12
2026-10-02 22:29:22
(1 day ago)
Web application probing: 17 requests to typical attack paths (/.env.backup, /.env.bak, /.env.copy, / ...
show more
Web application probing: 17 requests to typical attack paths (/.env.backup, /.env.bak, /.env.copy, /.env) within 5 min. Reported automatically by a SIEM; contact via abuse mailbox of the reporting network.
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
Vegascosmetics
2026-10-02 17:25:52
(1 day ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after sensitive config/credentials exposure ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after sensitive config/credentials exposure probe. Evidence: AttackPattern: /\.env (Match: /.env)
show less
Hacking
Brute-Force
Web App Attack
๐ช๐ธ
elcruzado.es
2026-10-02 15:40:56
(1 day ago)
(mod_security) mod_security triggered on hostname [redacted] 20.42.98.202 (US/United States/-)
SQL Injection
๐ฉ๐ช
Viveronese
2026-10-02 15:00:13
(1 day ago)
HTTP vulnerability scanning
Web App Attack
๐จ๐ญ
zynex
2026-10-02 14:14:56
(1 day ago)
URL Probing: /.env
Web App Attack