๐จ๐ฟ
ptlab
2026-08-30 12:45:40
(2 days ago)
Detected env_leak attack from WP-host.
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-30 12:44:07
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 20.80.12.118 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 20.80.12.118 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 30 08:44:01.797823 2026] [security2:error] [pid 1529267:tid 1529330] [client 20.80.12.118:53182] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "seips.org"] [uri "/.env"] [unique_id "apQlkZ4rCD7dAzHyRdjZVwAAAJY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
voormedia
2026-08-30 11:52:58
(2 days ago)
Accessed trap at '/.env'
Web App Attack
๐จ๐ฆ
Mediashaker
2026-08-30 11:50:55
(2 days ago)
(apache-scanners) Failed apache-scanners trigger with match [redacted] from 20.80.12.118 (US/United ...
show more
(apache-scanners) Failed apache-scanners trigger with match [redacted] from 20.80.12.118 (US/United States/-)
show less
Port Scan
๐ฉ๐ช
LRob
2026-08-30 11:27:50
(2 days ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.env | 2026-08-30 11:27 UTC
show less
Hacking
Web App Attack
๐ฟ๐ฆ
simon boshoff
2026-08-30 11:16:25
(2 days ago)
RdpGuard detected brute-force attempt on HTTP
Brute-Force
๐ธ๐ฌ
securejdprop
2026-08-30 10:36:02
(2 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/suricata-major-severity(ET INFO Request to ...
show more
This IP was detected by CrowdSec triggering crowdsecurity/suricata-major-severity(ET INFO Request to Hidden Environment File - Inbound).
show less
Hacking
Web App Attack
๐บ๐ธ
ipblock.com
2026-08-30 10:29:00
(2 days ago)
IPBlock protected site ID [4055-d][s=07].
Exploit request, vulnerability scanner.
Hacking
Bad Web Bot
Web App Attack
๐ณ๐ฑ
informedclearly.com
2026-08-30 10:06:43
(2 days ago)
WAF_BAN reason=ENV_PROBE rule=ENV_PATH hits=1 path=/.env? ua=Mozilla/5.0 (Windows NT 10.0; Win64; x6 ...
show more
WAF_BAN reason=ENV_PROBE rule=ENV_PATH hits=1 path=/.env? ua=Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36 Edg/120.
show less
Hacking
๐บ๐ธ
mnsf
2026-08-30 10:06:30
(2 days ago)
Scanning/Probing (12)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-30 10:03:39
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 20.80.12.118 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 20.80.12.118 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 30 06:03:35.602864 2026] [security2:error] [pid 4510:tid 4510] [client 20.80.12.118:62578] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "socialstudiesforkids.com"] [uri "/.env"] [unique_id "apP_9xjo8UZFQQrRN0rIBAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-08-30 10:01:42
(2 days ago)
Multiple WAF Violations
Web App Attack
๐ฎ๐น
VHosting
2026-08-30 09:50:04
(2 days ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐ช๐ธ
el-brujo
2026-08-30 09:42:48
(2 days ago)
20.80.12.118 - - [30/Aug/2026:11:42:46 +0200] "GET /.env.local?m=1 HTTP/2.0" 404 16044 "-" "Mozilla/ ...
show more
20.80.12.118 - - [30/Aug/2026:11:42:46 +0200] "GET /.env.local?m=1 HTTP/2.0" 404 16044 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Mobile Safari/537.36"
20.80.12.118 - - [30/Aug/2026:11:42:46 +0200] "GET /.env.production HTTP/2.0" 404 16044 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:109.0) Gecko/20100101 Firefox/121.0"
20.80.12.118 - - [30/Aug/2026:11:42:47 +0200] "GET /.env.example?m=1 HTTP/2.0" 404 16044 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_2 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.2 Mobile/15E148 Safari/605.1.15"
...
show less
DDoS Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-30 09:27:45
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 20.80.12.118 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 20.80.12.118 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 30 05:27:38.887975 2026] [security2:error] [pid 15709:tid 15709] [client 20.80.12.118:60774] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "individualhealth.com"] [uri "/.env"] [unique_id "apP3iqbVVrhZW0Ev0Wy28AAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack