๐ฉ๐ช
NewGastroline
2026-05-16 07:26:19
(2 weeks ago)
Malicious request blocked by CrowdSec on gastro-prod1.boreus.de
Bad Web Bot
Web App Attack
๐ง๐ช
voormedia
2026-05-16 07:18:44
(2 weeks ago)
Accessed trap at '/.env'
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-16 06:37:44
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 208.84.100.71 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 208.84.100.71 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 16 02:37:38.899317 2026] [security2:error] [pid 16450:tid 16450] [client 208.84.100.71:45152] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thresholddigital.com"] [uri "/.env"] [unique_id "aggQsrVCt2wT88z9O6DDggAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
CrystalMaker
2026-05-16 06:25:35
(2 weeks ago)
Wordpress attack - GET /serviceAccountKey.json; GET /service-account.json; GET /.env.local; GET /sec ...
show more
Wordpress attack - GET /serviceAccountKey.json; GET /service-account.json; GET /.env.local; GET /secrets.json; GET /credentials.json; GET /api/.env; GET /backend/.env; GET /google-service-account.json; GET /app/.env; GET /.env; GET /.env.production; GET /.aws/credentials; GET /firebase-service-account.json; GET /.env.production.copy; GET /.env~; GET /.env.local~; GET /.env.swp; GET /.env.bak; GET /.env.production.backup; GET /.env.local.backup; GET /.env.local.old; GET /.env.copy; GET /.env.local.copy; GET /.env.local.swp; GET /.env.local.bak; GET /.env.orig; GET /.env.save; GET /.git/logs/HEAD; GET /.env.local.orig; GET /.env.production.bak; GET /.git/refs/heads/main; GET /.git/FETCH_HEAD; GET /.git/refs/heads/master; GET /.git/HEAD; GET /.env.old; GET /.git/config; GET /.env.backup; GET /.env.production.old; GET /.env.production.save; GET /.env.production~; GET /.env.production.swp; GET /.env.local.save; GET /.env.production.orig
show less
Web App Attack
๐ท๐ด
iulianh
2026-05-16 05:50:53
(2 weeks ago)
*
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-05-16 05:31:02
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 208.84.100.71 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 208.84.100.71 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 16 01:30:56.779905 2026] [security2:error] [pid 29790:tid 29790] [client 208.84.100.71:58306] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "chaubaolau.com"] [uri "/.env"] [unique_id "aggBEE5TVxHO-O0TzUhH4gAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
openstrike.co.uk
2026-05-16 05:14:52
(2 weeks ago)
68 attacks on password grabbing URLs, config grabbing URLs (type 2), VC URLs, env grabbing URLs:
GET ...
show more
68 attacks on password grabbing URLs, config grabbing URLs (type 2), VC URLs, env grabbing URLs:
GET /.aws/credentials HTTP/1.1
GET /secrets.json HTTP/1.1
GET /.git/config HTTP/1.1
GET /.env.production.orig HTTP/1.1
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-05-16 05:11:49
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 208.84.100.71 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 208.84.100.71 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 16 01:11:45.034476 2026] [security2:error] [pid 7373:tid 7373] [client 208.84.100.71:1188] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tecnoconce.com"] [uri "/.env"] [unique_id "agf8kewBfHMn0vGZNcp97gAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-16 04:55:48
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 208.84.100.71 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 208.84.100.71 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 16 00:55:42.004513 2026] [security2:error] [pid 22520:tid 22520] [client 208.84.100.71:19030] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gfsprod.com"] [uri "/api/.env"] [unique_id "agf4zrWVFC9D2N12NoNKkwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-16 04:20:46
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 208.84.100.71 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 208.84.100.71 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 16 00:20:40.603618 2026] [security2:error] [pid 5015:tid 5015] [client 208.84.100.71:57820] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fabulouswire.net"] [uri "/.env"] [unique_id "agfwmFxI2laT57iaA_zWNAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
netclix.gr
2026-05-16 04:11:40
(2 weeks ago)
(mod_security) mod_security triggered on hostname [redacted] 208.84.100.71 (US/United States/-): (C ...
show more
(mod_security) mod_security triggered on hostname [redacted] 208.84.100.71 (US/United States/-): (CF_ENABLE)
show less
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-05-16 04:00:52
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 208.84.100.71 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 208.84.100.71 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 16 00:00:47.367120 2026] [security2:error] [pid 3838:tid 3949] [client 208.84.100.71:64488] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mouserart.com"] [uri "/app/.env"] [unique_id "agfr7zGzORduN-LqHO5d_AAAANM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-16 03:33:58
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 208.84.100.71 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 208.84.100.71 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 23:33:52.678368 2026] [security2:error] [pid 31469:tid 31469] [client 208.84.100.71:58562] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "schonar.com"] [uri "/app/.env"] [unique_id "agfloHvY57bHV-29IuyckgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
paulshipley.com.au
2026-05-16 02:52:22
(2 weeks ago)
balcomberetreat.com.au:443 208.84.100.71 - - [16/May/2026:12:52:18 +1000] "GET /credentials.json HTT ...
show more
balcomberetreat.com.au:443 208.84.100.71 - - [16/May/2026:12:52:18 +1000] "GET /credentials.json HTTP/1.1" 404 75241 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Safari/537.36"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-16 02:40:26
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 208.84.100.71 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 208.84.100.71 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 22:40:20.055247 2026] [security2:error] [pid 24700:tid 24700] [client 208.84.100.71:29008] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bisbyphotography.com"] [uri "/api/.env"] [unique_id "agfZFLvgFMjcwk3N3z3a1AAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack