Anonymous
2026-09-03 13:45:21
(1 day ago)
Observed scanned 1 known-sensitive endpoint(s), e.g.: /.env
Bad Web Bot
Web App Attack
🇬🇧
thetomtaylor.co.uk
2026-09-03 08:07:02
(1 day ago)
Fail2Ban - [WEB]Custom exploit pattern detected on customexploits ... [ice01,wa01,wa02]
Hacking
Brute-Force
Bad Web Bot
Web App Attack
🇭🇰
Mehmet_The_Script_Kiddie
2026-09-03 07:40:06
(1 day ago)
AUTOMATED REPORT: Tried to access .env file/.env
Bad Web Bot
Web App Attack
🇬🇧
thetomtaylor.co.uk
2026-09-03 07:08:00
(1 day ago)
Fail2Ban - [WEB]Custom exploit pattern detected on customexploits ... [ice02]
Hacking
Brute-Force
Bad Web Bot
Web App Attack
🇧🇬
Stoyko Stoykov
2026-09-03 06:54:36
(1 day ago)
212.32.69.200 - - [03/Sep/2026:09:54:36 +0300] "GET /.env HTTP/1.1" 301 162 "-" "Mozilla/5.0 (Macint ...
show more
212.32.69.200 - - [03/Sep/2026:09:54:36 +0300] "GET /.env HTTP/1.1" 301 162 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0"
...
show less
Hacking
Web App Attack
🇨🇦
Anytech
2026-09-03 06:43:10
(1 day ago)
Blocked by Conn-Monitor: env-probing
Web App Attack
Hacking
🇫🇮
000rosiu
2026-09-03 04:56:28
(1 day ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action: BLOCK | Protocol: HTTP/1.1 (GET) | Endpoi ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action: BLOCK | Protocol: HTTP/1.1 (GET) | Endpoint: /.env | UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0 • Generated by: github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-03 04:44:35
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 212.32.69.200 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 212.32.69.200 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 00:44:29.498315 2026] [security2:error] [pid 26002:tid 26002] [client 212.32.69.200:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "easy-byte.net"] [uri "/.env"] [unique_id "apj7LW-ywF1GFR7wUHflEgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇹🇷
oalver
2026-09-03 04:41:32
(1 day ago)
Detected by SiberKapan threat intelligence platform (siberkapan.org). Attack types: nginx_path_signa ...
show more
Detected by SiberKapan threat intelligence platform (siberkapan.org). Attack types: nginx_path_signature. Sources: nginx. Details: path_signature: request to /.env (HTTP 301). First seen: 2026-09-03. Risk score: 30/100.
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-03 04:18:21
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 212.32.69.200 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 212.32.69.200 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 00:18:15.202702 2026] [security2:error] [pid 1605052:tid 1605147] [client 212.32.69.200:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "earthtravel.net"] [uri "/.env"] [unique_id "apj1Bz6czfl9Og4BUlIhBQAAAMM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
BlueWire Hosting
2026-09-03 04:12:55
(1 day ago)
High-confidence malicious configuration/VCS probe
Web App Attack
🇭🇺
kranem
2026-09-03 03:00:25
(1 day ago)
Triggered Cloudflare WAF from US.
Action taken: BLOCK
ASN: 396356 (Latitude.sh)
Protocol: HTTP/1.1 ( ...
show more
Triggered Cloudflare WAF from US.
Action taken: BLOCK
ASN: 396356 (Latitude.sh)
Protocol: HTTP/1.1 (GET method)
Endpoint: /.env
Timestamp: 2026-09-03T01:36:22Z
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0
show less
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-03 02:59:25
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 212.32.69.200 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 212.32.69.200 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 22:59:18.586415 2026] [security2:error] [pid 18682:tid 18682] [client 212.32.69.200:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "uwsvita.org"] [uri "/.env"] [unique_id "apjihuAXHfVTDYEC_SC5zAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
Mundo Bueno
2026-09-03 02:30:01
(1 day ago)
[ISILIA Protection v2.1] Tentative d'accès: /.env | Pays: US | UA: Mozilla/5.0 (Macintosh; Intel Mac ...
show more
[ISILIA Protection v2.1] Tentative d'accès: /.env | Pays: US | UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0
show less
Hacking
Web App Attack
🇳🇱
MyGlobalFlowers
2026-09-03 02:11:43
(1 day ago)
Multiple WAF Violations
Web App Attack