π©πͺ
todix
2026-07-19 20:13:27
(15 hours ago)
Web App Attack Exploid from 212.32.69.203
Web App Attack
π·πΊ
DZBOT
2026-07-19 20:07:14
(15 hours ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-19 20:06:05
(15 hours ago)
(mod_security) mod_security (id:949110) triggered by 212.32.69.203 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:949110) triggered by 212.32.69.203 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 19 16:06:01.304570 2026] [security2:error] [pid 2133753:tid 2133753] [client 212.32.69.203:56229] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "faithfoundationenterprise.com"] [uri "/.env"] [unique_id "al0uKYoUxZ0N1sGQft6u1gAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-19 19:48:48
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 212.32.69.203 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 212.32.69.203 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 19 15:48:42.115281 2026] [security2:error] [pid 10935:tid 10935] [client 212.32.69.203:57445] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "brodyworks.com"] [uri "/.env"] [unique_id "al0qGuEB1AU0Q3VqgjtFFAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-19 18:40:26
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 212.32.69.203 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 212.32.69.203 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 19 14:40:17.636267 2026] [security2:error] [pid 24743:tid 24753] [client 212.32.69.203:50381] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nourishmentofthesoul.org"] [uri "/.env"] [unique_id "al0aEapchObznMGtvfoF_QAAAUA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-19 18:21:14
(17 hours ago)
[ns1.skdns.gr] httpd-suspicious-path: iis-w3c
Hacking
Web App Attack
Anonymous
2026-07-19 18:04:04
(17 hours ago)
Bot / scanning and/or hacking attempts: GET /.env HTTP/1.1
Hacking
Web App Attack
π³π±
debestelapp
2026-07-19 17:40:07
(18 hours ago)
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-19 17:32:27
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 212.32.69.203 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 212.32.69.203 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 19 13:32:20.346853 2026] [security2:error] [pid 11181:tid 11181] [client 212.32.69.203:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "betiqos.com"] [uri "/.env"] [unique_id "al0KJGD5A8Uz4-zDLrU8CgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π±π»
garmtech.com
2026-07-19 17:28:08
(18 hours ago)
IM360 WAF: Direct access to sensitive file or dotfile MV:/.env
Web App Attack
π΅πΎ
armandosaucedo.me
2026-07-19 17:23:04
(18 hours ago)
Threat Intelligence via ARMTI, Web Attack: GET /.env
Web App Attack