Anonymous
2026-08-22 10:24:04
(1 week ago)
212.32.69.33 - - [22/Aug/2026:18:24:03 +0800] "GET /.env HTTP/1.1" 200 19012 "-" "Mozilla/5.0 (Macin ...
show more
212.32.69.33 - - [22/Aug/2026:18:24:03 +0800] "GET /.env HTTP/1.1" 200 19012 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
RH5
2026-08-22 09:30:27
(1 week ago)
Restricted URL probing (/.env) (UTC 2026-08-22 09:30)
Web App Attack
๐ฉ๐ช
Vegascosmetics
2026-08-22 09:27:37
(1 week ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after sensitive config/credentials exposure ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after sensitive config/credentials exposure probe. Evidence: AttackPattern: /\.env (Match: /.env)
show less
Hacking
Brute-Force
Web App Attack
Anonymous
2026-08-22 09:26:17
(1 week ago)
http scanning for .env files
...
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-22 09:25:45
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 212.32.69.33 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 212.32.69.33 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 05:25:38.199861 2026] [security2:error] [pid 28118:tid 28118] [client 212.32.69.33:28129] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "davidlbennett.com"] [uri "/.env"] [unique_id "aolrEiimhxxh92FWl3rTXQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
Anytech
2026-08-22 09:20:37
(1 week ago)
Blocked by Conn-Monitor: env-probing
Web App Attack
Hacking
๐บ๐ธ
ambor
2026-08-22 09:15:57
(1 week ago)
Honeypot access: Environment file access attempt. Path: /.env
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-22 08:56:09
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 212.32.69.33 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 212.32.69.33 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 04:56:02.684148 2026] [security2:error] [pid 28928:tid 28928] [client 212.32.69.33:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "chaitanyaconsult.in"] [uri "/.env"] [unique_id "aolkIijosksGJ9BMGVo-8wAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-22 08:29:50
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 212.32.69.33 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 212.32.69.33 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 04:29:42.853644 2026] [security2:error] [pid 4506:tid 4506] [client 212.32.69.33:55389] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "albertmassaad.com"] [uri "/.env"] [unique_id "aold9uafYA0pfRbwxj54ngAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
bryth
2026-08-22 07:34:44
(1 week ago)
Wordpress login/xmlrpc abuse (Sat Aug 22 07:17:58 AM UTC 2026)
Hacking
Web App Attack
๐ต๐ฑ
nakordoni.eu
2026-08-22 07:30:05
(1 week ago)
Blocked by nakordoni.eu automated security: nakordoni-probe-gate. Jail: nakordoni-probe-gate, 1 matc ...
show more
Blocked by nakordoni.eu automated security: nakordoni-probe-gate. Jail: nakordoni-probe-gate, 1 matches. ISP: VPN Consumer Dallas, United States of America (US), Usage: Data Center/Web Hosting/Transit. Prior AbuseIPDB score at ban time: 57/100.
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
TheDjRider
2026-08-22 07:25:28
(1 week ago)
CrowdSec detected Web application reconnaissance. Scenario: local/framework-recon. Automatic ban tri ...
show more
CrowdSec detected Web application reconnaissance. Scenario: local/framework-recon. Automatic ban triggered. Detection time (UTC): 2026-08-22T07:25:26.686305045Z. Context: http_status=404
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-22 07:22:51
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 212.32.69.33 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 212.32.69.33 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 03:22:46.679826 2026] [security2:error] [pid 19114:tid 19114] [client 212.32.69.33:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "totalsafe-security.com"] [uri "/.env"] [unique_id "aolORknoguptlSRE4GBiaAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
kie
2026-08-22 07:02:52
(1 week ago)
22-08-2026:07:01:58UTC [Nginx Web Server] Suspicious web request: path:/.env (1 request(s)).
Bad Web Bot
Web App Attack
๐ซ๐ท
Baking333
2026-08-22 06:46:37
(1 week ago)
[redacted] 212.32.69.33 - - [22/Aug/2026:07:46:35 +0100] "GET /.env HTTP/2.0" 301 291 "-" "Mozilla/5 ...
show more
[redacted] 212.32.69.33 - - [22/Aug/2026:07:46:35 +0100] "GET /.env HTTP/2.0" 301 291 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0" [redacted] 212.32.69.33 - - [22/Aug/2026:07:46:35 +0100] "GET /fr/.env/ HTTP/2.0" 404 34451 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0"
show less
Bad Web Bot
Web App Attack