πΊπΈ
PhilGoode
2026-09-20 04:22:36
(3 days ago)
HTTP web-application probing on TCP 80 requested /new/.env and /vendor/laravel/.env. Observed by a w ...
show more
HTTP web-application probing on TCP 80 requested /new/.env and /vendor/laravel/.env. Observed by a web honeypot.
show less
Web App Attack
πΊπΈ
wbsouza
2026-09-20 03:40:50
(3 days ago)
CrowdSec: infra/bad-path-probe β automated firewall drops on self-hosted IDS sensor
Hacking
πΊπΈ
technojoe99
2026-09-20 03:30:39
(3 days ago)
Exploit scan from 213.254.175.140. GET /public/.env HTTP/1.1.
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-19 19:45:05
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.140 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.140 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 15:44:49.406467 2026] [security2:error] [pid 30558:tid 30558] [client 213.254.175.140:63513] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.57"] [uri "/app/config/.env"] [unique_id "aq7mMa6bt9tDKRHTeYXU3gAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-19 08:04:34
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.140 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.140 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 04:04:26.741924 2026] [security2:error] [pid 5925:tid 5925] [client 213.254.175.140:31131] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.250"] [uri "/.env"] [unique_id "aq5CCnB-YQboRCgN7G6BLgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
β¨
2026-09-19 00:10:09
(4 days ago)
Domain : redirect.netenergy.uk
Rule : env
2026-09-19 00:08:10 217.194.210.152 GET /audio/.env - 80 - ...
show more
Domain : redirect.netenergy.uk
Rule : env
2026-09-19 00:08:10 217.194.210.152 GET /audio/.env - 80 - 213.254.175.140 HTTP/1.1 Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36 - 217.194.210.152 404 0 2 1503 236 127 - -
show less
Hacking
SQL Injection
πΊπΈ
TPI-Abuse
2026-09-18 11:32:44
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.140 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.140 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 18 07:32:27.410482 2026] [security2:error] [pid 1124:tid 1148] [client 213.254.175.140:55095] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.80"] [uri "/storage/.env"] [unique_id "aq0hSzHi_ey7GSglmDDyngAAAMo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
Lino Project
2026-09-18 09:59:16
(5 days ago)
213.254.175.140 - - [18/Sep/2026:11:59:16 +0200] "GET /vendor/.env HTTP/1.1" 404 397 "-" "Mozilla/5. ...
show more
213.254.175.140 - - [18/Sep/2026:11:59:16 +0200] "GET /vendor/.env HTTP/1.1" 404 397 "-" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-18 07:27:44
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.140 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.140 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 18 03:27:26.944264 2026] [security2:error] [pid 27528:tid 27528] [client 213.254.175.140:56727] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.242"] [uri "/public/.env"] [unique_id "aqzn3mlSZiFACJWdoM4NogAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-17 12:29:44
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.140 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.140 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 08:29:40.273164 2026] [security2:error] [pid 4809:tid 4809] [client 213.254.175.140:22637] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.190"] [uri "/.env"] [unique_id "aqvdNI6eJQ61ZeJBwlvmOwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-17 10:45:25
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.140 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.140 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 06:45:08.840890 2026] [security2:error] [pid 31558:tid 31558] [client 213.254.175.140:40621] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.36"] [uri "/newsite/.env"] [unique_id "aqvEtAELs-_o3GKA64bxzQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
bescared
2026-09-17 07:20:02
(6 days ago)
F2B - Malicious activity detected. URL Probing. -151302cd-
Hacking
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-17 04:58:58
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.140 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.140 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 00:58:50.616927 2026] [security2:error] [pid 14188:tid 14285] [client 213.254.175.140:51935] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.201"] [uri "/web201.dnchosting.com/.env"] [unique_id "aqtzilzWrjP-0_ynNOHzIgAAAcw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
Starburst SysOp Team
2026-09-17 02:39:01
(6 days ago)
Host header is a numeric IP address. Pattern match "(?:^( (920350-mnz6-1)
Hacking
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-09-17 01:10:39
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.140 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.140 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 21:10:00.873368 2026] [security2:error] [pid 24467:tid 24467] [client 213.254.175.140:42635] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.162"] [uri "/local/.env"] [unique_id "aqs96CdfYh-DqLlKYVpjSwAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack