Anonymous
2026-07-27 12:09:59
(3 hours ago)
216.81.248.107 - - [27/Jul/2026:12:09:59 +0000] "GET /.env.bak HTTP/1.1" 404 3049 "-" "Mozilla/5.0 ( ...
show more
216.81.248.107 - - [27/Jul/2026:12:09:59 +0000] "GET /.env.bak HTTP/1.1" 404 3049 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/42.0.2311.135 Safari/537.36 Edge/12.246"
...
show less
Brute-Force
Web App Attack
๐ง๐ช
voormedia
2026-07-27 11:22:10
(4 hours ago)
Accessed trap at '/.env'
Web App Attack
๐ฉ๐ช
33three
2026-07-27 11:08:46
(4 hours ago)
Fail2Ban jail WebAttack triggered
Brute-Force
๐จ๐ฆ
Mediashaker
2026-07-27 09:59:30
(5 hours ago)
(apache-scanners) Failed apache-scanners trigger with match [redacted] from 216.81.248.107 (US/Unite ...
show more
(apache-scanners) Failed apache-scanners trigger with match [redacted] from 216.81.248.107 (US/United States/ip107.kcy.lh-nap.net)
show less
Port Scan
๐ธ๐ช
vaia.cloud
2026-07-27 09:50:02
(5 hours ago)
crowdsecurity/CVE-2017-9841
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 00:28:49
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 216.81.248.107 (ip107.kcy.lh-nap.net): 1 in the ...
show more
(mod_security) mod_security (id:210492) triggered by 216.81.248.107 (ip107.kcy.lh-nap.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 26 20:28:41.805051 2026] [security2:error] [pid 7416:tid 7416] [client 216.81.248.107:49032] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lmga.net"] [uri "/.env.bak"] [unique_id "amamOWGD0M6rExmky35XSgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฒ๐พ
Rizzy
2026-07-27 00:23:13
(15 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐ฑ๐ป
garmtech.com
2026-07-27 00:13:17
(15 hours ago)
IM360 WAF: Direct access to sensitive file or dotfile MV:/.env.local
Web App Attack
๐ฑ๐ป
garmtech.com
2026-07-26 23:55:17
(15 hours ago)
IM360 WAF: PrestaShop PHPUnit Arbitrary Code Execution vulnerability (CVE-2017-9841) MV:<?php phpinf ...
show more
IM360 WAF: PrestaShop PHPUnit Arbitrary Code Execution vulnerability (CVE-2017-9841) MV:<?php phpinfo();
show less
Web App Attack
๐บ๐ธ
IndigoRidge
2026-07-26 20:03:34
(19 hours ago)
216.81.248.107 - - [26/Jul/2026:16:03:29 -0400] "GET /.env HTTP/1.0" 301 4879 "-" "Mozilla/5.0 (Wind ...
show more
216.81.248.107 - - [26/Jul/2026:16:03:29 -0400] "GET /.env HTTP/1.0" 301 4879 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/42.0.2311.135 Safari/537.36 Edge/12.246"
216.81.248.107 - - [26/Jul/2026:16:03:29 -0400] "GET /.env HTTP/1.0" 404 48937 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/42.0.2311.135 Safari/537.36 Edge/12.246"
216.81.248.107 - - [26/Jul/2026:16:03:33 -0400] "GET /account/.env HTTP/1.0" 301 4887 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/42.0.2311.135 Safari/537.36 Edge/12.246"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-26 19:50:33
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 216.81.248.107 (ip107.kcy.lh-nap.net): 1 in the ...
show more
(mod_security) mod_security (id:210492) triggered by 216.81.248.107 (ip107.kcy.lh-nap.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 26 15:50:28.106401 2026] [security2:error] [pid 4054505:tid 4054505] [client 216.81.248.107:47844] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "livingwaterresortandspa.com"] [uri "/.env.bak"] [unique_id "amZlBM9EYR_siBPOHHIbCgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
maxpower
2026-07-26 19:43:10
(20 hours ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 216.81.248.107 (US/United States/ip107.k ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 216.81.248.107 (US/United States/ip107.kcy.lh-nap.net): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 216.81.248.107 - - [26/Jul/2026:21:43:06 +0200] "POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/2.0" 403 207 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:75.0) Gecko/20100101 Firefox/75.0" "216.81.248.107" host=liverpoolitalia.it
show less
Port Scan
๐ซ๐ท
dynamix
2026-07-26 19:25:23
(20 hours ago)
Multiple WAF Violations
Web App Attack
๐ซ๐ท
Octopuce
2026-07-26 19:24:36
(20 hours ago)
Aggressive web search of vulnerable pages: /.env.local /.env /account/.env /projects/.env /project/. ...
show more
Aggressive web search of vulnerable pages: /.env.local /.env /account/.env /projects/.env /project/.env ...
show less
Web App Attack
Anonymous
2026-07-26 15:05:20
(1 day ago)
Blocked: Reason='Suspicious traffic score=80 (review-based detection)'; Requests=74
Hacking