🇧🇬
alnaasd
2026-08-10 13:14:53
(4 weeks ago)
WAF block action triggered by rule set "Version Control - Information Disclosure" (2 occurrences obs ...
show more
WAF block action triggered by rule set "Version Control - Information Disclosure" (2 occurrences observed).
show less
Web App Attack
🇫🇷
✨
2026-08-03 14:15:05
(1 month ago)
Domain : gestioncgt.es
Rule : config
2026-08-03 14:14:14 2a00:11c0:47:18cd::2 GET /.git/config - 80 ...
show more
Domain : gestioncgt.es
Rule : config
2026-08-03 14:14:14 2a00:11c0:47:18cd::2 GET /.git/config - 80 - 2400:8d60:3::5502:a13 HTTP/1.1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36 - gestioncgt.es 404 8 0 278 211 605 - -
show less
Hacking
SQL Injection
🇺🇸
TPI-Abuse
2026-08-03 14:01:43
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 2400:8d60:3::5502:a13 (Unknown): 1 in the last ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:8d60:3::5502:a13 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 03 10:01:35.769328 2026] [security2:error] [pid 4099749:tid 4099749] [client 2400:8d60:3::5502:a13:54060] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.indoorsfinishing.com"] [uri "/.env"] [unique_id "anCfPywCIfrhTjLaA14UqAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-02 01:07:17
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 2400:8d60:3::5502:a13 (Unknown): 1 in the last ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:8d60:3::5502:a13 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 21:07:12.537027 2026] [security2:error] [pid 3089198:tid 3089198] [client 2400:8d60:3::5502:a13:36552] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "logosformacion.net"] [uri "/.env"] [unique_id "am6YQNqdLlpv5nj_9-l9mAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-01 15:35:33
(1 month ago)
2400:8d60:3::5502:a13 - - [01/Aug/2026:23:35:31 +0800] "GET /.env HTTP/1.1" 404 300911 "-" "Mozilla/ ...
show more
2400:8d60:3::5502:a13 - - [01/Aug/2026:23:35:31 +0800] "GET /.env HTTP/1.1" 404 300911 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-07-31 17:20:32
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 2400:8d60:3::5502:a13 (Unknown): 1 in the last ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:8d60:3::5502:a13 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 13:20:29.001331 2026] [security2:error] [pid 824035:tid 824035] [client 2400:8d60:3::5502:a13:44670] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sharc.d-sinema.com"] [uri "/.env.development"] [unique_id "amzZXVLj-HFqaJObVewOnQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
dynamix
2026-07-31 17:16:32
(1 month ago)
Multiple WAF Violations
Web App Attack
🇩🇪
LRob
2026-07-31 11:16:27
(1 month ago)
CrowdSec: crowdsecurity/http-sensitive-files | req: /.env.prod | 5 distinct paths | UA: Mozilla/5.0 ...
show more
CrowdSec: crowdsecurity/http-sensitive-files | req: /.env.prod | 5 distinct paths | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36
show less
Hacking
🇺🇸
TPI-Abuse
2026-07-31 11:10:06
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 2400:8d60:3::5502:a13 (Unknown): 1 in the last ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:8d60:3::5502:a13 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 07:09:59.647899 2026] [security2:error] [pid 31891:tid 31891] [client 2400:8d60:3::5502:a13:38164] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lmga.net"] [uri "/.git/config"] [unique_id "amyCh6L9gSZ2l4aRRaQ9uQAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
Baking333
2026-07-31 10:58:59
(1 month ago)
[redacted] 2400:8d60:3::5502:a13 - - [31/Jul/2026:11:58:57 +0100] "GET /.[redacted] HTTP/1.1" 302 15 ...
show more
[redacted] 2400:8d60:3::5502:a13 - - [31/Jul/2026:11:58:57 +0100] "GET /.[redacted] HTTP/1.1" 302 1573 0/232953 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" [redacted] 2400:8d60:3::5502:a13 - - [31/Jul/2026:11:58:57 +0100] "GET /.[redacted] HTTP/1.1" 302 1573 0/239948 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" [redacted] 2400:8d60:3::5502:a13 - - [31/Jul/2026:11:58:57 +0100] "GET /.[redacted] HTTP/1.1" 302 1573 0/166881 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
show less
Bad Web Bot
Web App Attack
🇺🇸
helios.live
2026-07-31 10:54:46
(1 month ago)
2026/07/31 10:54:46 [error] 2758937#2758937: *278814 access forbidden by rule, client: 2400:8d60:3:: ...
show more
2026/07/31 10:54:46 [error] 2758937#2758937: *278814 access forbidden by rule, client: 2400:8d60:3::5502:a13, server: kocerroxy.com, request: "GET /.env.save HTTP/1.1", host: "kocerroxy.com"
2026/07/31 10:54:46 [error] 2758937#2758937: *278814 access forbidden by rule, client: 2400:8d60:3::5502:a13, server: kocerroxy.com, request: "GET /.env.backup HTTP/1.1", host: "kocerroxy.com"
2026/07/31 10:54:46 [error] 2758937#2758937: *278814 access forbidden by rule, client: 2400:8d60:3::5502:a13, server: kocerroxy.com, request: "GET /.env.local HTTP/1.1", host: "kocerroxy.com"
2026/07/31 10:54:46 [error] 2758937#2758937: *278814 access forbidden by rule, client: 2400:8d60:3::5502:a13, server: kocerroxy.com, request: "GET /.env.production HTTP/1.1", host: "kocerroxy.com"
2026/07/31 10:54:46 [error] 2758937#2758937: *278814 access forbidden by rule, client: 2400:8d60:3::5502:a13, server: kocerroxy.com, request: "GET /.env.prod HTTP/1.1", host: "kocerroxy.com"
...
show less
Web App Attack
🇫🇷
ELYAZ
2026-07-31 01:19:53
(1 month ago)
(y3) Failed access -byebye- from 2400:8d60:3::5502:a13 (Unknown): (CF_ENABLE)
Hacking
🇫🇷
Baking333
2026-07-31 01:08:53
(1 month ago)
[redacted] 2400:8d60:3::5502:a13 - - [31/Jul/2026:02:08:51 +0100] "GET /.[redacted] HTTP/1.1" 302 16 ...
show more
[redacted] 2400:8d60:3::5502:a13 - - [31/Jul/2026:02:08:51 +0100] "GET /.[redacted] HTTP/1.1" 302 1633 0/76028 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" [redacted] 2400:8d60:3::5502:a13 - - [31/Jul/2026:02:08:51 +0100] "GET /.[redacted] HTTP/1.1" 302 1633 0/92891 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" [redacted] 2400:8d60:3::5502:a13 - - [31/Jul/2026:02:08:51 +0100] "GET /.[redacted] HTTP/1.1" 302 1633 0/90301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
show less
Bad Web Bot
Web App Attack
🇩🇪
ardexter
2026-07-30 23:44:20
(1 month ago)
Wordpress attack and DDOS
DDoS Attack
Web App Attack
🇩🇪
LRob
2026-07-30 23:04:32
(1 month ago)
CrowdSec: crowdsecurity/http-sensitive-files | req: /.env.backup | 5 distinct paths | UA: Mozilla/5. ...
show more
CrowdSec: crowdsecurity/http-sensitive-files | req: /.env.backup | 5 distinct paths | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36
show less
Hacking