๐ณ๐ฑ
homeshowdomain.nl
2026-08-28 21:59:51
(2 days ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-08-27.
show less
Web App Attack
SSH
Hacking
๐ฌ๐ง
openstrike.co.uk
2026-08-27 05:14:42
(4 days ago)
3 attacks on env grabbing URLs:
HEAD /.env HTTP/1.1
Hacking
๐ณ๐ฑ
mieg
2026-08-27 05:10:13
(4 days ago)
Web vulnerability probing
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 04:44:43
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 2a09:bac1:36c0:20::2a8:18 (Unknown): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 2a09:bac1:36c0:20::2a8:18 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 00:44:36.637136 2026] [security2:error] [pid 23980:tid 23980] [client 2a09:bac1:36c0:20::2a8:18:34300] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.register-yacht-guernsey.com"] [uri "/.env"] [unique_id "ao_AtMsHE3pfUGxuH9fwXAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
LRob
2026-08-27 04:15:41
(4 days ago)
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: ...
show more
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: /.env | 2026-08-27 04:15 UTC
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 03:56:51
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 2a09:bac1:36c0:20::2a8:18 (Unknown): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 2a09:bac1:36c0:20::2a8:18 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 23:56:43.684496 2026] [security2:error] [pid 23888:tid 23888] [client 2a09:bac1:36c0:20::2a8:18:17164] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "universitydental.org"] [uri "/.env"] [unique_id "ao-1e-MWmAfTcqkf83xD-QAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-27 03:46:11
(4 days ago)
Web attack blocked by Wordfence on 1valkenburg.nl (1 hit). Reported by CRMON.
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 03:34:04
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 2a09:bac1:36c0:20::2a8:18 (Unknown): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 2a09:bac1:36c0:20::2a8:18 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 23:33:56.063006 2026] [security2:error] [pid 25631:tid 25631] [client 2a09:bac1:36c0:20::2a8:18:28968] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.insidepublications.com"] [uri "/.env"] [unique_id "ao-wJFN8FzswMaB6ei4r3QAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 03:06:11
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 2a09:bac1:36c0:20::2a8:18 (Unknown): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 2a09:bac1:36c0:20::2a8:18 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 23:06:06.345520 2026] [security2:error] [pid 23429:tid 23429] [client 2a09:bac1:36c0:20::2a8:18:17246] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.consolidatedoperationsgroup.com"] [uri "/.env"] [unique_id "ao-pnlAHTtEuq4JeW2m2sQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
securejdprop
2026-08-27 01:42:05
(4 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/vpatch-env-access.
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 01:27:16
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 2a09:bac1:36c0:20::2a8:18 (Unknown): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 2a09:bac1:36c0:20::2a8:18 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 21:27:09.482002 2026] [security2:error] [pid 3254:tid 3254] [client 2a09:bac1:36c0:20::2a8:18:14284] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.lyounglaw.com"] [uri "/.env"] [unique_id "ao-SbTBW_dYqIcpwmKAJSAAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 01:05:42
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 2a09:bac1:36c0:20::2a8:18 (Unknown): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 2a09:bac1:36c0:20::2a8:18 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 21:05:34.140241 2026] [security2:error] [pid 25255:tid 25255] [client 2a09:bac1:36c0:20::2a8:18:38548] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.bosozuki.com"] [uri "/.env"] [unique_id "ao-NXmz0jZOU5xgOTp22SgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Baking333
2026-08-27 00:46:26
(4 days ago)
[redacted] 2a09:bac1:36c0:20::2a8:18 - - [27/Aug/2026:01:46:24 +0100] "HEAD /.env HTTP/2.0" 301 287 ...
show more
[redacted] 2a09:bac1:36c0:20::2a8:18 - - [27/Aug/2026:01:46:24 +0100] "HEAD /.env HTTP/2.0" 301 287 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" [redacted] 2a09:bac1:36c0:20::2a8:18 - - [27/Aug/2026:01:46:25 +0100] "HEAD /fr/.env/ HTTP/2.0" 404 90 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 00:45:11
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 2a09:bac1:36c0:20::2a8:18 (Unknown): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 2a09:bac1:36c0:20::2a8:18 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 20:45:03.371890 2026] [security2:error] [pid 3021:tid 3021] [client 2a09:bac1:36c0:20::2a8:18:12372] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "westernmassaa.net"] [uri "/.env"] [unique_id "ao-IjymuUPVnKfXMPgoJegAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack