๐ฑ๐ป
garmtech.com
2026-07-23 11:22:03
(1 hour ago)
IM360 WAF: Direct access to sensitive file or dotfile MV:/.env
Web App Attack
๐ธ๐ช
nekopavel
2026-07-23 10:12:38
(2 hours ago)
3.85.31.94 - - [23/Jul/2026:12:12:35 +0200]"GET /.env HTTP/2.0" 404 518"-" uwu.so "Mozilla/5.0 (Wind ...
show more
3.85.31.94 - - [23/Jul/2026:12:12:35 +0200]"GET /.env HTTP/2.0" 404 518"-" uwu.so "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36""0.006" "0.000""Ashburn" "US"
3.85.31.94 - - [23/Jul/2026:12:12:35 +0200]"GET /.env.local HTTP/2.0" 404 518"-" uwu.so "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36""0.006" "0.000""Ashburn" "US"
3.85.31.94 - - [23/Jul/2026:12:12:36 +0200]"GET /.env.production HTTP/2.0" 404 518"-" uwu.so "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36""0.006" "0.001""Ashburn" "US"
...
show less
Hacking
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Redeco Hosting
2026-07-23 07:30:05
(5 hours ago)
Failed login attempt detected by Fail2Ban in plesk-apache jail
Web App Attack
Anonymous
2026-07-23 05:21:54
(7 hours ago)
suspicious behavior
Blog Spam
Brute-Force
Web App Attack
๐ฒ๐ฝ
impra
2026-07-22 16:41:19
(20 hours ago)
Detected 29 connection attempts across 17 ports.
Port Scan
Hacking
Web App Attack
๐ณ๐ฟ
Antinson
2026-07-22 15:58:56
(20 hours ago)
Scraping with a high error ratio and request rate
Bad Web Bot
๐ณ๐ฑ
Lentini
2026-07-22 14:34:34
(22 hours ago)
visuitslagen.nl: malicious request:/.env
Web App Attack
๐ซ๐ท
Octopuce
2026-07-22 14:21:57
(22 hours ago)
Aggressive web search of vulnerable pages: /.env /.env.local /api/.env /backend/.env /admin/.env .. ...
show more
Aggressive web search of vulnerable pages: /.env /.env.local /api/.env /backend/.env /admin/.env ...
show less
Web App Attack
๐ฉ๐ช
Roper123
2026-07-22 10:57:15
(1 day ago)
Web exploits - access forbidden
Web App Attack
๐ฉ๐ช
Tamsy
2026-07-22 10:06:39
(1 day ago)
HTTPD - Web Application vulnerability scan
Web App Attack
๐จ๐ญ
Origon
2026-07-22 05:42:18
(1 day ago)
http-probing - IP: 3.85.31.94 - time="2026-07-22T07:42:18+02:00" level=info msg="(555f66b4f6a74558b ...
show more
http-probing - IP: 3.85.31.94 - time="2026-07-22T07:42:18+02:00" level=info msg="(555f66b4f6a74558bc11e3f93469658es8App0Mcc0TKEeje/crowdsec) crowdsecurity/http-probing by ip 3.85.31.94 (US/14618) : 4h ban on Ip 3.85.31.94" module=db
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-22 01:58:11
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 3.85.31.94 (ec2-3-85-31-94.compute-1.amazonaws. ...
show more
(mod_security) mod_security (id:210492) triggered by 3.85.31.94 (ec2-3-85-31-94.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 21:58:06.076541 2026] [security2:error] [pid 2191441:tid 2191441] [client 3.85.31.94:34772] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nightknightalarms.com"] [uri "/.env"] [unique_id "amAjrvrqLuiVOb7NnjZ9GQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-22 00:51:17
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 3.85.31.94 (ec2-3-85-31-94.compute-1.amazonaws. ...
show more
(mod_security) mod_security (id:210492) triggered by 3.85.31.94 (ec2-3-85-31-94.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 20:51:10.197327 2026] [security2:error] [pid 30303:tid 30303] [client 3.85.31.94:51652] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mvseasea.com"] [uri "/.env"] [unique_id "amAT_k-77diHmXp7sSvbBQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-07-22 00:15:47
(1 day ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-21 21:11:19
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 3.85.31.94 (ec2-3-85-31-94.compute-1.amazonaws. ...
show more
(mod_security) mod_security (id:210492) triggered by 3.85.31.94 (ec2-3-85-31-94.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 17:11:16.407872 2026] [security2:error] [pid 26846:tid 26846] [client 3.85.31.94:47754] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fpstudios.puoci.com"] [uri "/.env"] [unique_id "al_gdL4_BJpvm1jU7zIznAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack