๐ง๐พ
lns.bz
2025-11-29 21:03:59
(9 months ago)
.env scanning [BY]
Web App Attack
๐ณ๐ฑ
Site.eu
2025-11-29 20:14:53
(9 months ago)
Excessive multi-domain requests
Brute-Force
Anonymous
2025-11-29 17:18:12
(9 months ago)
Ports: 80,443; Direction: 0; Trigger: LF_MODSEC
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2025-11-29 13:44:45
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 3.96.203.46 (ec2-3-96-203-46.ca-central-1.compu ...
show more
(mod_security) mod_security (id:210492) triggered by 3.96.203.46 (ec2-3-96-203-46.ca-central-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Nov 29 08:44:41.104372 2025] [security2:error] [pid 754:tid 754] [client 3.96.203.46:41680] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.matronasoy.com"] [uri "/.env.local"] [unique_id "aSr4yZhJxnYox2EYf_y_rwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-11-29 12:26:08
(9 months ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐ฉ๐ช
FeG Deutschland
2025-11-29 10:51:05
(9 months ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-29 10:50:32
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 3.96.203.46 (ec2-3-96-203-46.ca-central-1.compu ...
show more
(mod_security) mod_security (id:210492) triggered by 3.96.203.46 (ec2-3-96-203-46.ca-central-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Nov 29 05:50:24.680752 2025] [security2:error] [pid 488:tid 488] [client 3.96.203.46:49322] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "c-blanchard.online"] [uri "/.env.remote"] [unique_id "aSrP8E8D1iMr8FG67hDSZgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐พ
lns.bz
2025-11-29 10:10:02
(9 months ago)
Too many 404 requests [BY]
Web App Attack
๐ง๐ช
cmbplf
2025-11-29 07:26:04
(9 months ago)
474 requests with url.path *.env
Brute-Force
Bad Web Bot
Anonymous
2025-11-29 03:22:34
(9 months ago)
Bot / scanning and/or hacking attempts: GET /.env.sample HTTP/1.1, GET /.env.staging HTTP/1.1, GET / ...
show more
Bot / scanning and/or hacking attempts: GET /.env.sample HTTP/1.1, GET /.env.staging HTTP/1.1, GET /.env.development HTTP/1.1, GET /.env.save HTTP/1.1, GET /lib/.env HTTP/1.1, GET /.env.test HTTP/1.1, GET /.env.example HTTP/1.1, GET /.env.old HTTP/1.1, GET /.env HTTP/1.1, GET /.env.remote HTTP/1.1, GET /lab/.env HTTP/1.1, GET /vendor/.env HTTP/1.1
show less
Hacking
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2025-11-28 23:02:18
(9 months ago)
Auto-ban: >3000 req/min op 2025-11-28
Hacking
Web App Attack
SSH
๐บ๐ธ
TPI-Abuse
2025-11-28 20:29:06
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 3.96.203.46 (ec2-3-96-203-46.ca-central-1.compu ...
show more
(mod_security) mod_security (id:210492) triggered by 3.96.203.46 (ec2-3-96-203-46.ca-central-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Nov 28 15:28:59.386587 2025] [security2:error] [pid 3375307:tid 3375313] [client 3.96.203.46:57736] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "draas.info"] [uri "/.env"] [unique_id "aSoGC3Q5XhD38jaI1WiLOQAAAEE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
GoodOldTOS
2025-11-28 19:02:52
(9 months ago)
Bad keywords detected in request: /.env
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-28 18:48:53
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 3.96.203.46 (ec2-3-96-203-46.ca-central-1.compu ...
show more
(mod_security) mod_security (id:210492) triggered by 3.96.203.46 (ec2-3-96-203-46.ca-central-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Nov 28 13:48:49.187066 2025] [security2:error] [pid 15872:tid 15872] [client 3.96.203.46:35094] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dojoonthego.com"] [uri "/.env.local"] [unique_id "aSnukcqHOj4uId5a3Z9MFQAAAC4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2025-10-02 21:59:25
(11 months ago)
Auto-ban: >500 bad req/min on 2025-10-01
Hacking
Web App Attack
SSH