Anonymous
2026-08-01 17:30:41
(8 hours ago)
Blocked by siteaihub.com: live autoban: immediate: /.env
Hacking
Bad Web Bot
๐ฉ๐ช
neckaralb-admin.de
2026-08-01 17:19:44
(8 hours ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
๐ฉ๐ช
LRob
2026-08-01 17:14:52
(9 hours ago)
CrowdSec: crowdsecurity/http-sensitive-files | req: /.env.local | 5 distinct paths | UA: crusader-wo ...
show more
CrowdSec: crowdsecurity/http-sensitive-files | req: /.env.local | 5 distinct paths | UA: crusader-worker/1.0
show less
Hacking
๐ฉ๐ช
YF
2026-08-01 17:00:11
(9 hours ago)
Environment file probe
Web App Attack
๐ฉ๐ช
tentwentyfour
2026-08-01 16:24:13
(9 hours ago)
Blocked for probing for sensitive web application components
Brute-Force
Web App Attack
๐ซ๐ท
thilo
2026-08-01 16:18:58
(9 hours ago)
Probe for vulnerabilities. Path attempted: /.env.local
Web App Attack
๐ซ๐ท
masterguru
2026-08-01 15:34:31
(10 hours ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-197)
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 15:22:30
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.101.59.9 (9.59.101.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.101.59.9 (9.59.101.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 11:22:23.958599 2026] [security2:error] [pid 2905792:tid 2905807] [client 34.101.59.9:37068] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "norse.eagletons.com"] [uri "/.env.prod"] [unique_id "am4PL6gTNrrL8heozGrvSAAAAE0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 14:51:08
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.101.59.9 (9.59.101.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.101.59.9 (9.59.101.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 10:51:02.873221 2026] [security2:error] [pid 1814243:tid 1814243] [client 34.101.59.9:56060] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pcsyportatiles.com.integratic.com.co"] [uri "/.env.old"] [unique_id "am4H1iz_nrPyv4HY96NFygAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-08-01 14:16:12
(12 hours ago)
Multiple unauthorized connection attempts
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 14:12:21
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.101.59.9 (9.59.101.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.101.59.9 (9.59.101.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 10:12:13.381307 2026] [security2:error] [pid 561613:tid 561615] [client 34.101.59.9:53864] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.corianworks.conceptsinammunition.com"] [uri "/.env.production"] [unique_id "am3-vYuaOtnbGhbsEq2A7gAAAEA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-01 14:02:56
(12 hours ago)
[server.tmg.gr] httpd-config-scan: sites=www.add2025.gr; logs=/var/log/httpd/domains/add2025.gr.log; ...
show more
[server.tmg.gr] httpd-config-scan: sites=www.add2025.gr; logs=/var/log/httpd/domains/add2025.gr.log; samples=/.env.save | /.env.backup | /.env.old
show less
Hacking
Web App Attack
๐ซ๐ท
masterguru
2026-08-01 14:02:32
(12 hours ago)
URL file extension is restricted by policy. String match within ".ani/ .asa/ .asax/ .ascx/ .backup/ ...
show more
URL file extension is restricted by policy. String match within ".ani/ .asa/ .asax/ .ascx/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .compositefont/ .config/ .conf/ .crt/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dist/ .dll/ .dos/ .dpkg-dist/ .drv/ .gadget/ .hta/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .inf/ .ini/ .jse/ .key/ .licx/ .lnk/ .log/ .mdb/ .msc/ .ocx/ .old/ .pass/ .pdb/ .pfx/ .pif/ .pem/ .pol/ .prf/ .printer/ .pwd/ .rdb/ .rdp/ .reg/ .resources/ .resx/ .scr/ .sct/ .shs/ .sql/ .swp/ .sys/ .tlb/ .tmp/ .url/ .vb/ .vbe/ .vbs/ .vbproj/ .vsdisco/ .vxd/ .webinfo/ .ws/ .wsc/ .wsf/ .wsh/ .xsd/ .xsx/" at TX:extension. (920440-195)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-01 13:57:10
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.101.59.9 (9.59.101.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.101.59.9 (9.59.101.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 09:57:01.367702 2026] [security2:error] [pid 1824343:tid 1824343] [client 34.101.59.9:44380] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lewpratt.com"] [uri "/.env.old"] [unique_id "am37LXGPwOu8gtpS4sLFdQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-01 13:56:45
(12 hours ago)
Scenarios: http-sensitive-files
Total requests: 10
Web App Attack