π³π±
homeshowdomain.nl
2026-06-16 22:03:11
(3 months ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-06-15.
show less
Web App Attack
SSH
Hacking
πΊπΈ
TPI-Abuse
2026-06-15 07:01:25
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 34.104.234.7 (7.234.104.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.104.234.7 (7.234.104.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 03:01:20.154705 2026] [security2:error] [pid 23020:tid 23020] [client 34.104.234.7:35294] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.jayworthallen.com.drjaymissdiana.com"] [uri "/.env.save"] [unique_id "ai-jQIu408o0JlVGiA2pvwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-15 05:56:28
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 34.104.234.7 (7.234.104.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.104.234.7 (7.234.104.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 01:56:22.312441 2026] [security2:error] [pid 32065:tid 32065] [client 34.104.234.7:55656] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.dev.specialtypayments.com"] [uri "/.env.example"] [unique_id "ai-UBvmg11RgLpOnMHyrPwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
Cloud86 B.V.
2026-06-15 04:00:02
(3 months ago)
categories: DDoS Attack
DDoS Attack
π©πͺ
FeG Deutschland
2026-06-15 01:54:33
(3 months ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
π©πͺ
Isha
2026-06-15 01:42:38
(3 months ago)
Shield Guard: Honeypot: /.env.save
Web App Attack
π¬π§
consul.to
2026-06-15 00:36:50
(3 months ago)
Web attack/malicious scanning detected
Web App Attack
π³π±
ConsulHosting
2026-06-14 23:09:00
(3 months ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack
πΊπΈ
WellSpring
2026-06-14 22:49:19
(3 months ago)
env leak on 860.today/internal/.env β WellSpr.ing/NetSentinel civic-AI security layer
Web App Attack
Anonymous
2026-06-14 14:37:42
(3 months ago)
[Sun Jun 14 16:37:40.538456 2026] [:error] [pid 2549783:tid 2549783] [client 34.104.234.7:46628] Mod ...
show more
[Sun Jun 14 16:37:40.538456 2026] [:error] [pid 2549783:tid 2549783] [client 34.104.234.7:46628] ModSecurity: Warning. Matched "Operator `PmFromFile' with parameter `restricted-files.data' against variable `REQUEST_FILENAME' (Value: `/.env.backup.txt' ) [file "/usr/local/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "131"] [id "930130"] [rev ""] [msg "Restricted File Access Attempt"] [data "Matched Data: .env found within REQUEST_FILENAME: /.env.backup.txt"] [severity "2"] [ver "OWASP_CRS/4.28.0-dev"] [maturity "0"] [accuracy "0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/ATTACK-LFI"] [tag "capec/1000/255/153/126"] [uri "/.env.backup.txt"] [unique_id "178144786065.396006"] [ref "o1,4v4,16t:utf8toUnicode,t:urlDecodeUni,t:normalizePathWin"]
[Sun Jun 14 16:37:40.539554 2026] [:error] [pid 2549781:tid 2549781] [client 34.104.234.7:
...
show less
Web App Attack
π³π±
Site.eu
2026-06-14 02:14:17
(3 months ago)
Excessive 404/403 errors
Brute-Force
π«π·
Octopuce
2026-06-14 02:13:40
(3 months ago)
Aggressive web search of vulnerable pages: /app/.env.local /backend/.env.local /staging/.env /backen ...
show more
Aggressive web search of vulnerable pages: /app/.env.local /backend/.env.local /staging/.env /backend/.env /production/.env ...
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-14 02:08:25
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 34.104.234.7 (7.234.104.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.104.234.7 (7.234.104.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 13 22:08:21.641137 2026] [security2:error] [pid 10384:tid 10410] [client 34.104.234.7:57810] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "visionforandfromchildren.org"] [uri "/api/v1/.env"] [unique_id "ai4NFTaxKgNbO4IQ-VexvgAAAFg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
Starburst SysOp Team
2026-06-13 23:38:11
(3 months ago)
Host header is a numeric IP address. Pattern match "(?:^( (920350-iad5-2)
Hacking
Bad Web Bot