๐ฎ๐ณ
evicky2002
2026-08-01 06:00:00
(1 hour ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐ฌ๐ง
AvonleaConsulting
2026-07-31 22:59:04
(8 hours ago)
Attempts to probe web pages for vulnerable PHP or other applications
Web App Attack
๐ณ๐ฑ
oisecnet
2026-07-31 21:02:31
(10 hours ago)
Automated report: Unauthorized vulnerability scanning detected on 2026-07-31. 129 requests from this ...
show more
Automated report: Unauthorized vulnerability scanning detected on 2026-07-31. 129 requests from this IP.
show less
Brute-Force
Web App Attack
SSH
๐บ๐ธ
TPI-Abuse
2026-07-31 17:34:51
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.133.83.72 (72.83.133.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.133.83.72 (72.83.133.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 13:34:45.106039 2026] [security2:error] [pid 4081942:tid 4081942] [client 34.133.83.72:40374] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.etrass.info.networkmediasoftware.com"] [uri "/.env"] [unique_id "amzctdE3JFeobLHZhJRl_wAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ต๐ฑ
Budyn
2026-07-31 17:17:28
(14 hours ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: url.budyn.wtf | URI: /.env | UA: crusader-worker/1.0 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-31 17:15:07
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.133.83.72 (72.83.133.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.133.83.72 (72.83.133.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 13:14:59.186621 2026] [security2:error] [pid 832144:tid 832144] [client 34.133.83.72:57774] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.jeffreylowenstein.com"] [uri "/.env"] [unique_id "amzYExj-viaVC3xrfAgKmAAAADI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2026-07-31 16:47:31
(14 hours ago)
586 requests with url.path *.env
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-07-31 16:43:08
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.133.83.72 (72.83.133.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.133.83.72 (72.83.133.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 12:43:04.094302 2026] [security2:error] [pid 3342593:tid 3342593] [client 34.133.83.72:55040] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "csme-eprr.com"] [uri "/.env"] [unique_id "amzQmE1sGNy5XgrJj9eghwAAAHw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-31 16:16:02
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.133.83.72 (72.83.133.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.133.83.72 (72.83.133.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 12:15:54.797723 2026] [security2:error] [pid 4371:tid 4401] [client 34.133.83.72:56690] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "inkandthreadllc.com"] [uri "/.env"] [unique_id "amzKOhhsz74znqk7-zuLuQAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
anon333
2026-07-31 16:06:14
(15 hours ago)
Invalid probes to web server T1206
Hacking
Exploited Host
๐บ๐ธ
mnsf
2026-07-31 16:05:36
(15 hours ago)
Abuse Detected (10)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-31 15:48:27
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.133.83.72 (72.83.133.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.133.83.72 (72.83.133.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 11:48:21.750207 2026] [security2:error] [pid 1162535:tid 1162578] [client 34.133.83.72:39856] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "meanmouse.com"] [uri "/.env"] [unique_id "amzDxalUBENaa4v5_So-ywAAAYo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
4server
2026-07-31 15:26:04
(15 hours ago)
[FriJul3117:26:00.1388982026][security2:error][pid3603710:tid3603864][client34.133.83.72:0]ModSecuri ...
show more
[FriJul3117:26:00.1388982026][security2:error][pid3603710:tid3603864][client34.133.83.72:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".env\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"365\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"piffarerio.ch.81-17-25-250.cpanel.site\"][uri\"/.env\"][unique_id\"amy-iJNWBKcJW3BEFbt2uwAAABY\"]
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-31 15:14:11
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.133.83.72 (72.83.133.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.133.83.72 (72.83.133.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 11:14:03.424000 2026] [security2:error] [pid 401090:tid 401090] [client 34.133.83.72:56550] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gpaarch.com"] [uri "/.env"] [unique_id "amy7u0Di8iNQovaDEuQImQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
zcampbell
2026-07-31 15:08:58
(16 hours ago)
Web vulnerability scanning: probing for exposed sensitive files (.env). Detected and blocked automat ...
show more
Web vulnerability scanning: probing for exposed sensitive files (.env). Detected and blocked automatically.
show less
Web App Attack
Bad Web Bot