๐ฉ๐ช
andorin
2026-08-02 01:10:02
(8 hours ago)
Automated report from halo.habith.eu (NGINX access log).
Detected 10 suspicious requests in last 20 ...
show more
Automated report from halo.habith.eu (NGINX access log).
Detected 10 suspicious requests in last 20000 lines.
Sample log lines:
34.145.150.142 - - [01/Aug/2026:17:20:44 +0200] "GET /.env HTTP/1.1" 403 162 "-" "crusader-worker/1.0"\n34.145.150.142 - - [01/Aug/2026:17:20:44 +0200] "GET /.env.local HTTP/1.1" 404 8126 "-" "crusader-worker/1.0"\n34.145.150.142 - - [01/Aug/2026:17:20:44 +0200] "GET /.env.example HTTP/1.1" 404 8126 "-" "crusader-worker/1.0"\n34.145.150.142 - - [01/Aug/2026:17:20:44 +0200] "GET /.env.dev HTTP/1.1" 404 8126 "-" "crusader-worker/1.0"\n34.145.150.142 - - [01/Aug/2026:17:20:44 +0200] "GET /.env.bak HTTP/1.1" 403 162 "-" "crusader-worker/1.0"\n34.145.150.142 - - [01/Aug/2026:17:20:44 +0200] "GET /.env.prod HTTP/1.1" 404 8126 "-" "crusader-worker/1.0"
show less
DDoS Attack
Ping of Death
Hacking
๐จ๐ฆ
polycoda
2026-08-01 17:26:35
(15 hours ago)
AutoBlock: ๐ฏ Vulnerability Scanner (Non Decay-Based)
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 17:18:22
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.145.150.142 (142.150.145.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.145.150.142 (142.150.145.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 13:18:16.908590 2026] [security2:error] [pid 2184782:tid 2184782] [client 34.145.150.142:44608] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.bjennehall.thehallway.net"] [uri "/.env"] [unique_id "am4qWJsDrvZUT-dDSRhlPAAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
paissangroup
2026-08-01 17:14:49
(16 hours ago)
Multiple WAF Violations
Web App Attack
Anonymous
2026-08-01 16:39:50
(16 hours ago)
[ns27.kdns.gr] httpd-config-scan: sites=www.foraofakous.gr; logs=/var/log/httpd/domains/foraofakous. ...
show more
[ns27.kdns.gr] httpd-config-scan: sites=www.foraofakous.gr; logs=/var/log/httpd/domains/foraofakous.gr.log; samples=/.env.production | /.env.prod | /.env.local
show less
Hacking
Web App Attack
๐จ๐ญ
4server
2026-08-01 16:29:30
(16 hours ago)
[SatAug0118:29:22.5649332026][security2:error][pid25207:tid25400][client34.145.150.142:0]ModSecurity ...
show more
[SatAug0118:29:22.5649332026][security2:error][pid25207:tid25400][client34.145.150.142:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".env\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"365\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"avvnicolaurbani.ch.81-17-25-250.cpanel.site\"][uri\"/.env.production\"][unique_id\"am4e4uoOtGoLy-SntgJ3gAAAAhA\"]
show less
Hacking
Web App Attack
๐บ๐ธ
Lee Daniel
2026-08-01 16:28:10
(16 hours ago)
34.145.150.142 - - [01/Aug/2026:12:28:09 -0400] "GET /.env HTTP/1.1" 403 6277 "-" "crusader-worker/1 ...
show more
34.145.150.142 - - [01/Aug/2026:12:28:09 -0400] "GET /.env HTTP/1.1" 403 6277 "-" "crusader-worker/1.0"
...
show less
DDoS Attack
Web Spam
Email Spam
Port Scan
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-01 16:15:23
(17 hours ago)
Web application attack detected.
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 16:00:17
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.145.150.142 (142.150.145.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.145.150.142 (142.150.145.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 12:00:09.964317 2026] [security2:error] [pid 29659:tid 29659] [client 34.145.150.142:57068] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "w.planettony.com"] [uri "/.env.dev"] [unique_id "am4YCcSxSzbed1SwiKgTcgAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 15:43:28
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.145.150.142 (142.150.145.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.145.150.142 (142.150.145.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 11:43:21.109563 2026] [security2:error] [pid 933012:tid 933012] [client 34.145.150.142:43448] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "imaginationbyme.com.swhinc.net"] [uri "/.env.old"] [unique_id "am4UGVdWJ5TeOmyJLLa4FwAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
kosada.com
2026-08-01 15:16:04
(18 hours ago)
Web vulnerability probing: /.env.example
Web App Attack
๐บ๐ธ
aks4226
2026-08-01 15:11:42
(18 hours ago)
Bot search, attacking common web applications.
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-08-01 14:24:47
(18 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 14:15:27
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.145.150.142 (142.150.145.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.145.150.142 (142.150.145.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 10:15:23.364323 2026] [security2:error] [pid 1843094:tid 1843094] [client 34.145.150.142:51404] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bonvivantorganics.com"] [uri "/.env.backup"] [unique_id "am3_e_fkJkPrnfert2sxpQAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 13:52:27
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.145.150.142 (142.150.145.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.145.150.142 (142.150.145.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 09:52:21.858433 2026] [security2:error] [pid 25061:tid 25061] [client 34.145.150.142:39420] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "indie100.com"] [uri "/.env.prod"] [unique_id "am36FaHJ-6oadW7z8YP3QwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack