Anonymous
2026-09-07 06:50:30
(8 hours ago)
Multiple web server 400 error codes from same source ip
Web App Attack
🇫🇷
SpaceHost-Server
2026-09-06 22:18:39
(17 hours ago)
Brute-Force
Web App Attack
Anonymous
2026-09-06 13:45:08
(1 day ago)
Observed scanned 12 known-sensitive endpoint(s), e.g.: /, /%2eenv, /.ENV, /.env, /.env.bak, /.env.ol ...
show more
Observed scanned 12 known-sensitive endpoint(s), e.g.: /, /%2eenv, /.ENV, /.env, /.env.bak, /.env.old
show less
Bad Web Bot
Web App Attack
Anonymous
2026-09-06 09:35:55
(1 day ago)
apache vulnerability scan
Web App Attack
🇮🇩
bps-statistics
2026-09-06 06:45:11
(1 day ago)
Web Application Attacks
Web App Attack
🇺🇸
hyena
2026-09-06 06:09:33
(1 day ago)
Repeated mod_security events.
Web App Attack
Anonymous
2026-09-06 06:02:39
(1 day ago)
Honey Pot Hit / Attack Vector found!
Port Scan
Hacking
Web App Attack
🇬🇧
openstrike.co.uk
2026-09-06 05:13:39
(1 day ago)
13 attacks on env grabbing URLs, PHP URLs:
GET /.env.dev HTTP/1.1
GET /wp-config.php.bak HTTP/1.1
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 03:51:26
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.148.148.40 (40.148.148.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.148.148.40 (40.148.148.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:51:22.204998 2026] [security2:error] [pid 26674:tid 26674] [client 34.148.148.40:59742] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.citystreetsalon.com"] [uri "/.env.prod"] [unique_id "apzjOmeqVF07Ur_D90Ku1wAAAJA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 03:32:44
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.148.148.40 (40.148.148.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.148.148.40 (40.148.148.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:32:36.495228 2026] [security2:error] [pid 18042:tid 18052] [client 34.148.148.40:38546] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "certifiedfinancialanalyst.org"] [uri "/.env.backup"] [unique_id "apze1PBEH8oKGMOdva82VQAAAUM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
CBJ
2026-09-06 02:25:14
(1 day ago)
fail2ban: apache-filepath-recon
...
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 02:18:56
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.148.148.40 (40.148.148.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.148.148.40 (40.148.148.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:18:52.657894 2026] [security2:error] [pid 19117:tid 19117] [client 34.148.148.40:54216] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "stufflebeam.name"] [uri "/.env.production"] [unique_id "apzNjJ2fHGN18xh_IntZRwAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
macrob
2026-09-06 02:07:55
(1 day ago)
2026/09/06 02:07:53 [error] 1902782#1902782: *561274074 access forbidden by rule, client: 34.148.148 ...
show more
2026/09/06 02:07:53 [error] 1902782#1902782: *561274074 access forbidden by rule, client: 34.148.148.40, server: fn.binixo.es, request: "GET /.env.example HTTP/2.0", host: "server2.fastcredit.net.ua"
2026/09/06 02:07:53 [error] 1902782#1902782: *561274076 access forbidden by rule, client: 34.148.148.40, server: fn.binixo.es, request: "GET /storage/logs/laravel.log HTTP/2.0", host: "server2.fastcredit.net.ua"
2026/09/06 02:07:53 [error] 1902785#1902785: *561274077 access forbidden by rule, client: 34.148.148.40, server: fn.binixo.es, request: "GET /.env.old HTTP/2.0", host: "server2.fastcredit.net.ua"
...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 02:00:19
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.148.148.40 (40.148.148.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.148.148.40 (40.148.148.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:00:15.218749 2026] [security2:error] [pid 24467:tid 24467] [client 34.148.148.40:43824] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "marcastecnologia.com"] [uri "/.env.save"] [unique_id "apzJLzI7KzxwCuaHiIqtvgAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Vegascosmetics
2026-09-06 00:56:19
(1 day ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after admin/path reconnaissance / port-scan ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after admin/path reconnaissance / port-scan-like web scan. Evidence: AttackPattern: /actuator/ (Match: /actuator/)
show less
Port Scan
Hacking
Web App Attack