Anonymous
2026-08-01 17:32:29
(5 hours ago)
[ns41.kdns.gr] httpd-config-scan: sites=www.example.com; logs=/var/log/httpd/access_log; samples=/.e ...
show more
[ns41.kdns.gr] httpd-config-scan: sites=www.example.com; logs=/var/log/httpd/access_log; samples=/.env.local | /.env | /.env.backup
show less
Hacking
Web App Attack
๐ฉ๐ช
LRob
2026-08-01 17:31:46
(5 hours ago)
CrowdSec: crowdsecurity/http-sensitive-files | req: /.env.dev | 5 distinct paths | UA: crusader-work ...
show more
CrowdSec: crowdsecurity/http-sensitive-files | req: /.env.dev | 5 distinct paths | UA: crusader-worker/1.0
show less
Hacking
๐ณ๐ฑ
sernate
2026-08-01 17:19:38
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.151.82.196 (AU/Australia/196.82.151.34.bc.go ...
show more
(mod_security) mod_security (id:210492) triggered by 34.151.82.196 (AU/Australia/196.82.151.34.bc.googleusercontent.com): 10 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_MODSEC
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-08-01 17:18:13
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.151.82.196 (196.82.151.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.151.82.196 (196.82.151.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 13:18:09.899074 2026] [security2:error] [pid 25682:tid 25682] [client 34.151.82.196:60866] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.edesa.pamplonaserviciotecnico.com"] [uri "/.env"] [unique_id "am4qUfxduBzclaHBWvay6gAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
FreeMyIP
2026-08-01 17:10:17
(6 hours ago)
Automated fail2ban report: web application attack / scanning for exploitable paths.
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 16:58:42
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.151.82.196 (196.82.151.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.151.82.196 (196.82.151.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 12:58:37.968565 2026] [security2:error] [pid 816854:tid 816860] [client 34.151.82.196:60300] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lamcohomecare.com.lamco.us"] [uri "/.env.production"] [unique_id "am4lvT13_8AJoVqvfxqI7QAAAIM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 16:32:06
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.151.82.196 (196.82.151.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.151.82.196 (196.82.151.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 12:32:01.066727 2026] [security2:error] [pid 2203652:tid 2203652] [client 34.151.82.196:42624] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cidv.net"] [uri "/.env.save"] [unique_id "am4fgR3UZrceLowbx6I77gAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Aetherweb Ark
2026-08-01 16:03:49
(7 hours ago)
(mod_security) mod_security (id:949110) triggered by 34.151.82.196 (AU/Australia/196.82.151.34.bc.go ...
show more
(mod_security) mod_security (id:949110) triggered by 34.151.82.196 (AU/Australia/196.82.151.34.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
๐ฉ๐ช
on-com
2026-08-01 15:45:07
(7 hours ago)
URL scan
Brute-Force
Web App Attack
๐ธ๐ช
vaia.cloud
2026-08-01 15:40:03
(7 hours ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 15:13:34
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.151.82.196 (196.82.151.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.151.82.196 (196.82.151.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 11:13:29.509602 2026] [security2:error] [pid 937290:tid 937290] [client 34.151.82.196:43498] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "legalnexuslawfirm.com"] [uri "/.env.dev"] [unique_id "am4NGT4PotSYPFPr_vMRXAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-08-01 13:58:24
(9 hours ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-201)
Hacking
Web App Attack
๐บ๐ธ
OceanTreasure
2026-08-01 13:57:21
(9 hours ago)
tcp/443; Environment file access attempt: "GET /.env" @ 2026-08-01T13:54:59Z [proxy]
Web App Attack
๐ฉ๐ช
hbrks
2026-08-01 13:33:21
(9 hours ago)
11 attack(s) detected, such as these: {"event":"web_block","ip":"34.151.82.196","host":"wsh.big.marc ...
show more
11 attack(s) detected, such as these: {"event":"web_block","ip":"34.151.82.196","host":"wsh.big.marche-be.com","request":"GET /.env.local HTTP/1.1","user_agent":"","reason":"Status-301","timestamp":"2026-08-01T13:33:21 00:00","logentry":"wsh.big.marche-be.com 34.151.82.196 - - [01/Aug/2026:15:33:21 0200] \"GET /.env.local HTTP/1.1\" 301 169 \"-\" \"crusader-worker/1.0\" \"-\""} * Report Details *: https://p4u.xyz/BI4XRRJULBL/1* IP Details *: https://p4u.xyz/BI4XRRJULBL/2
show less
Web Spam
Hacking
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-08-01 13:16:34
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.151.82.196 (196.82.151.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.151.82.196 (196.82.151.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 09:16:30.568121 2026] [security2:error] [pid 2198193:tid 2198193] [client 34.151.82.196:40450] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tools.alitcogroup.com"] [uri "/.env.prod"] [unique_id "am3xrtZaoF-ef3i0tgUowQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack