🇺🇸
Epimetheus
2026-09-10 00:32:32
(7 minutes ago)
Zombie network / Bot scanner detected:
[GET] /proc/self/environ
[GET] /files../.env
[GET] /horizon/ ...
show more
Zombie network / Bot scanner detected:
[GET] /proc/self/environ
[GET] /files../.env
[GET] /horizon/dashboard
[GET] /.env.production.bak
[GET] /login/..;/actuator/env
[GET] /.env.dev
[GET] /service/.env
[GET] /media../.env
[GET] /static../.aws/credentials
[GET] /backup.sql
[GET] /kubernetes.yml
[GET] /admin/.env.local
[GET] /apps/backend/.env
[GET] /database/.env
[GET] /server/.env.production
[GET] /credentials.ini
[GET] /.env.testing
[GET] /apps/api/.env
[GET] /.terraform/terraform.tfstate
[GET] /config/env.php
[GET] /docker-compose.prod.yml
[GET] /config/env.json
[GET] /config/credentials.json
[GET] /backend/api/.env
[GET] /backend/.env.production
[GET] /src/api/.env
[GET] /frontend/.env.local
[GET] /private/.env
[GET] /internal/.env
[GET] /services/.env
[GET] /test/.env
[GET] /frontend/.env.production
[GET] /app/api/.env
[GET] /stripe.env
[GET] /sendgrid/.env
[GET] /config/sendgrid.env
[GET] /var/www/html/.env
[GET] /back/.env
[GET] /serverless.yaml
[GET] /stripe.json
...(Truncated)
show less
Bad Web Bot
Exploited Host
Web App Attack
Anonymous
2026-09-09 23:23:14
(1 hour ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
🇳🇱
e.fierstra
2026-09-09 23:12:13
(1 hour ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
Anonymous
2026-09-09 22:01:45
(2 hours ago)
Bad Web Bot
🇧🇷
vfAcceloReporter
2026-09-09 21:53:09
(2 hours ago)
34.16.128.0 - - [09/Sep/2026:18:53:08 -0300] "GET /@fs/.env.production?raw?? HTTP/1.1" 200 1442 "-" ...
show more
34.16.128.0 - - [09/Sep/2026:18:53:08 -0300] "GET /@fs/.env.production?raw?? HTTP/1.1" 200 1442 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot)"
...
show less
Brute-Force
Web App Attack
Exploited Host
🇳🇱
Savvii
2026-09-09 21:44:29
(2 hours ago)
20 attempts against mh-misbehave-ban on lunar
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 20:51:44
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.16.128.0 (0.128.16.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.16.128.0 (0.128.16.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 16:51:38.321515 2026] [security2:error] [pid 1108:tid 1108] [client 34.16.128.0:18172] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.vrevgaming.net"] [uri "/@fs/app/.env"] [unique_id "aqHG2rx-vXbvxRpCv5FkVAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
sdos.es
2026-09-09 17:58:04
(6 hours ago)
"Restricted File Access Attempt - Matched Data: /.env found within REQUEST_FILENAME: /@fs/app/.env"
Web App Attack
🇲🇾
Rizzy
2026-09-09 17:41:02
(6 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack
🇨🇭
zynex
2026-09-09 17:33:28
(7 hours ago)
URL Probing: /@fs/.env
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 13:00:53
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.16.128.0 (0.128.16.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.16.128.0 (0.128.16.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 09:00:46.138519 2026] [security2:error] [pid 19309:tid 19309] [client 34.16.128.0:50106] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.john-bell-associates.com"] [uri "/@fs/app/.env"] [unique_id "aqFYfi3hw5jF--TggHhkKwAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Site.eu
2026-09-09 12:27:43
(12 hours ago)
Excessive multi-domain requests
Brute-Force
🇺🇸
TPI-Abuse
2026-09-09 12:02:46
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.16.128.0 (0.128.16.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.16.128.0 (0.128.16.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 08:02:40.633125 2026] [security2:error] [pid 30317:tid 30317] [client 34.16.128.0:34050] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ajwood.net"] [uri "/@fs/../../.env"] [unique_id "aqFK4I34yzjh-nNcaah2wQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-09 11:27:00
(13 hours ago)
Excessive crawling/scraping. Vulnerable file probing.
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
big-cloud.nl
2026-09-09 10:53:41
(13 hours ago)
Try to access /@fs/..%252f..%252f..%252f..%252f..%252froot/.env?raw??
Web App Attack