๐ซ๐ท
tecnicorioja
2026-08-01 22:02:07
(9 hours ago)
(Mod_security)
Web App Attack
Brute-Force
Bad Web Bot
๐ซ๐ท
dynamix
2026-08-01 17:28:30
(13 hours ago)
Multiple WAF Violations
Web App Attack
๐ฉ๐ช
LRob
2026-08-01 17:18:08
(13 hours ago)
CrowdSec: crowdsecurity/http-sensitive-files | req: /.env.backup | 5 distinct paths | UA: crusader-w ...
show more
CrowdSec: crowdsecurity/http-sensitive-files | req: /.env.backup | 5 distinct paths | UA: crusader-worker/1.0
show less
Hacking
๐ฌ๐ง
Aetherweb Ark
2026-08-01 16:29:09
(14 hours ago)
(mod_security) mod_security (id:949110) triggered by 34.21.212.103 (SG/Singapore/103.212.21.34.bc.go ...
show more
(mod_security) mod_security (id:949110) triggered by 34.21.212.103 (SG/Singapore/103.212.21.34.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 16:12:40
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.21.212.103 (103.212.21.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.21.212.103 (103.212.21.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 12:12:34.500062 2026] [security2:error] [pid 596264:tid 596264] [client 34.21.212.103:56784] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.angove.biz"] [uri "/.env.production"] [unique_id "am4a8r_ODb99MGKWrz9H1wAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-08-01 15:34:29
(15 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 15:33:12
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.21.212.103 (103.212.21.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.21.212.103 (103.212.21.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 11:33:07.232297 2026] [security2:error] [pid 927625:tid 927625] [client 34.21.212.103:48542] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "notearsweb.com"] [uri "/.env.dev"] [unique_id "am4Rsyz9ifOu9rPn9zsKbQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฏ๐ต
beon
2026-08-01 15:12:24
(16 hours ago)
[DateTime=>2026-08-01T15:12:24Z (UTC)] , [HoneyPot_Hits=>10 times] , [HoneyPots=>/.env.backup, /.env ...
show more
[DateTime=>2026-08-01T15:12:24Z (UTC)] , [HoneyPot_Hits=>10 times] , [HoneyPots=>/.env.backup, /.env.local, /.env.old, /.env, /.env.prod, /.env.example and others] , [total_Hits=>10 times]
show less
Bad Web Bot
Web App Attack
Hacking
๐ฉ๐ช
AetherFox
2026-08-01 15:08:30
(16 hours ago)
AetherFox VoidGuard detected: [Sat Aug 01 15:08:29.619295 2026] [authz_core:error] [pid 3735240:tid ...
show more
AetherFox VoidGuard detected: [Sat Aug 01 15:08:29.619295 2026] [authz_core:error] [pid 3735240:tid 3735286] [client 34.21.212.103:45986] AH01630: client denied by server configuration: proxy:https://[MASKED]/.env
[Sat Aug 01 15:08:29.619573 2026] [authz_core:error] [pid 3735240:tid 3735274] [client 34.21.212.103:46008] AH01630: client denied by server configuration: proxy:https://[MASKED]/.env.prod
[Sat Aug 01 15:08:29.619806 2026] [authz_core:error] [pid 3735240:tid 3735287] [client 34.21.212.103:46018] AH01630: client denied by server configuration: proxy:https://[MASKED]/.env.production
[Sat Aug 01 15:08:29.622387 2026] [authz_core:error] [pid 3735241:tid 3735251] [client 34.21.212.103:45982] AH01630: client denied by server configuration: proxy:https://[MASKED]/.env.save
[Sat Aug 01 15:08:29.622428 2026] [authz_core:error] [pid 3735241:tid 3735293] [client 34.21.212.103:46006] AH01630: client denied by server configuration: proxy:https://[MASKED]
...
show less
Bad Web Bot
Web App Attack
๐ฒ๐พ
Rizzy
2026-08-01 14:07:10
(17 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 14:01:57
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.21.212.103 (103.212.21.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.21.212.103 (103.212.21.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 10:01:51.643847 2026] [security2:error] [pid 3884:tid 3911] [client 34.21.212.103:52528] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cargosanibel.com"] [uri "/.env"] [unique_id "am38T3zJU5Zx7kKwqcYr7wAAAVY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
polycoda
2026-08-01 13:46:29
(17 hours ago)
AutoBlock: ๐ฏ Vulnerability Scanner (Non Decay-Based)
Hacking
Web App Attack
๐ซ๐ท
masterguru
2026-08-01 13:37:56
(17 hours ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-201)
Hacking
Web App Attack
๐ซ๐ท
COMAITE
2026-08-01 13:11:33
(18 hours ago)
Suspicious URL access.
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 13:04:44
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.21.212.103 (103.212.21.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.21.212.103 (103.212.21.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 09:04:37.894552 2026] [security2:error] [pid 9238:tid 9238] [client 34.21.212.103:43390] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lp.veneerdent.com"] [uri "/.env"] [unique_id "am3u5e-EhA0jKJIrBbNfFwAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack