Anonymous
2026-06-12 13:25:02
(1 day ago)
suspicious request in access.log
Web App Attack
๐ฑ๐ป
garmtech.com
2026-06-12 13:07:57
(1 day ago)
IM360 WAF: Laravel Apps Leaking Secrets exploit attempt MV:androxgh0st
Web App Attack
๐ฑ๐ป
garmtech.com
2026-06-12 13:07:57
(1 day ago)
IM360 WAF: Direct access to sensitive file or dotfile MV:/.env
Web App Attack
๐บ๐ธ
Starburst SysOp Team
2026-06-12 13:06:11
(1 day ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-mnz6-1)
Hacking
Web App Attack
๐น๐ผ
kk_it_man
2026-06-12 13:03:02
(1 day ago)
ET INFO Request to Hidden Environment File - Inbound
ET SCAN Laravel Debug Mode Information Disclo ...
show more
ET INFO Request to Hidden Environment File - Inbound
ET SCAN Laravel Debug Mode Information Disclosure Probe Inbound
show less
Port Scan
๐ณ๐ฟ
Tripwire
2026-06-12 13:01:45
(1 day ago)
Scanning for exploits - /.env
Web App Attack
๐ง๐ช
voormedia
2026-06-12 12:59:25
(1 day ago)
Accessed trap at '/.env'
Web App Attack
๐ณ๐ฑ
informedclearly.com
2026-06-12 12:56:25
(1 day ago)
WAF_BAN reason=ENV_PROBE rule=ENV_PATH hits=1 path=/.env? ua=Mozilla/5.0 (X11; Linux x86_64) AppleWe ...
show more
WAF_BAN reason=ENV_PROBE rule=ENV_PATH hits=1 path=/.env? ua=Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-06-11 13:44:00
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.219.56.210 (ec2-34-219-56-210.us-west-2.comp ...
show more
(mod_security) mod_security (id:210492) triggered by 34.219.56.210 (ec2-34-219-56-210.us-west-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 11 09:43:55.323466 2026] [security2:error] [pid 25613:tid 25613] [client 34.219.56.210:59929] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.individualhealth.com"] [uri "/.env"] [unique_id "aiq7m2omnNQY8kY4Ty2YfAAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-11 13:16:39
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.219.56.210 (ec2-34-219-56-210.us-west-2.comp ...
show more
(mod_security) mod_security (id:210492) triggered by 34.219.56.210 (ec2-34-219-56-210.us-west-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 11 09:16:32.348761 2026] [security2:error] [pid 13676:tid 13676] [client 34.219.56.210:55981] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.tsiwny.org"] [uri "/.env"] [unique_id "aiq1MKIOzcuzQaO0ytbXOwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-06-11 13:06:27
(2 days ago)
Abuse Detected (1)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-11 12:59:29
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.219.56.210 (ec2-34-219-56-210.us-west-2.comp ...
show more
(mod_security) mod_security (id:210492) triggered by 34.219.56.210 (ec2-34-219-56-210.us-west-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 11 08:59:22.149581 2026] [security2:error] [pid 29092:tid 29092] [client 34.219.56.210:52804] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.creartest.com"] [uri "/.env"] [unique_id "aiqxKtw0FGBtQWs3AhzAFgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-11 12:42:06
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.219.56.210 (ec2-34-219-56-210.us-west-2.comp ...
show more
(mod_security) mod_security (id:210492) triggered by 34.219.56.210 (ec2-34-219-56-210.us-west-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 11 08:42:01.257469 2026] [security2:error] [pid 3638:tid 3638] [client 34.219.56.210:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.socialstudiesforkids.com"] [uri "/.env"] [unique_id "aiqtGTxRxLh9MN3J7DBVQgAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Rayulcifer
2026-06-11 12:37:48
(2 days ago)
34.219.56.210 - - [11/Jun/2026:07:37:48 -0500] "GET /.env HTTP/1.1" 200 5834 "-" "Mozilla/5.0 (X11; ...
show more
34.219.56.210 - - [11/Jun/2026:07:37:48 -0500] "GET /.env HTTP/1.1" 200 5834 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36"
...
show less
Open Proxy
Port Scan
Hacking
Web App Attack
SSH
๐ช๐ธ
el-brujo
2026-06-11 12:34:24
(2 days ago)
Cloudflare WAF: Request Path: /.env Request Query: Host: www.elhacker.net userAgent: Mozilla/5.0 (X ...
show more
Cloudflare WAF: Request Path: /.env Request Query: Host: www.elhacker.net userAgent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36 Action: block Source: firewallManaged ASN Description: Amazon.com, Inc. Country: US Method: GET Timestamp: 2026-06-11T12:34:24Z ruleId: 23548ee2b36547a1be09bb2c0550c529. Report generated by Cloudflare-WAF-to-AbuseIPDB (https://github.com/MHG-LAB/Cloudflare-WAF-to-AbuseIPDB).
show less
Hacking
SQL Injection
Web App Attack