๐ฉ๐ช
MBombeck
2026-08-30 06:01:10
(2 weeks ago)
Fail2Ban/traefik-botsearch on apps-01: banned after 5 failures
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-08-29 22:01:09
(2 weeks ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-08-28.
show less
Web App Attack
SSH
Hacking
๐ซ๐ท
masterguru
2026-08-29 03:32:58
(2 weeks ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-195)
Hacking
Web App Attack
๐บ๐ธ
ruusvuu
2026-08-29 01:15:10
(2 weeks ago)
Automated abuse report: 15 attack/probe requests from Google LLC / US.
Targeted paths: /.env.old, /. ...
show more
Automated abuse report: 15 attack/probe requests from Google LLC / US.
Targeted paths: /.env.old, /.env.prod, /.env.save, /.env.local, /wp-config.php~.
Sample log lines:
[mir-com] [8/28/2026, 6:15:10 PM] GET .mirregistry.com/.env.example 404 34.28.26.191 - 8.306 ms
[mir-com] [8/28/2026, 6:15:10 PM] GET .mirregistry.com/.env.bak 404 34.28.26.191 - 3.894 ms
[mir-com] [8/28/2026, 6:15:10 PM] GET .mirregistry.com/actuator/env 404 34.28.26.191 - 7.013 ms
Detected by an automated web-server log monitor.
show less
Web App Attack
๐ฎ๐ฉ
Burayot
2026-08-29 00:18:16
(2 weeks ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 34.28.26.191 (US/United States/191. ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 34.28.26.191 (US/United States/191.26.28.34.bc.googleusercontent.com): 1 in the last 3600 secs
show less
Web App Attack
๐จ๐ฆ
john doe
2026-08-28 23:54:19
(2 weeks ago)
SentinelBot: Secret-path hunting (5 distinct paths): Env File Hunting, Backup File Hunt (score: 68)
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-08-28 23:54:01
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.28.26.191 (191.26.28.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.28.26.191 (191.26.28.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 19:53:57.467075 2026] [security2:error] [pid 7037:tid 7037] [client 34.28.26.191:41254] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.wall.cswiki.us"] [uri "/.env.example"] [unique_id "apIflc9BSmtV4jQeBn_WkQAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฒ๐พ
Rizzy
2026-08-28 23:52:55
(2 weeks ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 23:32:42
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.28.26.191 (191.26.28.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.28.26.191 (191.26.28.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 19:32:38.255723 2026] [security2:error] [pid 29994:tid 29994] [client 34.28.26.191:41508] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "arklatexds.wisk.org"] [uri "/wp-config.php.swp"] [unique_id "apIaltHepF36YLJkzIIPHwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 22:59:38
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.28.26.191 (191.26.28.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.28.26.191 (191.26.28.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 18:59:30.714604 2026] [security2:error] [pid 26347:tid 26347] [client 34.28.26.191:47038] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.chat.underraided.com"] [uri "/wp-config.php.bak"] [unique_id "apIS0jr63tGTRchs3qdBKAAAACU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 21:42:59
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.28.26.191 (191.26.28.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.28.26.191 (191.26.28.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 17:42:55.485447 2026] [security2:error] [pid 2684:tid 2684] [client 34.28.26.191:54234] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sarahsmith.ws"] [uri "/.env.dev"] [unique_id "apIA391yvt3v_lzjcTclOwAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 20:57:42
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.28.26.191 (191.26.28.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.28.26.191 (191.26.28.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 16:57:33.983906 2026] [security2:error] [pid 17851:tid 17851] [client 34.28.26.191:35386] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ileronde.com"] [uri "/.env.prod"] [unique_id "apH2PSZMkR8SNSSkbR_hOAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ช
vaia.cloud
2026-08-28 18:46:05
(3 weeks ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
๐ณ๐ฟ
Tripwire
2026-08-28 18:35:12
(3 weeks ago)
Scanning for exploits - /.env.prod
Web App Attack
Anonymous
2026-08-28 17:12:04
(3 weeks ago)
Bot / scanning and/or hacking attempts: GET /.env.backup HTTP/1.1, GET /wp-config.php~ HTTP/1.1, GET ...
show more
Bot / scanning and/or hacking attempts: GET /.env.backup HTTP/1.1, GET /wp-config.php~ HTTP/1.1, GET /.env.example HTTP/1.1, GET /.env.bak HTTP/1.1, GET /.env.prod HTTP/1.1, GET /env HTTP/1.1, GET /wp-config.php.swp HTTP/1.1, GET /.env.production HTTP/1.1, GET /.env.dev HTTP/1.1, GET /_ignition/health-check HTTP/1.1, GET /wp-config.php.bak HTTP/1.1, GET /actuator/configprops HTTP/1.1, GET /.env.old HTTP/1.1, GET /actuator/env HTTP/1.1
show less
Hacking
Web App Attack