Anonymous
2026-07-29 07:00:00
(1 day ago)
Apache probe; attempts=365; exact paths: /.env | /.env.backup | /.env.bak | /.env.dev | /.env.develo ...
show more
Apache probe; attempts=365; exact paths: /.env | /.env.backup | /.env.bak | /.env.dev | /.env.development | /.env.example | /.env.local | /.env.old | /.env.php.bak | /.env.prod.bak | /.env.production | /.env.production.bak | /.env.staging | /.env.swp | /.env.test | /.git-credentials | /.git/HEAD | /.git/config | /.hermes/.env | /.openclaw/.env | /@fs/.env?raw?? | /@fs/root/.env?raw?? | /actuator | /actuator/configprops | /actuator/env | /actuator/mappings | /admin/.env | /api/.env | /app/.env | /backend/.env | /config.env | /config/.env | /config/.env.php | /core/.env | /dev/.env | /docker/.env | /frontend/.env | /laravel/.env | /production/.env | /public/.env | /sendgrid.env | /server/.env | /src/.env | /staging/.env | /web/.env
show less
Web App Attack
๐บ๐ธ
jormaster3k
2026-07-24 14:42:20
(5 days ago)
Attack against Apache (too many 404s)
Web App Attack
๐ธ๐ช
vaia.cloud
2026-07-24 08:55:03
(6 days ago)
crowdsecurity/http-crawl-non_statics
Brute-Force
Web App Attack
๐จ๐ฟ
ptlab
2026-07-24 08:45:41
(6 days ago)
Detected env_leak attack from WP-host.
Hacking
Web App Attack
๐ฉ๐ฐ
HostingGroup
2026-07-24 07:41:53
(6 days ago)
Automated malicious activity (Honeypot Trap) detected and blocked at the CDN edge by NordicCDN Shiel ...
show more
Automated malicious activity (Honeypot Trap) detected and blocked at the CDN edge by NordicCDN Shield. Offenses: 3. First blocked: 2026-07-24.
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
Dominik Lysiak
2026-07-24 07:16:05
(6 days ago)
34.32.104.239 - - [24/Jul/2026:09:16:04 +0200] "GET /.env HTTP/2.0" 200 5481 "-" "anthropic-ai"
34.3 ...
show more
34.32.104.239 - - [24/Jul/2026:09:16:04 +0200] "GET /.env HTTP/2.0" 200 5481 "-" "anthropic-ai"
34.32.104.239 - - [24/Jul/2026:09:16:04 +0200] "GET /.aws/config HTTP/2.0" 200 9801 "-" "Mozilla/5.0 (compatible; Applebot-Extended/0.1; +http://www.apple.com/go/applebot)"
34.32.104.239 - - [24/Jul/2026:09:16:04 +0200] "GET /.aws/credentials HTTP/2.0" 200 9810 "-" "CCBot/2.0 (https://commoncrawl.org/faq/)"
...
show less
Web App Attack
๐ง๐ช
voormedia
2026-07-24 02:53:44
(6 days ago)
Accessed trap at '/.aws/config'
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-07-24 02:46:42
(6 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐ฎ๐น
CoreTech srl
2026-07-24 02:23:56
(6 days ago)
cloudlinux2 fail2ban: 2026-07-24 04:23:00,035 fail2ban.filter [1589]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-07-24 04:23:00,035 fail2ban.filter [1589]: INFO [plesk-modsecurity] Found 34.32.104.239 - 2026-07-24 04:23:00cloudlinux2 fail2ban: 2026-07-24 04:23:00,060 fail2ban.filter [1589]: INFO [recidive] Found 34.32.104.239 - 2026-07-24 04:23:00cloudlinux2 fail2ban: 2026-07-24 04:22:59,952 fail2ban.filter [1589]: INFO [plesk-modsecurity] Found 34.32.104.239 - 2026-07-24 04:22:59cloudlinux2 fail2ban: 2026-07-24 04:22:59,964 fail2ban.filter [1589]: INFO [plesk-modsecurity] Found 34.32.104.239 - 2026-07-24 04:22:59cloudlinux2 fail2ban: 2026-07-24 04:23:00,050 fail2ban.actions [1589]: NOTICE [plesk-modsecurity] Ban 34.32.104.239cloudlinux2 fail2ban: 2026-07-24 04:23:00,004 fail2ban.filter [1589]: INFO [plesk-modsecurity] Found 34.32.104.239 - 2026-07-24 04:22:59cloudlinux2 fail2ban: 2026-07-24 04:23:00,044 fail2ban.filter [1589]: INFO [plesk-modsecurity] Found 34.32.104.239 - 2026-07-24 04:23:00cloudlinux2 fail2ban: 2026-0
show less
Brute-Force
๐ง๐พ
lns.bz
2026-07-24 02:09:54
(6 days ago)
.env scanning [BY]
Web App Attack
๐ฉ๐ช
Gwyneth Llewelyn
2026-07-24 01:53:47
(6 days ago)
2026/07/24 02:53:45 [error] 1770200#1770200: *1081122 access forbidden by rule, client: 34.32.104.23 ...
show more
2026/07/24 02:53:45 [error] 1770200#1770200: *1081122 access forbidden by rule, client: 34.32.104.239, server: centroestudostibetanos.org, request: "GET /.env HTTP/1.1", host: "portal.centroestudostibetanos.org"
34.32.104.239 - - [24/Jul/2026:02:53:45 +0100] "GET /.env HTTP/1.1" 403 1057 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ClaudeBot/1.0; +mailto:[email protected] "
2026/07/24 02:53:45 [error] 1770200#1770200: *1081110 access forbidden by rule, client: 34.32.104.239, server: centroestudostibetanos.org, request: "GET /api/.env HTTP/1.1", host: "portal.centroestudostibetanos.org"
show less
Brute-Force
Web App Attack
๐ฌ๐ง
gws-hostmaster
2026-07-24 01:27:03
(6 days ago)
ModSecurity OWASP CRS (Anomaly Score: ): Restricted File Access Attempt;Restricted File Access Attem ...
show more
ModSecurity OWASP CRS (Anomaly Score: ): Restricted File Access Attempt;Restricted File Access Attempt: AI Coding Assistant Artifact;URL file extension is restricted by policy;
show less
Web App Attack
๐ฆ๐บ
screwlooseit.com.au
2026-07-24 01:00:21
(6 days ago)
Blocked by CSF 13 firewall - Rule: config-dotfile
US/United States/239.104.32.34.bc.googleuserconten ...
show more
Blocked by CSF 13 firewall - Rule: config-dotfile
US/United States/239.104.32.34.bc.googleusercontent.com
show less
Web App Attack
Anonymous
2026-07-24 00:29:03
(6 days ago)
Bot / scanning and/or hacking attempts: GET / HTTP/2.0, GET /phpinfo.php HTTP/2.0, GET /api/.env HTT ...
show more
Bot / scanning and/or hacking attempts: GET / HTTP/2.0, GET /phpinfo.php HTTP/2.0, GET /api/.env HTTP/2.0, GET /login HTTP/2.0
show less
Hacking
Web App Attack
๐ฉ๐ช
electra
2026-07-23 23:29:02
(6 days ago)
Attempted to access path /backend/.env (GET request)
Hacking
Brute-Force
Web App Attack