🇺🇸
ambor
2026-09-07 10:35:36
(1 day ago)
Honeypot access: Environment file access attempt. Path: /.env
Web App Attack
🇳🇱
e.fierstra
2026-09-07 10:24:23
(1 day ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇺🇦
URAN Publishing Service
2026-09-07 10:22:32
(1 day ago)
[07/Sep/2026:13:22:31 +0300] -- 34.42.48.77 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET /@f ...
show more
[07/Sep/2026:13:22:31 +0300] -- 34.42.48.77 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET /@fs/../.env?raw?? HTTP/1.1
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 09:43:35
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.42.48.77 (77.48.42.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.42.48.77 (77.48.42.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 05:43:32.620150 2026] [security2:error] [pid 454:tid 454] [client 34.42.48.77:55324] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.limpiezadevidriosyoficinas.com"] [uri "/@fs/../.env"] [unique_id "ap6HRHkBEPganaq9id8GegAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-07 09:19:50
(1 day ago)
Aggressive web scan
Web App Attack
🇫🇷
Octopuce
2026-09-07 09:13:35
(1 day ago)
Aggressive web search of vulnerable pages: /.docker/.env /uploads../.env /v2/.env /.env /images../.e ...
show more
Aggressive web search of vulnerable pages: /.docker/.env /uploads../.env /v2/.env /.env /images../.env ...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 09:08:54
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.42.48.77 (77.48.42.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.42.48.77 (77.48.42.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 05:08:50.206868 2026] [security2:error] [pid 22001:tid 22001] [client 34.42.48.77:42156] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.danafrostick.com"] [uri "/@fs/app/.env"] [unique_id "ap5_IqaMx8i7DQ5YzB9w_gAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇸🇪
vaia.cloud
2026-09-07 08:46:36
(1 day ago)
crowdsecurity/http-probing
Brute-Force
Web App Attack
🇳🇱
Site.eu
2026-09-07 07:18:41
(1 day ago)
Excessive multi-domain requests
Brute-Force
Anonymous
2026-09-07 07:08:29
(1 day ago)
34.42.48.77 - - [07/Sep/2026:09:08:28 +0200] "GET /@fs/.env?raw?? HTTP/1.1" 301 169 "-" "Mozilla/5.0 ...
show more
34.42.48.77 - - [07/Sep/2026:09:08:28 +0200] "GET /@fs/.env?raw?? HTTP/1.1" 301 169 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; meta-externalagent/1.1; +https:///docs/sharing/webmasters/crawler"
show less
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-07 06:43:02
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.42.48.77 (77.48.42.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.42.48.77 (77.48.42.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 02:42:56.690340 2026] [security2:error] [pid 32220:tid 32220] [client 34.42.48.77:25514] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hazeltrane.com"] [uri "/@fs/.env"] [unique_id "ap5c8DZ30Ur-EDOci-1k8gAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇪
cmbplf
2026-09-07 05:51:02
(1 day ago)
433 requests with url.path *.azure/*
Brute-Force
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-07 05:42:31
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.42.48.77 (77.48.42.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.42.48.77 (77.48.42.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 01:42:27.764727 2026] [security2:error] [pid 7730:tid 7730] [client 34.42.48.77:20654] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.finishlineenterprisesllc.com"] [uri "/@fs/.env.production"] [unique_id "ap5Owy9faGBGjJUXCx1FpgAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 04:01:19
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.42.48.77 (77.48.42.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.42.48.77 (77.48.42.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 00:01:15.008496 2026] [security2:error] [pid 15227:tid 15227] [client 34.42.48.77:63928] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.customgraduationnapkins.com"] [uri "/@fs/.env.production"] [unique_id "ap43C7g5G869IMhjI_05ZAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
service Informatique
2026-09-07 04:00:37
(1 day ago)
/.git
Web App Attack