🇳🇱
ReyhZhao
2026-09-08 00:24:50
(2 hours ago)
BunkerWeb alert: A request for a sensitive path (/.env) was detected and served with a 301 redirect, ...
show more
BunkerWeb alert: A request for a sensitive path (/.env) was detected and served with a 301 redirect, indicating a potential attempt to access environment configuration files.
show less
Brute-Force
🇦🇺
2000cn.com.au
2026-09-08 00:17:53
(2 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇫🇷
Octopuce
2026-09-07 23:29:33
(3 hours ago)
Aggressive web search of vulnerable pages: /.env /.env.local /app/.env /apps/.env /api/.env ...
Web App Attack
🇨🇭
zynex
2026-09-07 23:22:20
(3 hours ago)
URL Probing: /.env
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 19:33:21
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.65.235.215 (215.235.65.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.235.215 (215.235.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 15:33:15.662518 2026] [security2:error] [pid 22929:tid 22929] [client 34.65.235.215:50626] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sellitwithsteve.com"] [uri "/.git/config"] [unique_id "ap8Re1Jk_omwED0S1yfUfAAAADw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
Baking333
2026-09-07 19:29:42
(7 hours ago)
[redacted] 34.65.235.215 - - [07/Sep/2026:20:29:41 +0100] "GET /.git/config HTTP/1.1" 302 6798 0/495 ...
show more
[redacted] 34.65.235.215 - - [07/Sep/2026:20:29:41 +0100] "GET /.git/config HTTP/1.1" 302 6798 0/49530 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" [redacted] 34.65.235.215 - - [07/Sep/2026:20:29:41 +0100] "GET /.env HTTP/1.1" 302 1579 0/40105 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 17:01:18
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.65.235.215 (215.235.65.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.235.215 (215.235.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 13:01:11.624045 2026] [security2:error] [pid 612047:tid 612088] [client 34.65.235.215:49696] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sellarsmail.com"] [uri "/.git/config"] [unique_id "ap7t1wTxzc63XGIzqud7dQAAARQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-09-07 16:26:23
(10 hours ago)
Web attack/malicious scanning detected
Web App Attack
🇺🇸
paulo.apoloni
2026-09-07 15:13:17
(11 hours ago)
34.65.235.215 - - [07/Sep/2026:12:13:14 -0300] "GET /.git/config HTTP/1.1" 444 0 "-" "Mozilla/5.0 (W ...
show more
34.65.235.215 - - [07/Sep/2026:12:13:14 -0300] "GET /.git/config HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.65.235.215 - - [07/Sep/2026:12:13:15 -0300] "GET /.env HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.65.235.215 - - [07/Sep/2026:12:13:16 -0300] "GET /.env.bak HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.65.235.215 - - [07/Sep/2026:12:13:16 -0300] "GET /.env.backup HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.65.235.215 - - [07/Sep/2026:12:13:16 -0300] "GET /.env.save HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
🇫🇷
dynamix
2026-09-07 12:55:50
(13 hours ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 12:42:42
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.65.235.215 (215.235.65.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.235.215 (215.235.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 08:42:35.840962 2026] [security2:error] [pid 28331:tid 28346] [client 34.65.235.215:41220] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "selfhelpbook.org"] [uri "/.git/config"] [unique_id "ap6xOymI4ZSCVXq7VkmkJAAAAIw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇴
jad-abuse
2026-09-07 09:53:07
(17 hours ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_expos ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_exposure, env_probe, source_backup. Observed by 1 sensor(s); 118 hits.
show less
Web App Attack
🇳🇱
middelkoopcc
2026-09-07 08:35:01
(18 hours ago)
2026-09-07 10:33:18 GET /.git/config [301] && 2026-09-07 10:33:18 GET /.env [301] && 2026-09-07 10:3 ...
show more
2026-09-07 10:33:18 GET /.git/config [301] && 2026-09-07 10:33:18 GET /.env [301] && 2026-09-07 10:33:19 GET /app/.env [301] && 214 more within 20 minutes
show less
Web App Attack
🇳🇱
ConsulHosting
2026-09-07 08:12:58
(18 hours ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack
🇩🇪
EGP Abuse Dept
2026-09-07 08:02:57
(18 hours ago)
Scanning for web/db/file exploits on selection.chockdesign.com
SQL Injection
Bad Web Bot
Web App Attack