๐ซ๐ท
Octopuce
2026-06-15 07:38:31
(5 days ago)
Aggressive web search of vulnerable pages: /api/v3/.env /backend/.env /v1/.env /src/api/.env /src/.e ...
show more
Aggressive web search of vulnerable pages: /api/v3/.env /backend/.env /v1/.env /src/api/.env /src/.env ...
show less
Web App Attack
๐ณ๐ฑ
Savvii
2026-06-15 07:10:23
(5 days ago)
84 attempts against mh_ha-misbehave-ban on glow
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ช
vaia.cloud
2026-06-15 05:39:01
(5 days ago)
trying wp-login.php/xmlrpc.php 151 times in 1 minutes
Brute-Force
Web App Attack
Anonymous
2026-06-15 02:46:43
(5 days ago)
Multiple web server 400 error codes from same source ip
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-15 00:26:36
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 34.73.220.221 (221.220.73.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.73.220.221 (221.220.73.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 20:26:29.797128 2026] [security2:error] [pid 534:tid 534] [client 34.73.220.221:48102] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.ultratec.com.mx.activethinkers.net"] [uri "/.env.backup.txt"] [unique_id "ai9GtfaZ4hofkas9GaLkNwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐น
services.org.pl
2026-06-14 22:54:24
(6 days ago)
open() "/var/www/html/api/.env" failed (2: No such file or directory), client: 34.73.220.221, server ...
show more
open() "/var/www/html/api/.env" failed (2: No such file or directory), client: 34.73.220.221, server: web.services.org.pl, request: "GET /api/.env HTTP/1.1", host: "web.services.org.pl"
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-14 21:12:23
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 34.73.220.221 (221.220.73.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.73.220.221 (221.220.73.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 17:12:19.698040 2026] [security2:error] [pid 18894:tid 18894] [client 34.73.220.221:38350] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "switkoprofiri.org"] [uri "/.env.template"] [unique_id "ai8ZM-HPNtIX7CqnXxc97wAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Savvii
2026-06-14 20:11:19
(6 days ago)
20 attempts against mh-misbehave-ban on guava
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Savvii
2026-06-14 11:48:03
(6 days ago)
20 attempts against mh_ha-misbehave-ban on ceres
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-14 05:25:16
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 34.73.220.221 (221.220.73.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.73.220.221 (221.220.73.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 01:25:09.945981 2026] [security2:error] [pid 5242:tid 5245] [client 34.73.220.221:35170] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.surdick.com.faimreps.com"] [uri "/.env.copy"] [unique_id "ai47NXihatz6_huYiN_yTAAAAQA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-14 04:34:42
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 34.73.220.221 (221.220.73.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.73.220.221 (221.220.73.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 00:34:37.186959 2026] [security2:error] [pid 5598:tid 5598] [client 34.73.220.221:56584] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "shawnlayne.com"] [uri "/.env.backup.txt"] [unique_id "ai4vXcWjTNQSZR5ynRD1ogAAADQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-06-14 02:55:04
(6 days ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack