🇳🇱
i-turnradio.nl
2026-09-06 06:14:21
(1 day ago)
2026-09-06 @ 08:14:02 (CET) ~ Blocked for trying to access: /.env.backup
Web App Attack
🇩🇪
big-cloud.nl
2026-09-06 06:01:15
(1 day ago)
Try to access /.env
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 03:26:44
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.84.14.231 (231.14.84.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.84.14.231 (231.14.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:26:39.913066 2026] [security2:error] [pid 16900:tid 16922] [client 34.84.14.231:40016] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cargowebstore.newleafpro.com"] [uri "/.env.prod"] [unique_id "apzdb6TNKh2FGrL4HnSNPgAAAVE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
SCHAPPY
2026-09-06 02:54:39
(1 day ago)
Mutliple attempts to access forbidden web resources, HTTP code 403.
Web App Attack
🇹🇼
kk_it_man
2026-09-06 02:43:03
(1 day ago)
ET INFO Request to Hidden Environment File - Inbound
ET WEB_SERVER Tilde in URI - potential .php~ ...
show more
ET INFO Request to Hidden Environment File - Inbound
ET WEB_SERVER Tilde in URI - potential .php~ source disclosure vulnerability
show less
Port Scan
🇺🇸
TPI-Abuse
2026-09-06 01:40:39
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.84.14.231 (231.14.84.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.84.14.231 (231.14.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 21:40:34.272238 2026] [security2:error] [pid 27312:tid 27312] [client 34.84.14.231:43858] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||appleconsultant.micahgartman.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "appleconsultant.micahgartman.com"] [uri "/mysql.sql"] [unique_id "apzEktW6nHhR2wFWtrX8sAAAADE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
FD-IX
2026-09-06 01:30:18
(1 day ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
🇩🇪
Nevermind
2026-09-06 01:10:38
(1 day ago)
34.84.14.231 - - [06/Sep/2026:03:10:38 +0200] "GET /.env.production HTTP/1.1" 403 6278 "-" "crusader ...
show more
34.84.14.231 - - [06/Sep/2026:03:10:38 +0200] "GET /.env.production HTTP/1.1" 403 6278 "-" "crusader-worker/1.0"
34.84.14.231 - - [06/Sep/2026:03:10:38 +0200] "GET /.env.local HTTP/1.1" 403 6278 "-" "crusader-worker/1.0"
34.84.14.231 - - [06/Sep/2026:03:10:38 +0200] "GET /.env.save HTTP/1.1" 403 6278 "-" "crusader-worker/1.0"
34.84.14.231 - - [06/Sep/2026:03:10:38 +0200] "GET /wp-config.php.swp HTTP/1.1" 403 6278 "-" "crusader-worker/1.0"
...
show less
Web App Attack
Anonymous
2026-09-06 00:31:27
(1 day ago)
Scanner hitting /.env.bak on nats-0.osef.cloud (GOOGL-2) — aaguard
Brute-Force
Port Scan
🇺🇸
TPI-Abuse
2026-09-05 23:57:17
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.84.14.231 (231.14.84.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.84.14.231 (231.14.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 19:57:09.841176 2026] [security2:error] [pid 3466926:tid 3466926] [client 34.84.14.231:51540] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.dynamic-therapy-mn.com"] [uri "/.env.backup"] [unique_id "apysVeDmmpszcz87C2oLSQAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
dynamix
2026-09-05 22:59:57
(1 day ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 22:17:08
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.84.14.231 (231.14.84.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.84.14.231 (231.14.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 18:17:01.987116 2026] [security2:error] [pid 25191:tid 25191] [client 34.84.14.231:59508] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cuteswimwear.brazilianbottom.com"] [uri "/.env.old"] [unique_id "apyU3XuYMRnqI2m50Gcn8QAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇵🇱
Budyn
2026-09-05 21:07:16
(1 day ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: budyn.ovh | URI: /actuator/env | UA: crusader-worker/1.0 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
🇺🇸
kosada.com
2026-09-05 20:57:28
(1 day ago)
Repeated exploit attempts, for example: /.env.old /.env (HTTP/1.1 port 443)
Web App Attack
Anonymous
2026-09-05 20:34:55
(1 day ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack