🇩🇪
big-cloud.nl
2026-09-06 06:37:15
(1 hour ago)
Try to access /.env
Web App Attack
🇬🇧
openstrike.co.uk
2026-09-06 05:13:51
(2 hours ago)
26 attacks on PHP URLs, env grabbing URLs:
GET /wp-config.php.swp HTTP/1.1
GET /.env.dev HTTP/1.1
Web App Attack
Hacking
🇫🇷
masterguru
2026-09-06 03:22:02
(4 hours ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-197)
Hacking
Web App Attack
🇳🇱
e.fierstra
2026-09-06 03:02:12
(4 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
Anonymous
2026-09-06 00:34:32
(7 hours ago)
Blocked by ModSec and CSF
Port Scan
🇳🇱
homeshowdomain.nl
2026-09-05 22:02:46
(9 hours ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-04.
show less
Web App Attack
SSH
Hacking
🇩🇪
raph
2026-09-05 20:36:02
(11 hours ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack
🇫🇷
dynamix
2026-09-05 20:20:34
(11 hours ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 14:44:59
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.95.30.42 (42.30.95.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.95.30.42 (42.30.95.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 10:44:54.160107 2026] [security2:error] [pid 3805:tid 3805] [client 34.95.30.42:39762] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cesadoruf.it"] [uri "/.env.bak"] [unique_id "aprZZrdteh-rYcJ4t8885gAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 14:06:09
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.95.30.42 (42.30.95.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.95.30.42 (42.30.95.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 10:06:03.281065 2026] [security2:error] [pid 3070:tid 3070] [client 34.95.30.42:56162] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.scrunchiebutt.com"] [uri "/.env.dev"] [unique_id "aprQS9ji_WVT-CenXze4wwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-04 13:01:02
(1 day ago)
...
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-04 11:56:52
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇫🇷
dynamix
2026-09-04 11:44:29
(1 day ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 11:43:34
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.95.30.42 (42.30.95.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.95.30.42 (42.30.95.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 07:43:29.422083 2026] [security2:error] [pid 27947:tid 27947] [client 34.95.30.42:51872] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.hardemancountyjournal.com"] [uri "/.env.save"] [unique_id "apqu4QWI_6x_vdQfDHbZgQAAACg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 10:55:56
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.95.30.42 (42.30.95.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.95.30.42 (42.30.95.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:55:52.877919 2026] [security2:error] [pid 11145:tid 11153] [client 34.95.30.42:47392] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "blurmypic.com"] [uri "/.env.prod"] [unique_id "apqjuHrzwxXVEFl6VeBZSAAAAQY"]
show less
Brute-Force
Bad Web Bot
Web App Attack